Home / Managed IT / Governance, Risk & Compliance
Section F · Service 17
Compliance as a programme, not an annual scramble.
Risk assessments and gap analyses against your target framework, policy development, continuous control monitoring, third-party risk, cyber insurance support and customer security questionnaire responses — run as evidence collected continuously rather than assembled the month before an assessment.
Book a consultation →All managed IT servicesThe problem
Why compliance work usually costs more than it should
Most organizations experience compliance as a periodic emergency. An assessment date is set, someone is asked to produce twelve months of evidence that was never systematically collected, screenshots are gathered by hand, and policies written years ago are hurriedly reconciled with what the organization actually does. The cost is not the audit fee. It is the weeks of senior time consumed reconstructing a record that could have been accumulating all along.
The second cost is subtler and more damaging: when evidence is assembled retrospectively, controls get documented as they were supposed to work rather than as they did. That produces a compliant-looking file and an organization that remains exposed, which is the outcome nobody paid for.
Continuous, not periodic
Control evidence is collected as a by-product of operating the environment — patch compliance, access reviews, backup restore tests, training completion and change records are already produced by the managed service. Compliance becomes a reporting exercise rather than a reconstruction.
One programme, several frameworks
Most frameworks overlap heavily. A single control set mapped to several frameworks avoids running parallel programmes for SOC 2, HIPAA and a customer’s security questionnaire, each demanding their own version of the same evidence.
What we do
The governance and compliance service
Risk assessment & gap analysis
A measured comparison of current state against your target framework, producing a prioritized remediation roadmap rather than an undifferentiated list of deficiencies.
Policy & procedure
Development and ongoing upkeep of the policy library, written to match how the organization actually operates so that staff can follow it and an assessor can verify it.
Compliance readiness
Preparation for SOC 2, HIPAA, PCI DSS, CMMC and others — control implementation, evidence design and pre-assessment review before an assessor is engaged.
Continuous control monitoring
Automated and scheduled checks that controls remain in force, with drift surfaced as it happens rather than discovered at the next assessment.
Third-party & vendor risk
Assessment and ongoing monitoring of the suppliers who hold your data or connect to your systems — increasingly the route by which incidents arrive.
Cyber insurance support
Application and renewal support, including the control attestations insurers now require. Answering these inaccurately is a coverage problem, not a paperwork problem.
Security questionnaires
Responses to customer due-diligence questionnaires on your behalf, drawn from the evidence repository so answers stay consistent between customers and over time.
Audit liaison
Working directly with your assessor or CPA firm, coordinating evidence requests and sampling so the burden does not land on your operational staff.
What you receive
A maintained risk register, policy library, evidence repository, remediation roadmap, compliance dashboard and audit-ready reporting.
Frameworks
What we work against
Our processes, controls and reporting align to recognized frameworks rather than to an internal invention. That alignment is what allows the same underlying work to satisfy an auditor, an insurer and a customer running due diligence.
Alignment and certification are different claims and we keep them distinct. Aligning a control set to a framework means the controls are designed against its criteria and the evidence is structured to match — it is the work that precedes an assessment. Certification is an opinion issued by an independent assessor after examining that evidence. We do the former and prepare you for the latter; we are not your auditor, and any provider offering both should prompt a question about independence.
For organizations in the federal supply chain, NIST SP 800-171 and CMMC deserve specific mention: the control requirements are prescriptive, the assessment regime has tightened, and the flow-down obligations reach subcontractors who often do not realize they are in scope. As a service-disabled veteran-owned small business we work in that lane ourselves, which is the context our vCISO and strategic advisory service brings to roadmap and budget planning.
Framework references: NIST Cybersecurity Framework 2.0, NIST SP 800-171 Rev. 3, and the CIS Critical Security Controls.
Mapping
How the catalog maps to NIST CSF 2.0
Every service we run maps to one or more of the six framework functions. This is what turns a service list into something measurable, and it is the structure we report against.
Risk strategy & oversight
vCISO and advisory, governance risk and compliance, vendor risk management, service reviews and executive reporting.
