How we work
01Internal audit of the management system
To ISO 19011, for ISMS, QMS, EMS and BCMS - audit programme, execution, findings and follow-up of corrective actions.
02Compliance review against the Act
Scoring across the 13 measures and 99 sub-measures, against the control catalogue, with a list of missing evidence.
03Data protection review
Records of processing, lawful bases, processor contracts, transfers outside the EU and data subject requests.
04Pre-audit review
A simulation of the audit process, with a report of findings and priorities.
05Corrective action tracking
Owner, deadline and closure evidence for every finding, in the GRC platform.
What you get
Audit programme
Findings report
Corrective action plan
Evidence base
Management review
Measures of Annex II this service covers
01 Commitment and accountability of those responsible for implementing cyber risk management measures
03 Risk management
11 Incident handling
Sectors where it is most in demand
Check for yourself before we talk
Entity categorisation check
Readiness check against the 13 measures
Incident reporting deadline calculator
Not sure where you stand?
Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.