Cybersecurity

Cybersecurity and assurance

Pass the security questionnaire.

Your customer’s procurement team, your group CISO and your NIS2 auditor all ask the same thing in different words: show us your controls. We build the controls and the evidence together, so the answer already exists when the request arrives.

Most companies fail on evidence, not on controls

The firewall is usually there. The backups usually run. What is missing is the risk register, the incident response plan, the supplier inventory and the dated record showing the controls were actually operating.

That gap turns a two-week questionnaire into a three-month scramble — and occasionally into a lost contract. We keep the paperwork current as part of routine maintenance, not as a rescue project.

Technical controls

  • Endpoint protection with real-time monitoring across servers and workstations
  • Scheduled patching of operating systems and applications
  • Firewall, network segmentation and secured remote access
  • Two-factor authentication on email and critical systems
  • Email authentication and anti-impersonation protection

Organisational controls

  • Risk assessment and inventory of critical systems
  • Written incident response plan with reporting deadlines
  • Access policy covering joiners, movers and leavers
  • Supplier register recording third-party access to your systems
  • Short, practical staff awareness training

Free, 30 minutes

Where does your evidence stand?

We walk through the questions your customers and auditors ask, and tell you which ones you can already answer. NIS2 reaches many companies indirectly, through the supply chain, well before it applies to them by sector or headcount.

  • Has a customer sent you a security questionnaire?
  • Does your group require a documented risk assessment?
  • Could you evidence your controls at short notice?

If your evidence is already in order, we will say so. We do not sell compliance work you do not need.