N-104Data security — Compliance & Testing
Compliance & Testing
Evidence that the controls exist, and proof they work.
Insurers and regulators increasingly ask a question most businesses cannot answer: show me. Not whether you have a policy, but whether the control was actually in place on a given date. Compliance work produces that record — and testing establishes whether the controls survive contact with someone trying to get past them.
AWhat the install covers
- Gap assessment against the framework that applies to you
- Network penetration testing, internal and external
- Written policies that describe what you actually do
- Evidence collection so an audit is a retrieval exercise, not a scramble
- Cyber insurance questionnaire support — answered accurately
O&MAfter handover
What we keep doing once it works.
Included in a management agreement. Without one, this is the part that quietly stops happening the day the installer drives away.
How managed service works →- Scheduled re-testing rather than a single point-in-time report
- Continuous compliance monitoring with drift alerts
- Remediation tracked to closure, not just listed
QCommon questions
Compliance & Testing, asked and answered.
- What does a penetration test actually involve?
- A controlled attempt to get in, internally and externally, using the methods an attacker would. The output is a prioritised list of what worked and what to fix — not a vulnerability scan report, which lists theoretical issues without establishing whether they are exploitable in your environment.
- Our cyber insurance renewal has a security questionnaire. Can you help?
- Yes. The important part is answering it accurately. Overstating a control to secure a better premium can void the policy at claim time, which is the worst possible moment to discover the answer was optimistic.
- How often should we test?
- At least annually, and after any significant change — a new office, a migration, a new line-of-business application. A point-in-time test describes the day it was run; scheduled re-testing describes the trend.
- What if a test finds serious problems?
- That is the test working. Findings come prioritised by real exploitability rather than raw severity score, and remediation is tracked to closure rather than handed over as a list.
T-900Next step
Every job starts with someone walking the building.
A site survey costs you nothing and produces a real drawing — device counts, cable paths, and a fixed number. Not a brochure.