Skip to main content
NexITC
B8 · CYBERSECURITY · 6–12 WEEKS · BUILD

Compliance controls.
Operationalised.

B8 · Controls Implementation Build™ implements prioritised controls from your compliance backlog and operationalises the evidence workflows that turn readiness into a continuous state. Not a policy document. Not another spreadsheet. Working controls with named owners, measurable evidence completeness, and exception management that survives the annual audit.

DURATION
6–12 wks
DELIVERABLES
4 named
COMMERCIAL
Fixed fee
B8·PROJECTION / EVIDENCE COMPLETENESS
B8
BEFORE
20%
EVIDENCE · MANUAL SPREADSHEET
B8
AFTER
90%+
EVIDENCE · AUTOMATED WORKFLOW
WK 00
WK 03
WK 06
WK 09
STEADY
CONTROLS · TRANCHE
40
EVIDENCE COMPLETENESS
90+%
AUDIT PREP ↓
60%
SCENARIO · UAE HEALTHCARE · N=1
ILLUSTRATIVE
§ 00 · THESIS
01
WHY CONTROLS
STAY ON PAPER.

Every UAE enterprise compliance team we work with is fighting the same losing battle. The policy exists. The controls are documented in the manual. The framework mapping is complete in the master spreadsheet. And yet every audit surfaces the same class of finding: controls exist in the library but evidence of their continuous operation is missing, inconsistent, or last collected six months ago by someone who has since left the company.

The instinct is to write more policy or hire more compliance analysts. The instinct is expensive and it does not fix the underlying problem. What fixes the problem is turning controls into operations — named owners, automated evidence generation where possible, structured exception management, and reporting cadences a CRO can actually run on. B8 does that work on a fixed scope for the top-tranche controls in your backlog, then hands the operating discipline to the team that lives with it every day.

STATE · PAPER
Controls documented in library. Evidence collected reactively before audit. Findings recur year after year.
STATE · OPERATIONAL
Controls owned, evidence workflows running, exceptions managed. Audit finds nothing surprising.
§ 01 · WORK STREAMS

Six streams,
ending in controls that operate.

Control prioritisation and design front-load weeks 1–3. Implementation and evidence workflows overlap through weeks 3–9. Owner enablement and validation close weeks 9–12.

STREAM 01
WK 01–02

Control prioritisation

Backlog reviewed against regulatory exposure, evidence-automation potential, and business risk. Signed control-selection matrix agreed by CISO and CRO before Phase 2.

STREAM 02
WK 02–04

Control design

Each in-scope control designed for measurable operation — trigger, evidence artefact, cadence, owner, escalation path. Not "the policy says X" but "here is what X actually looks like in production."

OUTCOME
40
CONTROLS IMPLEMENTED
+ EVIDENCE WORKFLOWS LIVE
STREAM 03
WK 03–08

Implementation

Controls implemented in the systems where they actually operate — IAM, network, endpoint, application, data. Configuration-as-code where possible, documented change tickets where not.

STREAM 04
WK 05–10

Evidence workflows

Automated evidence collection wired for every control that supports it. Manual evidence workflows designed for the rest — with cadences, owners, and escalation for missed cycles.

STREAM 05
WK 08–11

Exception management

Structured exception workflow — request, approve, expire, review. Exceptions are not failures; unmanaged exceptions are.

STREAM 06
WK 11–12

Owner enablement & validation

Control owners trained on their specific controls. Audit templates handed over. Validation against an internal audit sample. 30/60/90-day check-ins scheduled.

EXPLICITLY NOT COVERED
Policy authoring or framework interpretation
boundary work for your GC and CISO office in partnership with legal advisors. B8 implements controls that already exist in policy.
Continuous operations after handover
run by your compliance team or by C6 ComplianceOps™ UAE as a managed retainer.
§ 02 · TIMELINE

Twelve weeks maximum.
Six minimum. Four phases.

Phase count is fixed. Duration flexes with backlog size, evidence-automation feasibility, and the number of control owners requiring enablement. Milestones are signed gates — not aspirations.

WK 0102030405060708091011 · 12Phase 1 · Prioritisation & designPhase 2 · ImplementationPhase 3 · Evidence workflowsPhase 4 · EnablementControl matrix signedEND WK 04 · GATE 01Controls implementedEND WK 08 · GATE 02Evidence workflows liveEND WK 11 · GATE 03Handover completeEND WK 12 · GATE 04OPERATING RHYTHMDaily standup · Weekly control-owner check-in · Bi-weekly Practice Lead reviewNAMED ACCOUNTABILITYPractice Lead — Cybersecurity (CEO escalationavailable)
§ 03 · APPROACH

Controls prioritised on evidence,
not on framework page count.

