Cyber security & IT audit advisory — London

Assurance you can put in writing.

Tehillah Digital Business Solutions helps UK businesses find out where their IT risk actually sits, then closes the gap — through independent assessments, control design, staff training and audit-ready reporting your board can rely on.

FCCA qualified CISA certified ISACA member ~20 years in IT risk & internal audit
What we do

Four ways we reduce your IT and cyber risk

Every engagement is scoped to your business, not sold off a shelf. Below is where most clients start.

IT & Cyber Risk Assessment

We benchmark your environment against recognised frameworks — ISO 27001, NIST CSF and COBIT — to build an honest picture of where you stand and a prioritised roadmap for improvement.

  • Gap analysis against the framework that fits your sector
  • Risk register with likelihood, impact and ownership
  • Board-ready summary and remediation roadmap
Start a risk assessment

Security Controls Design

We translate risk findings into controls that actually get used — access management, change control, data protection and logging that fit how your teams already work.

  • Control design tailored to your systems and headcount
  • Practical, business-relevant policies and procedures
  • Handover pack for your IT team or provider to run
Design my controls

Security Awareness Training

Most incidents start with a person, not a firewall. We run plain-English training and phishing simulations so your team becomes a control, not a liability.

  • Role-based sessions for staff, managers and the board
  • Simulated phishing with follow-up coaching, not blame
  • Short refresher content your people will actually read
Book training

Compliance & Audit Readiness

Preparing for an ISO 27001 certification, a client security questionnaire, or your first internal audit function? We get your evidence, controls and reporting into shape beforehand.

  • Pre-certification readiness reviews
  • Internal audit methodology and reporting templates
  • Support responding to client due-diligence requests
Get audit-ready
How an engagement runs

Four stages, one straight line to a signed-off outcome

No jargon-heavy deliverables you'll never reopen. Each stage ends with something you can act on.

01

Discover

A working conversation about your systems, your data and what keeps you up at night — no forms, no fluff.

02

Assess

We review your environment against the right framework and build a risk register with clear ownership.

03

Design

Controls, policies and training are designed around your team's real capacity — not a generic template.

04

Assure

You get a written report your board or clients can rely on, plus a plan for keeping it current.

Who's behind the work

Samuel Alema-Mensah, FCCA, CISA

Founder, Tehillah Digital Business Solutions

Samuel has spent close to two decades in IT risk, controls, internal audit and governance — including Big Four experience with PwC in London and Ghana, and senior internal audit leadership within a large UK retail and healthcare group. He founded Tehillah Digital to bring that same rigour to businesses that don't yet have an internal audit function of their own.

The approach is deliberately plain-spoken: proven frameworks, applied to your actual business, written up in language your board and your bank manager can both understand.

  • FCCA Fellow of the Association of Chartered Certified Accountants
  • CISA Certified Information Systems Auditor
  • ISACA Member
  • B.Sc. Accounting, University of Ghana — First Class Honours
Currently taking on new advisory engagements and interim IT audit assignments — book a discovery call to discuss timing and scope.
Get in touch

Tell us what you're trying to fix

Send a short note about your business and what prompted the enquiry — a client asking about your security, an upcoming audit, or simply not knowing where your risk sits. We'll reply within one business day.

By sending this, you agree to be contacted about your enquiry. See our privacy notice.

HOURS Mon–Fri, 9:00–18:00 (UK time)