Governance and risk
The SRA expects effective governance structures, arrangements, systems and controls (Code of Conduct for Firms, paragraph 2.1). We supply the technical risk inputs and evidence that the controls work.
IT supplier oversight
Due diligence before you appoint, clear contract terms and ongoing supervision. We expect to be assessed and provide our certificate, scope and control information.
Contract terms
Security obligations, review and audit rights, incident notification, subcontractor controls and data return. We will work through these terms with you.
Protective controls
Multi-factor authentication, Conditional Access, device management, patching, encryption, backup and training, reported monthly.
Incident readiness
Cyber incidents that affect clients should be reported to the SRA promptly, and personal data breaches to the ICO within 72 hours where feasible. We help you agree who decides, rehearse the process and keep the logs you will need.
Evidence
A standing evidence pack for the SRA, insurers and client audits, so a request takes minutes rather than days.