Every control backlog runs a six-criteria scorecard in weeks 1–2. Each candidate control scored 1–5 with documented rationale. Signed by CISO and CRO before Phase 2 begins.

CONTROL PRIORITISATION SCORECARD · TEMPLATE
CRITERIA · 06 · WEIGHTED 1–5
ILLUSTRATIVE SAMPLE RENDERING — actual scores are engagement-specific and derived from evidence gathered during discovery.
01
Regulatory exposure
Controls tied to an active audit finding, supervisor commitment, or tender clause. Not "nice to have" — accountable to a named party.
5/5
02
Evidence automation potential
Whether evidence can be pulled programmatically from existing systems. Automated evidence compounds; manual evidence decays.
4/5
03
Business risk coverage
Highest-impact asset or process the control protects. Generic controls score lower than crown-jewel-covering ones.
4/5
04
Owner readiness
Whether a control owner exists, has capacity, and understands what continuous operation requires. Ownerless controls fail regardless of implementation quality.
3/5
05
Implementation complexity
Technical difficulty and operational disruption cost. Complex controls extend timeline; disruptive controls need change-window planning.
3/5
06
Cross-framework reuse
Whether one implemented control satisfies multiple frameworks (PDPL + ADHICS + NESA + sector-specific). Reuse multiplies ROI.
4/5
!
DISCLOSURE · VENDOR-NEUTRALITY
NexITC maintains commercial arrangements with several GRC platform vendors and evidence-automation tools — these are how specialist consultancies build sustainable practices. We do not disclose which arrangements exist publicly because we do not want them to influence tool choice by anyone reading this page. The scorecard exists precisely so selection happens on evidence, not on economics. In practice, we have recommended tools with which we have no partnership when the scorecard result favoured them.
§ 04 · ARCHITECTURE

From controls on paper
to controls in operation.

A typical pre-engagement state has a policy manual, a control library spreadsheet, and reactive evidence collection triggered by imminent audit. The engagement stands up the operational layer that makes controls continuous.

BEFORE · T=0
TYPICAL STATE
ARTIFACT_01
Policy manual
DOCUMENT · STATIC
ARTIFACT_02
Control library spreadsheet
MASTER TRACKER
ARTIFACT_03
Ad-hoc evidence folder
PRE-AUDIT SPRINT
ARTIFACT_04
Exception log (email)
UNMANAGED
AUDIT · TIME
3 weeks preparing evidence before every audit cycle
OPERATIONAL REALITY
  • Controls exist on paper; evidence is reactive
  • Ownership is diffuse; exceptions untracked
  • Same audit findings recur year after year
  • Compliance team burns time before every cycle
B8 · OPERATIONALISE
AFTER · STEADY STATE
TARGET-STATE
PLATFORM_01
Operational Controls
Owned · Cadenced · Configured · Escalated
PLATFORM_02
Evidence Workflows
Automated · Manual · Scheduled · Reviewed
↓ OWNED · MEASURED · EVIDENCED · EXCEPTIONS MANAGED ↓
POLICY LIBRARY · RETAINED
Unchanged · controls now reference implementations
STEADY-STATE OUTCOME
  • Top-tranche controls operating with named owners
  • Evidence completeness above 90% on implemented controls
  • Exception aging visible weekly, not annually
  • Audit preparation reduced from weeks to days

Reference pattern. Some engagements retain manual evidence collection for controls where automation is not economically justified. What always changes is that evidence generation becomes a scheduled operation, not a pre-audit sprint.

§ 05 · REPRESENTATIVE SCENARIO

A healthcare group,
controls operational.

Representative pattern for a UAE healthcare group of this scale — multi-facility operator, ADHICS v2 in scope, 80+ control backlog. Ranges reflect target outcomes NexITC underwrites in scope for this class of engagement. N=1 — illustrative composite, not a specific client.

SCENARIO / B8 / UAE HEALTHCARE · 80+ CONTROL BACKLOG
DURATION · 10 WKS
CONTROLS IMPLEMENTED
40
Top-tranche of 80+ backlog
EVIDENCE COMPLETENESS
90%
On implemented controls at steady state
AUDIT PREP TIME
60%
reduction on next cycle
SITUATION

UAE healthcare group. Multi-facility operator with ADHICS v2 in scope. Control library documented for 80+ controls but no operational implementation — evidence collected reactively in the two weeks before each annual audit, findings recur, compliance team burnt out.

