Protocol Zero — Cybersecurity & AI Governance

Start from
zero.
Build it right.

ISO 27001 · ISO 42001 · SOC 2 Type II
Audit readiness and AI governance consulting for organizations that take security seriously.

Scroll
Centennial, Colorado
Toba Group LLC
hello@tobasec.io

Services

01
ISO 27001:2022
Audit Readiness

Advisory on the internal controls required by ISO 27001 — gap assessments, control mapping, evidence requirements, and internal audit guidance. Your team implements. We advise on exactly what needs to be in place and make sure it holds up. We are not a certification body. We get you ready for the accredited auditor who is.

Information Security
02
ISO 42001:2023
AI Management

Advisory on building a credible AI Management System — governance frameworks, risk assessments, Annex A controls guidance, and AI Impact Assessment support. Your team implements. We advise on what the standard requires and how to satisfy it. Certification is issued by accredited bodies, not us.

AI Governance
03
SOC 2 Type II
Readiness

Advisory on the controls behind a clean SOC 2 Type II report — Trust Services Criteria scoping, control design, gap assessment, and evidence guidance ahead of your observation window. Your team implements. We advise on what the auditor will test and how to prove it operated. The report is issued by a licensed CPA firm. We get you ready for them.

Trust & Assurance

Different
by design.

You don't need a big firm and a team of generalists.
You need one expert, fully accountable, who does this and only this.

Advisory, not implementationWe advise your team on what controls are required, what evidence auditors expect, and what needs to change. Your organization owns the implementation. Certificates come from accredited bodies — we make sure you're ready for them.
Specialized focusISO 27001, ISO 42001, and SOC 2 Type II — not add-ons. Our entire practice.
Senior attention, alwaysYou work directly with the principal consultant. No handoffs. No surprises.
Built to act onDeliverables your team can execute — not reports that sit in a drawer.
Fixed fees, no surprisesScoped engagements with clear deliverables. Out-of-scope work requires a signed change order.
3+
Core frameworks mastered
1×
Point of contact. Always.
0%
Generic checklists. Zero.

Joshua
Sitompul

Founder & Principal Consultant · TobaSec

Most consultants study frameworks. I've implemented them.

I spent years as the internal GRC person at a B2B SaaS company, building the ISO 27001 and SOC 2 Type II programs, going through the audits, and fielding security questionnaires from federal agencies, defense contractors, healthcare organizations, universities, and Fortune 500 teams who needed to trust us before signing a contract. I know what enterprise security teams look for because I've spent years answering to them.

Along the way I implemented an ISO 42001 AI Management System, led a TPRM program, and did my time in blue team work: incident response, IAM, and identity governance.

TobaSec is built on that experience. You get someone who has been where you are.

Based in Centennial, Colorado. Serving clients across the United States.

Certifications
CISSP Certified Information Systems Security Professional · ISC2
ISO/IEC 27001 Lead Auditor Information Security Management Systems
ISO/IEC 42001 Lead Auditor Artificial Intelligence Management Systems
Joshua Sitompul — Founder of TobaSec

Ready to
get started?

Tell us about your organization and what you're trying to achieve. We'll schedule a no-obligation discovery call and go from there.

@
Email
hello@tobasec.io
Website
tobasec.io
📍
Location
Centennial, Colorado · Remote First