Know your assets and risks
Asset and lifecycle management, vulnerability and exposure management, SaaS and API discovery, risk assessments.
Reduce likelihood and impact
Patch and firmware, endpoint and MDM, identity and access, email and network security, awareness training, backup.
Find anomalies and attacks
Network and security monitoring, SIEM, managed detection and response, threat hunting, identity threat detection, dark web monitoring.
Contain and manage incidents
Incident response, containment and eradication, digital forensics, service desk remediation and stakeholder communications.
Restore operations and improve
Backup restore, disaster recovery failover, secure rebuild, post-incident review and corrective action plans.
Sequence
What the first year of a compliance programme looks like
Organizations usually arrive at compliance work with a deadline already attached — a customer contract conditional on an attestation, an insurer asking questions at renewal, or a prime contractor flowing requirements down. The sequence below is designed so that the early stages produce something useful even if the deadline moves.
Scope and baseline
Decide what is actually in scope — which systems, which data, which locations. Over-scoping is the most expensive early mistake and the hardest to unwind. The gap analysis then measures that scope against the target framework.
Prioritize the gaps
Findings are ranked by risk and by effort, not listed alphabetically. Some gaps are closed in an afternoon by changing a setting; others are projects. Separating the two is what makes the roadmap credible to a finance director.
Implement controls
The technical controls are largely the managed service itself — patching, access management, logging, backup, training. The compliance work is ensuring each one produces evidence in a form an assessor accepts.
Write the policies
Policies are written after the controls exist, not before, so they describe reality. Writing them first produces a library the organization immediately contradicts.
Accumulate evidence
Most frameworks require a period of operating effectiveness rather than a snapshot. This is the phase that cannot be compressed, which is why starting late is the single biggest driver of cost and stress.
Readiness and assessment
A pre-assessment review against the criteria, remediation of anything outstanding, then the independent assessment with us coordinating evidence requests and sampling.
Two honest cautions. The observation period is the constraint that most often forces a deadline to move, and no amount of effort shortens it — if a customer needs an attestation in ninety days and the framework requires six months of operating evidence, that conversation is better had at the start than at month five. And the risk register is only useful if it records accepted risks as deliberate decisions with an owner and a review date; a register listing only the things you intend to fix is a to-do list wearing a different name.
Questions we hear first
About governance, risk and compliance
Can you get us SOC 2 certified?
No provider can, and you should be wary of one that says otherwise. A SOC 2 report is issued by an independent CPA firm after they examine your controls. What we do is design the control set, implement it, run the evidence collection continuously and prepare you for the examination — which is the work that determines how the examination goes. We will not promise a particular outcome.
We only need to answer one customer’s questionnaire. Is this overkill?
Often the first questionnaire is not the last. If you are being asked once, you will likely be asked again, and inconsistent answers between customers create a problem of their own. Starting with a small maintained evidence set is usually cheaper than answering each questionnaire from scratch, and it costs little if the demand never grows.
Our policies were written years ago. Do they still count?
Only if they describe what the organization actually does. A policy library that contradicts practice is worse than none, because it documents a control failure in your own words and an assessor will test against what you wrote. Reconciling the two is usually the first piece of work.
What does cyber insurance have to do with this?
Insurers now require attestations about specific controls — multi-factor authentication coverage, backup immutability, endpoint detection, privileged access. Those attestations are underwriting representations, and answering them optimistically can affect a claim. We help you answer them from evidence rather than from memory.
Do we need this if we are small?
It depends on who your customers are and what data you hold, not on your headcount. A twelve-person business handling health information, card payments or federal contract data is in scope for the same obligations as a large one. The programme should be proportionate; the obligation does not scale with size.
How does this connect to the rest of the managed service?
Directly. The evidence a compliance programme needs — patch compliance, access reviews, restore tests, training records, change control — is produced as a by-product of running the managed service. Buying them separately means collecting the same evidence twice.
Start with a gap analysis
We measure current state against your target framework and return a prioritized roadmap with owners and effort, so you can decide what to fix, what to accept, and in what order.
Book a consultation →