000 Loading
Cybersecurity

Most organisations do not fail an assessment on exotic controls. They fail on asset inventory, logging retention and joiner-mover-leaver.

After enough assessments you stop being surprised. The controls that sink a first attempt are almost never the sophisticated ones — they are the housekeeping items that nobody owns.

1. Asset inventory that reflects reality

If your inventory is a spreadsheet last touched nine months ago, everything downstream is unverifiable. Start here, automate discovery, and accept that the first accurate count will be uncomfortable.

2. Log retention you can actually produce

Logging is usually enabled. Retention at the required window, in a form you can search under time pressure, usually is not.

3. Joiner-mover-leaver

The leaver half is the one that fails. Ask how long a departed employee's access persists — then verify it against the last three departures rather than the policy document.

4. Privileged access

Shared admin credentials remain the most common single finding. Vault them, and make check-out an event that gets logged.

5. Third-party risk

Your assessors will ask which suppliers touch your data. If the answer takes a week to assemble, that is itself the finding.

6. Backup restoration testing

Backups almost always run. Restores are almost never tested. Schedule a real restore quarterly and keep the evidence.

7. Change management

Emergency changes are legitimate; undocumented ones are not. A lightweight record beats a heavyweight process nobody follows.

8. Awareness that is measured

Completion rates are not outcomes. Run a phishing simulation, publish the click rate, and track it over time.

None of this is exotic. That is exactly why it gets skipped.

Typical reply: within 1 business day

Tell us what is not working.

A 30-minute discovery call, no cost and no obligation. You will leave it with an honest read on your situation — whether or not you work with us.