Skip to content

N-104Data security — Compliance & Testing

Compliance & Testing

Evidence that the controls exist, and proof they work.

Insurers and regulators increasingly ask a question most businesses cannot answer: show me. Not whether you have a policy, but whether the control was actually in place on a given date. Compliance work produces that record — and testing establishes whether the controls survive contact with someone trying to get past them.

AWhat the install covers

  • Gap assessment against the framework that applies to you
  • Network penetration testing, internal and external
  • Written policies that describe what you actually do
  • Evidence collection so an audit is a retrieval exercise, not a scramble
  • Cyber insurance questionnaire support — answered accurately

O&MAfter handover

What we keep doing once it works.

Included in a management agreement. Without one, this is the part that quietly stops happening the day the installer drives away.

How managed service works →
  • Scheduled re-testing rather than a single point-in-time report
  • Continuous compliance monitoring with drift alerts
  • Remediation tracked to closure, not just listed

QCommon questions

Compliance & Testing, asked and answered.

What does a penetration test actually involve?
A controlled attempt to get in, internally and externally, using the methods an attacker would. The output is a prioritised list of what worked and what to fix — not a vulnerability scan report, which lists theoretical issues without establishing whether they are exploitable in your environment.
Our cyber insurance renewal has a security questionnaire. Can you help?
Yes. The important part is answering it accurately. Overstating a control to secure a better premium can void the policy at claim time, which is the worst possible moment to discover the answer was optimistic.
How often should we test?
At least annually, and after any significant change — a new office, a migration, a new line-of-business application. A point-in-time test describes the day it was run; scheduled re-testing describes the trend.
What if a test finds serious problems?
That is the test working. Findings come prioritised by real exploitability rather than raw severity score, and remediation is tracked to closure rather than handed over as a list.

T-900Next step

Every job starts with someone walking the building.

A site survey costs you nothing and produces a real drawing — device counts, cable paths, and a fixed number. Not a brochure.