ENGAGEMENT

10-week B8. Weeks 1–3 prioritisation and design against ADHICS v2 exposure and evidence-automation potential. Weeks 3–8 implementation of the top 40 controls across IAM, network, endpoint, and application layers. Weeks 8–10 evidence workflows, exception management, and owner enablement.

OUTCOME

40 top-tranche controls operational with named owners. Evidence completeness at 90% on implemented controls. Exception aging visible weekly. First post-B8 audit cycle prepared in one week instead of three. Group transitioned to C6 ComplianceOps™ UAE to sustain the operating discipline.

§ 06 · DELIVERABLES

Four artifacts,
each with signed acceptance.

Every deliverable has documented acceptance criteria signed at engagement kickoff. Nothing more, nothing less.

D_01

Implemented Controls

Top-tranche controls implemented in the systems where they operate — IAM, network, endpoint, application, data. Configuration-as-code where possible; documented change tickets where not.

D_02 · CORE

Evidence Generation Workflows

Automated evidence collection wired for every control that supports it. Manual workflows designed for the rest — cadences, owners, escalation for missed cycles.

D_03

Owner Enablement Pack

Control owners trained on their specific controls. Runbook per control with trigger, evidence artefact, cadence, and escalation path.

D_04 · AUDIT-READY

Audit Templates & Exception Register

Evidence structure and export templates for the audit cycles you actually face. Exception register with request/approve/expire/review workflow — the document that turns "we don't know why this control is out" into "the CISO approved a 90-day exception on 12 March, scheduled for review 12 June."

HANDOVER
WK 12
§ 07 · OUTCOMES

Six outcome metrics,
measured pre and post.

Success is not "the controls are documented." It is measured against six specific outcomes captured in a baseline report at engagement start and re-measured at post-handover steady state.

THE EVIDENCE COMPLETENESS JOURNEY · REPRESENTATIVE
Twenty to ninety, across the four phases.
90%EVIDENCE · STEADY
100%75%50%25%020%BaselinePRE-ENGAGEMENT45%Controls implementedEND WK 0875%Workflows liveEND WK 1190%Steady state30 DAYS POST
01 · EVIDENCE
85+%
Evidence completeness on implemented controls at steady state.
02 · EXCEPTIONS
<10%
Controls with unresolved exceptions past due date.
03 · FINDINGS
50–70%
Reduction in audit findings on next cycle.
04 · AUDIT PREP
50–70%
Reduction in audit preparation time.
05 · OWNERSHIP
100%
Controls with a named, capable owner.
06 · AUTOMATION
40–60%
Controls with automated evidence generation.
§ 08 · FIT

Honest scoping.

B8 is a fit when specific conditions are met. It is not a fit when other conditions are. We say so before the scope conversation, not after the commercial commitment.

PREREQUISITES
Move fast when these five conditions are in place at kickoff.
01
A defined control backlog

Ideally from [[A3|A3 Compliance Fast-Track™ UAE]] or an existing internal assessment. If no backlog exists, sequence A3 first — B8 does not build the backlog from scratch.

02
CISO and CRO both engaged

Both sign the control prioritisation matrix. Sole CISO engagement without CRO buy-in stalls at Phase 2.

03
Control owners identifiable

Someone must be named per implemented control. Ownerless controls do not become operational, however well implemented.

04
System access for implementation

IAM, network, endpoint, application access agreed with the relevant infrastructure and application teams. Access delays are the most common cause of Phase 3 slippage.

05
A change-management window

Especially for controls that touch production authentication or network segmentation. Compressed windows extend timeline or narrow scope.

NOT SUITABLE IF
Four patterns indicate a different engagement is a better fit.
No control backlog yet defined

Start with A3 Compliance Fast-Track™ UAE — 2–4 weeks to produce the prioritised backlog.

You need policy authoring, not implementation

Boundary work for your GC or CISO office with legal advisors. B8 implements controls that already exist in policy.

You need a unified GRC operating platform across many frameworks

That's B17 GRC Platform Build™ — often paired with B8 when both implementation and platform are in scope.

Audit deadline is under 4 weeks and backlog is large

We can scope B8 to a defensible subset — with honest conversation about what stays uncovered. We do not sign to timelines we cannot defend.

