It seems we can’t find what you’re looking for. Perhaps searching can help.

ServicesCyber Risk Managment / Cyber Risk + Assessments

Cyber Risk + Compliance

Cyber risk audit and advisory for growing companies.

Security. Compliance. AI governance.

Security, compliance, and AI governance for organizations navigating an increasingly complex threat environment.

Placeholder executive portrait for the hero section

Founded

1971

A Top 100 assurance, tax + advisory firm

Turnaround

2 wks

Typical SOC 1 + SOC 2 reporting turnaround

Preferred assessor

1 of 12

Microsoft SSPA preferred assessors

Ranked

Top 100

INSIDE Public Accounting

Value beyond compliance

Compliance shouldn’t be a box-checking exercise.

Compliance shouldn’t be a box-checking exercise. Our clients view security and compliance as opportunities to strengthen their business rather than constraints imposed from outside.

Built on the expertise, reputation, and talent of Geels Norton, Smith + Howard Cyber Risk combines deep audit discipline, forward-looking advisory expertise, and hands-on implementation support. We serve clients directly with partner-level professionals from engagement scoping through delivery, guiding and educating throughout every step.

We believe the way you do anything is the way you do everything. That philosophy guides our three core commitments: High Touch. High Quality. High Value.

Why now

The pressures every growing company runs into.

Customer requirements

Enterprise buyers mandate SOC 2, ISO 27001, Microsoft SSPA, and other certifications before signing contracts.

Scattered compliance programs

Organizations lack a cohesive program for managing security, risk, and compliance — making day-to-day management harder and leaving gaps that auditors, regulators, and customers will find.

AI governance complexity

Boards and executives need frameworks for responsible AI adoption without the chaos of ad hoc experimentation.

Who we serve

Organizations at every stage.

Growth-Stage + Mid-Market SaaS

Organizations selling into enterprise buyers requiring SOC 2, ISO 27001, or other certifications.

Enterprises with International Operations

Organizations expanding into European and global markets, requiring ISO 27001 and related certifications.

AI-Native + AI-Adopting Organizations

Companies building AI-enabled products or responding to enterprise-buyer governance requirements.

Private Equity-Backed Companies

Organizations responding to sponsor mandates or preparing for exit, integration, or add-on acquisitions.

Boards + Executive Leadership

Organizations seeking independent validation of security posture or expert cyber risk guidance.

Our services

The right combination for where you are.

We assemble the right combination of audit expertise, strategic advisory, and hands-on support to meet you where you are.

01

SOC 1 + SOC 2 Audits

Third-party audits demonstrating security controls and operational maturity to enterprise buyers. Industry-recognized for high-quality reporting, white-glove service delivery, and two-week turnaround.

02

ISO 27001 + ISO 42001 Certification

Independent certification against ISO 27001 (Information Security Management Systems) and ISO 42001 (AI Management Systems). Unlocks international procurement and demonstrates intentional governance.

03

Microsoft SSPA Independent Assessments

Annual requirement for many Microsoft suppliers. As one of 12 Preferred Assessors globally, we deliver expert evaluations of security, privacy, and responsible AI controls.

04

AI Governance + Risk Management

Help organizations adopt AI purposefully and defensibly. We establish governance frameworks for evaluating, adopting, and overseeing AI without selecting or managing tools on your behalf — from strategy through implementation.

05

Cybersecurity Risk + Maturity Assessments

Independent evaluation of your security program against NIST CSF 2.0 or other recognized frameworks. We identify gaps, benchmark maturity, and produce defensible roadmaps for boards and executives.

06

Cyber Due Diligence

Buy-side and sell-side cybersecurity diligence on transaction timelines. Our Quality of Cyber™ framework evaluates IT and security maturity, incident history, and controls — framed in the language of the deal.

07

GRC Program Design + Implementation

Design and build governance, risk, and compliance programs aligned with SOC 2, ISO 27001, and ISO 42001. Includes control design tailored to your company, hands-on implementation guidance, and GRC platform enablement.

08

Audit Readiness + Gap Assessments

Pre-audit engagements identifying gaps against SOC or ISO requirements. Produces prioritized remediation roadmaps with partner-level oversight, positioning you to enter formal audits with confidence.

What sets us apart

The way you do anything is the way you do everything.

That philosophy guides our three core commitments.

Schedule a consultation

01

High Touch

We guide and educate throughout every engagement, and remain a resource well beyond report issuance. Partner-level professionals work directly with you from start to finish.

