About

A small consultancy for the companies that need ISO 27001 most

N4sec is an information security and compliance consultancy based in Colombo, founded in 2026.

We started the company because the Sri Lankan businesses that need ISO 27001 most, the software exporters, outsourcers, fintechs, finance companies and insurers with 20 to 300 staff, were being served by two kinds of firm: large practices built for banks and telecom operators, and template sellers who deliver a folder of policies and disappear before the audit.

We wanted a third option. A small team that does the work properly, at a price a mid-sized company can plan for, in plain language, and that stays until the certificate is issued.

How we think about the work

  • The certificate is the output, not the point. A management system only earns its keep if people follow it after the auditor leaves. We write policies that staff will read and controls that fit the way the business already runs.
  • Independence matters. We do not certify, we do not sell products, and we do not audit what we have built. If that costs us a sale, so be it.
  • Regulation is the starting point, not the pitch. We read the Central Bank directions, the IRCSL guideline and the Personal Data Protection Act so that you do not have to, and we tell you which parts actually apply to you.
  • Say the uncomfortable thing early. If you are not ready, if the timeline is unrealistic, or if a cheaper option would serve you better, we say so at scoping.

Where we work

We are based in Colombo and work on site anywhere in Sri Lanka. We also work remotely with Sri Lankan-founded companies whose teams or clients are overseas.

Talk to the people who will do the work.

There is no sales team. The person on the scoping call is the consultant who will run your project.