Skip to content

Security

Compliance Support

Compliance frameworks are mostly asking one question: can you show that a control exists and has been working? We build the controls and produce the evidence.

The problem

The evidence is what is missing, not the intent

Most businesses are broadly doing the right things and cannot prove any of it. When the auditor, the insurer or the client's security questionnaire arrives, there is no access review, no patch report, no restore test record and no documented policy — so a reasonable posture fails on paper.

Our approach

Controls that generate their own evidence

We implement the technical controls the frameworks actually require and set them up so they produce a record as a by-product: access reviews, patch compliance, backup verification, MFA coverage and audit retention. When the questionnaire arrives, the answers already exist.

What you get

Included as standard

Not an upsell list. These are the things that make the difference between a service you pay for and a service that works.

  • Gap assessment against the framework that applies to you
  • Written policies that match what you actually do
  • Access reviews on a schedule, with records
  • Patch compliance reporting
  • Backup and restore evidence
  • Audit log retention set to requirement
  • Cyber-insurance questionnaire support
  • Documented incident response plan

How we work

What actually happens

  1. 1

    Scope

    Establish which framework applies and what is genuinely in scope. Scope creep is the expensive part of compliance.

  2. 2

    Assess

    Gap analysis of current state against the requirement.

  3. 3

    Remediate

    Close the gaps, prioritising those that also reduce real risk.

  4. 4

    Evidence

    Ongoing reporting so the evidence accumulates continuously rather than being reconstructed annually.

Technologies

What we build on

Vendor-neutral where it matters. We will tell you when the cheaper option is the right one.

  • HIPAA Security Rule
  • PCI DSS
  • FTC Safeguards Rule
  • IRS Publication 4557
  • CIS Controls
  • Cyber-insurance frameworks

Questions

Compliance questions

Do you certify us as compliant?

No, and be wary of anyone who says they do. Compliance is determined by an auditor or the regulator. We implement and evidence the technical controls that determination rests on.

We are a small practice. Does HIPAA really apply?

The Security Rule applies regardless of size. What changes is what is reasonable and appropriate for an organisation of your scale, which is a genuine part of the standard rather than a loophole.

Our insurer sent a questionnaire we do not understand.

Send it over. Those questions map directly onto controls, and answering them inaccurately is worse than answering them honestly — a misstatement can void the policy at claim time.

Ready to secure your business?

A free assessment: we review your network, backups, Microsoft 365 settings and exposure, then hand you the findings in writing — whether or not you hire us.