Governance & Accountability
Board-level cyber accountability, policy framework, and security investment
Risk Management
Risk registers, assessments, third-party risk, and asset classification
Asset Management
Hardware/software inventory, attack surface visibility, and data classification
Identity & Access Management
MFA, least privilege, PAM, joiner/mover/leaver, access reviews
Data Protection & Privacy
UK GDPR, ICO registration, encryption, retention, and DPIAs
Network & Infrastructure Security
Firewalls, segmentation, VPN/zero-trust, monitoring, and OT/IT separation
Endpoint & Device Security
EDR, MDM, encryption, automated patching, and removable media controls
Vulnerability & Patch Management
Scanning, penetration testing, patch SLAs, remediation, and SCA
Incident Detection & Response
IR plans, SOC capability, breach history, tabletop exercises, and escalation
Business Continuity & Disaster Recovery
BC/DR plans, backup integrity, RTO/RPO, testing, and ransomware readiness
Supply Chain & Third-Party Risk
Supplier inventory, due diligence, certification requirements, monitoring, and contractual controls
Security Awareness & Training
All-staff training, phishing simulation, role-specific training, security culture, and onboarding
Secure Development & Change Management
SSDLC, code review, change management, environment separation, and source code security
Compliance & Regulatory Alignment
Certifications, sector regulations, enforcement history, cyber insurance, and audits