Audit and assurance
The evidence that your controls are in place and working, captured as the technology is run and packaged against the standard being assessed.
We map your obligations, close control gaps and keep the evidence current for clients, insurers, auditors and regulators. We are an appointed Cyber Essentials certification body, and certified for ISO 27001 by a UKAS-accredited certification body.
The governance advice here comes from a firm that holds both certificates itself, 00508-ISMS-001 and 00508-QMS-001, issued by a UKAS-accredited certification body.
How we run ISO 27001 for clientsYou have obligations to meet, and then to show you have met. We put the controls in place, run the technology behind them, and produce the evidence an auditor, insurer or prime contractor asks to see. The formal assessment is a separate engagement, and we do not guarantee you pass.
The evidence that your controls are in place and working, captured as the technology is run and packaged against the standard being assessed.
Preparation for Cyber Essentials and for Cyber Essentials Plus, which adds a technical audit where an assessor tests a sample of your devices and accounts, and the controls kept in place at each annual renewal. As an appointed Cyber Essentials certification body we also assess and certify other organisations, including your suppliers.
A full information security management system, the proof larger clients and regulators look for. We hold ISO 27001 ourselves, so we can guide you from gap analysis to your certification audit.
Alignment to the Cyber Assessment Framework for organisations in scope of the NIS Regulations, mapped across the framework's outcomes in the order that closes each gap.
What applies to you, from GDPR and the UK data protection regime to the rules your regulator enforces: Cyber Essentials, ISO 27001, FCA systems and controls, SRA, CQC, the NHS Data Security and Protection Toolkit, PCI DSS. Working out which of them applies is the first piece of work. A prioritised path, with the policies and evidence behind it, is the second.
The documented backbone every standard expects: information security and acceptable use policies, access control and data retention procedures, continuity and incident response plans, written for how you work.
Fixed-fee technology due diligence for private equity and M&A: what a target's IT and custom software are worth, what they cost to own, and whether that changes your offer. If you complete, we can fix what we found.
The work overlaps. The reason you are reading this usually does not, so each path is a different scope and a different price.
Technology due diligence for private equity and M&A, or sell-side readiness before you go to market. A fixed fee agreed before we start, and a remediation estimate the deal team can model.
See technology due diligenceA contract, a regulator, an insurer or a prime contractor has named a standard. We work out what applies, measure the gap, then close it in priority order.
See compliance readinessIt now has to stay true. We operate the controls and capture the evidence as the work happens, so the trail is current at the next assessment or questionnaire.
See audit and assurance
We are an appointed Cyber Essentials certification body, which means we can assess and certify other organisations against the standard. Because our assessors work to it every day, the controls we put in place are the ones the standard asks for.
Policy templates and dashboards are only part of the work. We patch the server, contain the incident, and stand behind every control we put in place. We run and secure the technology and record the proof as the work happens, so the evidence is current rather than assembled the week before an assessment, and one team is accountable for both halves.
Cyber Essentials, ISO 27001, monitoring and incident response, run by a certified team.
Go to Cyber Security Start hereThe low-commitment way in: a review of your IT, spend, security and efficiency, with a prioritised plan you own outright.
Explore the auditWhat this work costs is set out on our pricing page, and examples of it are in our case studies.
Book a consultation or start with an audit. You will speak to an engineer.
Hello, I am Ainsley, the AI assistant here at Dead Simple Computing. Ask me anything about managed IT, cyber security, software and AI, or governance and audit. I can also put you in touch with a person.
Replies are AI generated and can be wrong. Your messages are sent to a third-party AI service to produce them, and a member of our team can read this chat and may join it. Do not type anything confidential. See our privacy notice.