02

High Quality

Excellence is our baseline. Every engagement includes experienced leaders who bring deep expertise and a commitment to delivering work that strengthens your business, not just checks compliance boxes.

03

High Value

White-glove experience, world-class expertise, and fair pricing. We believe quality service should not require paying premium rates reserved for Big 4 consultancies.

Leadership

The partners and senior professionals you’ll work with.

Our Cyber Risk practice is led by experienced partners and senior professionals across audit, advisory, and AI governance.

Tulsi Adhikari

Principal · ISO, Cyber + GRC Advisory

Bryan-Geels

Bryan Geels

Partner · SOC

Maddie Hall

Principal · SSPA, AI Governance

Turner-Lee

Turner Lee

Principal · SOC

nick-norton

Nick Norton

Partner · SOC, Cyber + GRC Advisory

Jay Brietz

Partner · SOC

In their words

What clients say

Shout-out for being such amazing partners…

I want to give your entire team a huge shout-out for being such amazing partners to us year over year. We are thoroughly impressed by your mindset about security and how you take the time to delve into our specific circumstances, which makes our audit experience so much more useful and interesting. Moreover, the team’s fun and uncomplicated approach to working with us is truly appreciated!

Dora Neumeier

Compliance Lead at Sourcegraph

I was extremely impressed…

I was extremely impressed at how much your process reflected the mission and culture you pitched to us when we first met. It always felt like we were brainstorming together and never just checking boxes or jumping through hoops. Already the conversations we had throughout this process have us thinking about new ways to improve our operations.

Angel Say

CEO at Resolve

A strategic advantage, not a task

It is the primary reason we continue to do business with you and the rest of the team. Anyone can produce an audit. It is those that can make the audit process return value to the business — driving improvements that return operational efficiency, risk mitigation, and proof of process controls — that make the audit process strategic versus a task.

Nick Winchester

President at Creative Digital Imaging

A true partnership, not an “out of the box” engagement

It’s the reason we keep coming back. Highly customized approach to fit our needs and risks. Feels like a true partnership, not an “out of the box” engagement.

Elizabeth Mattin

Director – Governance, Risk, and Compliance; Customer Trust; Privacy at Abnormal AI

FAQ

Frequently asked questions.

What is a SOC 2 audit, and does my company need one?

A SOC 2 audit is an independent, third-party assessment of your security, availability, and other trust controls. It’s the de facto standard SaaS and technology-enabled companies use to prove security maturity to enterprise buyers — if your customers, contracts, or prospective buyers require proof of strong security practices, you likely need third-party assurance, like a SOC 2 report.

How long does a SOC 2 audit take with Smith + Howard?

Our standard turnaround is two weeks from fieldwork to report issuance, a meaningful difference from the timelines typical of Big 4 and mid-tier providers, without sacrificing audit quality.

What’s the difference between SOC 2 and ISO 27001?

SOC 2 is the de facto security standard in the U.S., while ISO 27001 is the internationally recognized standard for information security management systems. Many companies pursue both — SOC 2 for U.S. enterprise buyers and ISO 27001 to unlock European, UK, and global procurement.

What is ISO 42001, and why does it matter for AI?

ISO 42001 is the first international standard for AI Management Systems. It gives companies a structured framework to govern how they design, deploy, and oversee AI, and gives boards, regulators, and enterprise buyers independent validation that AI is being managed with the same discipline as other business-critical systems.

We’re not ready for a SOC 2 or ISO audit yet — can you help us prepare?

Yes. Our SOC 2 and ISO Readiness Assessments identify control gaps ahead of time and produce a prioritized remediation roadmap, typically over four to eight weeks, so you enter the formal audit with confidence.

How is Smith + Howard different from Big 4 firms for cyber risk services?

Every engagement includes a partner-level professional from scoping through issuance, our SOC 2 turnaround is two weeks, and our pricing doesn’t carry Big 4 overhead — white-glove service and deep expertise without the premium price tag.

Do you provide cybersecurity due diligence for M&A or private equity transactions?

Yes. Our Cyber Due Diligence service brings deal-context rigor to buy-side cybersecurity and IT diligence, evaluating a target’s control maturity, incident history, and third-party risk, with findings framed in the language of the deal.

What industries and company sizes do you work with?

We work with growth-stage through publicly traded companies, including SaaS and technology-enabled service providers, professional services firms, nonprofits, and private equity portfolio companies with material data, technology, or AI risk.

Navigate complexity with confidence

Whether you’re navigating a first audit, expanding into international markets, building an AI governance framework, or preparing for due diligence, our team can guide you through every stage.