Skip to content
  1. Home
  2. What we do
  3. Compliance & Risk

Managed GCC

Compliance & Risk

Auditors do not accept intentions. Every control needs an artefact, and producing those at audit time is how organisations lose two months.

Compliance work goes wrong in a predictable way. The framework is treated as a document exercise, controls are written to sound right, and then the evidence has to be assembled retrospectively under time pressure - at which point everyone discovers which controls were aspirational.

Controls that produce evidence

We design each control so that operating it generates its own artefact automatically. Access reviews that produce a signed record. Patch reports that are archived monthly. Backup tests that log their results. When the audit arrives, the evidence already exists.

Mapping once, satisfying many

Most organisations face several overlapping frameworks. The underlying controls are largely the same, so we map them once and produce framework-specific views from a single control set rather than running parallel programmes.

Cyber insurance

Insurers now underwrite on specific technical controls, and a questionnaire answered optimistically can void a claim. We answer it accurately, and where a control is genuinely absent we tell you what it costs to close before you sign.

Gap assessment first

We begin with an honest gap assessment against the target framework, sorted by effort and risk. Some gaps close in a fortnight; others are structural and need a budget conversation. Knowing which is which early is most of the value.

Sustaining it

Certification is a moment; compliance is a state. We run the recurring calendar - access reviews, policy attestation, vendor assessments, penetration testing - so the next audit is a collection exercise rather than a project.

What is included

  • Gap assessment

    Honest scoring against the target framework, sorted by effort and by risk.

  • Self-evidencing controls

    Designed so that operating the control produces the artefact automatically.

  • Multi-framework mapping

    One control set, several framework views - instead of parallel programmes.

  • Insurance questionnaires

    Answered accurately, with the cost of closing any genuine gap stated before you sign.

Common questions

Before you ask

No. Most engagements start with either an assessment or a co-managed arrangement where we take tickets and after-hours while your team keeps everything else. Expanding from there is a decision you make with two quarters of evidence rather than a sales promise.

Per user per month for the recurring service, with servers and sites priced separately. Project work, migrations and hardware are quoted individually so the monthly fee never becomes the place surprise costs hide.

A dedicated offshore team working only for you, in an entity we set up and run to your standards. It is not a shared outsourcing pool - the people are yours, and if you want to own the entity eventually, the transfer date goes in the contract up front.

Below roughly 50 seats the governance overhead usually eats the saving. Between 50 and 150 it works if the work is coherent enough to justify dedicated leadership. Above 150 the economics are almost always favourable if retention holds.

Frequently, and it is one of the arrangements that works best. We agree a written split of responsibilities before starting so nothing lands in the gap between two teams, and we work inside your ticketing system rather than making you adopt ours.

Ready to find out what your IT is really costing you?

A 45-minute working session gets you an honest read on estate health, security posture, and the two or three changes that would pay for themselves first.