§ 09 · COMMERCIAL

Fixed fee.
Milestone-based.

Total engagement fee agreed in the scope statement. Not time-and-materials. Not day rate. Every engagement is preceded by a scope conversation to ensure fit before commitment.

STANDARD MODEL
ENGAGEMENT MODEL
Fixed fee
PAYMENT CADENCE
Milestone-based

Payment schedule aligned to engagement phases and defined delivery milestones agreed upfront.


INCLUDED IN SCOPE
  • All 4 named deliverables with acceptance criteria
  • Named Practice Lead throughout the engagement
  • Bi-weekly executive sponsor reviews
  • 30/60/90-day post-handover check-ins
  • Written scope amendment process for any changes
01

Signed scope statement

Every engagement begins with a signed scope statement fixing deliverables, timeline, milestones, and commercial terms. No verbal agreements. No moving targets.

02

No scope creep

Scope changes require a signed scope amendment. If scope changes, so does the commercial arrangement — always in writing, always signed by both parties.

03

Named accountability

The Practice Lead is accountable for commercial and delivery outcomes throughout the engagement, with escalation to the CEO within 24 hours if needed.

§ 10 · QUESTIONS

Five, most asked.

Q_01Why implement controls rather than write policy first?

Because the policy already exists. Every UAE enterprise we work with arrives with a control library — PDPL controls, ADHICS controls, sector-specific controls — documented in a policy manual, mapped in a spreadsheet, and never operationalised.

The audit finding is not "you have no controls." The audit finding is "controls exist on paper but evidence of continuous operation is missing." B8 closes that specific gap.

Q_02How do you prioritise which controls to implement first?
Three factors, weighted. First, regulatory exposure — controls tied to an active audit finding or supervisor commitment go first. Second, evidence generation cost — controls where evidence can be automated from existing systems generate compounding returns and go early. Third, business risk — controls covering the highest-impact assets or processes go before generic housekeeping. The prioritisation exercise takes about a week and produces a signed control-selection matrix that the CISO and CRO both agree to before Phase 2 begins.
Q_03Do you write policy, or only implement existing policy?
Only implement. Policy authoring is a separate discipline and a different engagement — often best done by your GC or CISO office in partnership with a legal advisor. If your policy is incomplete or contradictory, we surface that in discovery and either scope B8 around the well-defined controls or recommend policy remediation first. The engagement respects the boundary between what should be decided by counsel and what should be built by engineers.
Q_04What happens to controls after B8 hands over?
Two paths. If you have an internal compliance team capable of operating the controls and maintaining the evidence workflows, we hand over cleanly and provide 30/60/90-day check-ins. If you need external hands to operate the controls continuously — running evidence collection, managing exceptions, preparing for audits — that is C6 ComplianceOps™ UAE, a Run-tier retainer. Most engagements sequence B8 → C6.
Q_05Can this align with a specific audit or tender deadline?
Yes, subject to scope realism. If the deadline is inside 6 weeks and the control backlog is large, we scope B8 around a subset that can be defensibly implemented and evidenced in time — with the honest conversation about what stays uncovered. We do not agree to timelines we cannot defend, and we do not report inflated evidence-completeness numbers to make an audit look better than it is.
§ 11 · NAMED ACCOUNTABILITY

One name
on the engagement letter.

A named Practice Lead is accountable for delivery, commercial outcomes, and the client relationship throughout the engagement. Not a project manager who disappears after kickoff. Not a partner who nods at the SOW and vanishes.

THE ROLE

Practice Lead — Cybersecurity

Present at every phase gate, every scope decision, every difficult conversation. Available for 30/60/90-day post-handover check-ins as part of the engagement.

SIX ACCOUNTABILITIES
01
Commercial arrangement

Including scope amendments.

02
Deliverables acceptance

Signs off all 4 deliverables.

03
Bi-weekly reviews

With executive sponsor.

04
Change orders

Authorised to negotiate.

05
Escalation path

CEO within 24 hours.

06
Post-handover

30/60/90-day check-ins.

§ 13 · BOOK A CLINIC

Thirty minutes.
No slide deck.

A structured 30-minute scope conversation with the Practice Lead. You describe the control backlog, the frameworks in scope, and who owns evidence today. We describe whether B8 is the right engagement — and if not, what is.

Book a clinic →Email directly
DURATION
30 minutes
PREPARATION
None required
FOLLOW-UP
Written scope, 5 business days