Skip to content
Lorendix

Cybersecurity · Governance and compliance

Certification as a by-product of how you already operate

ISO 27001, SOC 2, Cyber Essentials, DORA and NIS2, implemented as controls that run and produce their own evidence. The aim is that an audit becomes a report from the system rather than a project that stops delivery.

Where this starts

Compliance costs the most in the wrong places

The expensive part of certification is rarely the certificate. It is the six weeks beforehand when engineers stop delivering and start collecting screenshots, the sales cycles held up by a questionnaire nobody owns, and the controls that are genuine for one month a year. Auditors are not the problem. Evidence that has to be manufactured rather than produced is the problem.

What we usually find

  • Evidence gathered by hand in the weeks before an audit, then discarded
  • Policies written to satisfy a standard and unrecognisable to the teams they describe
  • A risk register maintained for the auditor rather than used for decisions
  • Security questionnaires answered from scratch each time by whoever happens to be free
  • Controls owned by a security function that only engineering can actually operate
  • Two or three frameworks implemented separately over the same underlying controls

Our position

A control that only holds during audit season is not a control. It is a performance, and everyone involved knows it.

What the work covers

Implementation, not interpretation

Plenty of firms will tell you what a clause requires. The work that changes anything is turning the clause into something that runs, owned by someone who is not surprised to have it.

One control set, mapped outward

ISO 27001, SOC 2, Cyber Essentials Plus and PCI DSS overlap heavily. We implement a single set of controls and map it to each framework, so a second certification is an evidence exercise rather than a second programme with a second budget.

Policy that matches practice

Policies written from what teams actually do, versioned in the repository alongside the systems they govern. A policy nobody follows is an audit finding that has not been written down yet.

Risk management that informs decisions

A register scoped to real business impact, reviewed on a cadence tied to change rather than to the calendar, with treatment decisions recorded where the engineering work is actually planned.

Third party and supply chain risk

Proportionate due diligence, concentration risk made visible, and contractual security requirements that match what you are able to monitor. This is increasingly the sharp end of assessment under DORA and NIS2.

Sector regimes

DORA for financial entities, NIS2 for essential and important entities, and UK GDPR throughout. We establish what applies, what it means operationally, and what genuinely has to change, which is usually less than a vendor will tell you and more than you hoped.

Customer assurance

A maintained questionnaire answer library and a trust page, so a security review shortens a sales cycle instead of stalling it for a fortnight.

How it stays fixed

Evidence the system produces

The measure of a good compliance programme is how little anyone has to do in the month before the audit.

Mapping
One control, many frameworks, so evidence collected once satisfies every standard it maps to and nobody collects the same artefact twice.
Collection
Evidence pulled from systems of record on a schedule: access reviews, change approvals, scan results, training completion. Dated, attributable and stored, rather than screenshotted.
Policy as code
Technical controls asserted by the pipeline, so the statement in the policy and the behaviour of the estate cannot diverge without something visibly failing.
Exceptions
Time limited, owned and visible, which is what makes an exception process credible to an auditor rather than a documented route around the control.
Reporting
A standing view of control health for the board built from the same underlying data as the audit pack, so there is only ever one version of the truth to defend.

What you are left holding

  • A single control set mapped to every framework you are asked about
  • Evidence collected automatically, dated and attributable
  • Policies your engineers recognise as a description of their own work
  • A questionnaire answer library that shortens security reviews
  • A board report produced from the same data as the audit pack

Tell us which certification is blocking a deal

We will tell you what is genuinely missing, what you already satisfy and have simply never evidenced, and how long the real gap takes to close.