Company details
Menu
WFH Labs / Cybersecurity & audit preparation

Understand what is required. Get the right safeguards in place.

A customer asks for security evidence. An audit is approaching. Your team needs to know which requirements apply to its systems and what work is still missing. We review the technical arrangements and help you prepare the changes and supporting records.

What we look at

  • The requirements or questionnaire you need to answer, and which systems they concern.
  • How access is granted and removed, how systems are maintained, and how recovery is arranged.
  • Whether written procedures match what people actually do.
  • Which records already support your answers, and which changes need an owner.

What you receive

  • A gap list linked to the requirements being reviewed.
  • A prioritised plan with responsible people and evidence needed for each item.
  • Technical input for customer questionnaires or audit preparation.
  • A review of agreed changes and the records that show they are in place.

Security in software delivery: what does DevSecOps mean?

DevSecOps means including security work in how software is designed, built, released and maintained. A practical review can cover code-review responsibilities, access to the build system, passwords and keys, third-party components, and what happens when a check finds a problem.

Adding a scanner only helps if findings reach someone who can assess and act on them. We can review the current workflow and agree a manageable set of changes with your engineering team.

NIST: Secure Software Development Framework ↗

Technical security and personal data

When a system handles personal data, we can help review access, data flows, backups and the technical arrangements supporting incident handling. The work can include documenting how selected safeguards operate.

This is the technical part of data protection. Questions about lawful processing, notices, contracts or legal reporting duties need the appropriate privacy or legal review.

A practical example

A questionnaire asks whether backups are tested. We check the recovery process and available test records, explain any gap and agree the work needed before the answer can be supported.

Illustrative example, not a claim about a completed client project.

Questions about this service

Can you help if we have very little documentation?

Yes. We start with the systems and working practices you have. The scope can include recording those practices and identifying the changes needed before documenting them as an established process.

Does this include NIS2 and ISO 27001?

We can review technical arrangements relevant to those requirements. We agree the applicable scope first and distinguish technical work from legal advice, organisational governance and certification.

Key terms

Next step / Start with your situation

You do not need to know the technical term.

Tell us what is happening, what it affects and when you need help. We’ll discuss whether we can help and what a useful first piece of work would be.