Governance and Audit / prove it

Governance, audit and compliance

We map your obligations, close control gaps and keep the evidence current for clients, insurers, auditors and regulators. We are an appointed Cyber Essentials certification body, and certified for ISO 27001 by a UKAS-accredited certification body.

CertifiedISO 27001, via a UKAS-accredited body
Certification bodyCyber Essentials
OutputAudit-ready evidence
Verified
ISO 27001 & 9001Certified by a UKAS-accredited certification body Cyber EssentialsCertification body Cyber Essentials PlusCertified NCSC AssuredCyber Advisor MicrosoftCertified Expert
ISO 27001 and ISO 9001 certified, via a UKAS-accredited certification body

Certified for ISO 27001 and ISO 9001, by a UKAS-accredited body.

The governance advice here comes from a firm that holds both certificates itself, 00508-ISMS-001 and 00508-QMS-001, issued by a UKAS-accredited certification body.

How we run ISO 27001 for clients
Governance and Audit / 01 · What we do

Audit, certification and compliance support

You have obligations to meet, and then to show you have met. We put the controls in place, run the technology behind them, and produce the evidence an auditor, insurer or prime contractor asks to see. The formal assessment is a separate engagement, and we do not guarantee you pass.

01Evidence

Audit and assurance

The evidence that your controls are in place and working, captured as the technology is run and packaged against the standard being assessed.

Evidence packsLogging and recordsInternal reviewBetween assessments
See audit and assurance
02Certify

Cyber Essentials and Cyber Essentials Plus

Preparation for Cyber Essentials and for Cyber Essentials Plus, which adds a technical audit where an assessor tests a sample of your devices and accounts, and the controls kept in place at each annual renewal. As an appointed Cyber Essentials certification body we also assess and certify other organisations, including your suppliers.

Readiness reviewPlus auditAnnual renewalSupplier assurance
See Cyber Security
03Assure

ISO 27001 support

A full information security management system, the proof larger clients and regulators look for. We hold ISO 27001 ourselves, so we can guide you from gap analysis to your certification audit.

Gap analysisISMS buildInternal auditCertification support
See ISO 27001
04Align

CAF alignment

Alignment to the Cyber Assessment Framework for organisations in scope of the NIS Regulations, mapped across the framework's outcomes in the order that closes each gap.

CAF objectives A to DNIS RegulationsGap to outcome mapping
Talk to us about CAF
05Comply

Compliance readiness

What applies to you, from GDPR and the UK data protection regime to the rules your regulator enforces: Cyber Essentials, ISO 27001, FCA systems and controls, SRA, CQC, the NHS Data Security and Protection Toolkit, PCI DSS. Working out which of them applies is the first piece of work. A prioritised path, with the policies and evidence behind it, is the second.

GDPR readinessSector rulesPolicy frameworksEvidence
Talk to us about readiness
06Document

Policy frameworks

The documented backbone every standard expects: information security and acceptable use policies, access control and data retention procedures, continuity and incident response plans, written for how you work.

Security policyAccess controlData retentionIncident plan
See policy frameworks
07Prove

Technology due diligence

Fixed-fee technology due diligence for private equity and M&A: what a target's IT and custom software are worth, what they cost to own, and whether that changes your offer. If you complete, we can fix what we found.

Deal ScanTechnical DDSell-side readinessPE and M&A
See technology due diligence
Governance and Audit / 02 · Where to start

Three separate paths in

The work overlaps. The reason you are reading this usually does not, so each path is a different scope and a different price.

01Diligence

You have a deal on the table

Technology due diligence for private equity and M&A, or sell-side readiness before you go to market. A fixed fee agreed before we start, and a remediation estimate the deal team can model.

See technology due diligence
02Prepare

Something is being asked of you

A contract, a regulator, an insurer or a prime contractor has named a standard. We work out what applies, measure the gap, then close it in priority order.

See compliance readiness
03Evidence

You already hold the certificate

It now has to stay true. We operate the controls and capture the evidence as the work happens, so the trail is current at the next assessment or questionnaire.

See audit and assurance
Governance and Audit / 03 · A distinct service

Cyber Essentials certification body

Dead Simple Computing, a Cyber Essentials Certification Body

We are an appointed Cyber Essentials certification body, which means we can assess and certify other organisations against the standard. Because our assessors work to it every day, the controls we put in place are the ones the standard asks for.

01We certify other organisations. If you run a supply chain or assess third parties, we can certify suppliers against the standard.
02Preparation and assessment stay separate. Where both would apply, they are separate engagements and the roles are kept apart.
Governance and Audit / 04 · Run and prove

We run the technology and record the proof

Policy templates and dashboards are only part of the work. We patch the server, contain the incident, and stand behind every control we put in place. We run and secure the technology and record the proof as the work happens, so the evidence is current rather than assembled the week before an assessment, and one team is accountable for both halves.

Run and proveOne team, both halvesWe operate the controls and evidence them, so the proof matches reality.
CertifiedWe hold it ourselvesCertified for ISO 27001 by a UKAS-accredited body, and an appointed Cyber Essentials certification body.

Meet it, and prove it.

Book a consultation or start with an audit. You will speak to an engineer.

Reading, Berkshire  /  reply within one working day