Security
Compliance Support
Compliance frameworks are mostly asking one question: can you show that a control exists and has been working? We build the controls and produce the evidence.
The problem
The evidence is what is missing, not the intent
Most businesses are broadly doing the right things and cannot prove any of it. When the auditor, the insurer or the client's security questionnaire arrives, there is no access review, no patch report, no restore test record and no documented policy — so a reasonable posture fails on paper.
Our approach
Controls that generate their own evidence
We implement the technical controls the frameworks actually require and set them up so they produce a record as a by-product: access reviews, patch compliance, backup verification, MFA coverage and audit retention. When the questionnaire arrives, the answers already exist.
What you get
Included as standard
Not an upsell list. These are the things that make the difference between a service you pay for and a service that works.
- Gap assessment against the framework that applies to you
- Written policies that match what you actually do
- Access reviews on a schedule, with records
- Patch compliance reporting
- Backup and restore evidence
- Audit log retention set to requirement
- Cyber-insurance questionnaire support
- Documented incident response plan
How we work
What actually happens
- 1
Scope
Establish which framework applies and what is genuinely in scope. Scope creep is the expensive part of compliance.
- 2
Assess
Gap analysis of current state against the requirement.
- 3
Remediate
Close the gaps, prioritising those that also reduce real risk.
- 4
Evidence
Ongoing reporting so the evidence accumulates continuously rather than being reconstructed annually.
Technologies
What we build on
Vendor-neutral where it matters. We will tell you when the cheaper option is the right one.
- HIPAA Security Rule
- PCI DSS
- FTC Safeguards Rule
- IRS Publication 4557
- CIS Controls
- Cyber-insurance frameworks
Questions
Compliance questions
Do you certify us as compliant?
No, and be wary of anyone who says they do. Compliance is determined by an auditor or the regulator. We implement and evidence the technical controls that determination rests on.
We are a small practice. Does HIPAA really apply?
The Security Rule applies regardless of size. What changes is what is reasonable and appropriate for an organisation of your scale, which is a genuine part of the standard rather than a loophole.
Our insurer sent a questionnaire we do not understand.
Send it over. Those questions map directly onto controls, and answering them inaccurately is worse than answering them honestly — a misstatement can void the policy at claim time.
Related
Often paired with
Cybersecurity Services
Layered defence built around how small businesses actually get breached: email, credentials and unpatched endpoints.
Learn moreBackup & Disaster Recovery
Backups that are tested on a schedule, with a recovery time you have actually seen demonstrated — not assumed.
Learn moreIT Consulting & Technology Planning
A written technology roadmap and budget, so replacing your server is a planned expense rather than an emergency.
Learn more
Ready to secure your business?
A free assessment: we review your network, backups, Microsoft 365 settings and exposure, then hand you the findings in writing — whether or not you hire us.