Compliance & Business Continuity
GDPR, ISO 27001 and NIS2 readiness with backup and disaster recovery plans that have been tested.
Compliance and continuity are the same problem from two sides: proving you control your systems and proving you can recover them. We run gap analyses against the frameworks that apply to you, write the policies that close the gaps and build the recovery plan that makes the policies true.
Everything is tested. A disaster recovery plan that has never been rehearsed is a document, not a plan.
- Policies are written by people who also run infrastructure, so they describe what can actually be done.
- Recovery objectives are agreed with the business, not assumed by IT.
- The tabletop exercise is included, not an optional extra.
- An energy, transport or logistics operator brought into scope by NIS2 with a board that wants a plain answer.
- A supplier to banks or airlines asked for ISO 27001 evidence before the next contract renewal.
- A group whose recovery plan was written for a data centre it no longer has.
- A customer questionnaire arrived and the answers had to be written from scratch.
- Policies exist but describe a process nobody follows.
- Recovery objectives have never been agreed with the business.
- The last restore test is older than the last major system change.
What is included.
- 01
Gap analysis
Controls assessed against GDPR, ISO 27001, NIS2 or the framework your customers demand.
- 02
Policy set
Practical policies and procedures written for your organisation, not copied from a template.
- 03
Backup architecture
Backups designed for recovery objectives, immutability and offsite copies.
- 04
Disaster recovery plan
Recovery priorities, procedures, contacts and communication plans.
- 05
Tabletop exercise
A facilitated rehearsal of a realistic outage with lessons captured.
Four steps, no surprises.
- 01
Scope
Confirm which frameworks apply and what the business must protect.
- 02
Assess
Gap analysis and business impact analysis.
- 03
Build
Policies, backup changes and the recovery plan.
- 04
Test
Tabletop exercise, restore tests and a remediation plan.
From first meeting to steady state.
- 01Weeks 1 to 4
Scope and assess
Frameworks confirmed, gap analysis and business impact analysis completed.
- 02Weeks 5 to 9
Build
Policies written, backup architecture changed and the recovery plan drafted with owners.
- 03Weeks 10 to 12
Test
Tabletop exercise, restore tests and a remediation plan agreed.
- Gaps closed against the chosen framework, tracked to zero.
- Recovery time and recovery point achieved in rehearsal against the agreed objectives.
- Time to answer a customer or regulator questionnaire.
- Findings raised at certification and surveillance audits.
- Lead compliance consultant
- Infrastructure engineer
- Business continuity specialist
- Engagement director
- Gap analysis report.
- Policy and procedure set.
- Backup and recovery architecture.
- Disaster recovery plan.
- Tabletop exercise report.
Readiness projects are fixed scope and take six to twelve weeks depending on framework and organisation size. Annual maintenance of policies, evidence and exercises is available on a light retainer.
Compliance & Governance (ISO 27001, SOC 2, NIS2, GDPR)
Gap assessment, policy writing and audit preparation across the frameworks your customers demand.
CybersecurityIncident Response Readiness & Retainer
An incident response plan, rehearsed with tabletop exercises, and an on-call retainer for when it happens.
IT ConsultingManaged IT & Support
Proactive monitoring, help desk and infrastructure management under a service level you can hold us to.
Compliance & Business Continuity, in plain terms.
It depends on sector, size and whether you supply an in-scope organisation. We check this in the first session and give a clear answer.
We prepare you for certification and support you through the audit. The certificate itself is issued by an accredited body.
Restore tests monthly and a full tabletop at least annually, or after any major change.
Backup is a copy of data. Disaster recovery is the plan and infrastructure to run the business again within an agreed time. You need both.