Security and compliance
ISO 27001 and Cyber Essentials readiness
ISO 27001 is the international standard for information security management; Cyber Essentials and Cyber Essentials Plus are the UK government-backed baseline controls. Readiness work builds the technical controls, policies and evidence needed to certify. Hexploits delivers the engineering side: access, devices, patching, logging, backups and secure development, mapped to the standard and evidenced for the auditor.
A named engineer replies within one working day. A written scope and an indicative price within two.
Who this is for
- Businesses told by a customer or tender that certification is required.
- IT directors preparing for a first certification or a renewal.
- Vendors selling into regulated firms who audit their suppliers.
What you get
Deliverables, not slogans. Each one appears in the statement of work.
- A gap analysis against the chosen standard with a prioritised plan.
- Technical controls implemented: identity and MFA, device management, patching, logging, backups, network and cloud configuration.
- Policies and procedures written to reflect how you actually operate.
- An evidence pack organised by control for the auditor.
- Support during the assessment.
Our engineers work across the major languages, frameworks and cloud platforms. We build on the stack you already run, with technology choices explained in writing before work begins.
How it is delivered
The same four stages as every Hexploits engagement, applied to this capability.
Stage 1
Gap analysis
Current state against every control, with the effort to close each gap.
Stage 2
Implement
Controls built into systems and processes, not written into a binder.
Stage 3
Evidence
Screenshots, logs, records and policies collected as the controls run.
Stage 4
Assess and maintain
Support during the audit, then ongoing maintenance of controls under managed support.
How success is measured
Every engagement agrees its measures and the measurement period in writing before work starts.
- Certification achieved, or a dated plan to it.
- Controls evidenced continuously rather than annually.
- Supplier questionnaires answered from the evidence pack.
Proof
Case studies with numbers, and reviews linked to Google where they were left there.
swarmd.ai · Software vendor · 6 months
Enterprise AI control plane delivered in six months at 75% under budget for a UK software vendor
Gradvisor · Charity · 8 weeks to production, then ongoing
98% faster page loads and a 12% smaller cloud bill for a UK careers charity
Director, IO Solutions
“Fantastic to work with. High level of attention to detail and flawless communication throughout. Would recommend to anyone looking to develop or improve a software product.”

Director, Lothbury
“Top quality delivery, and reasonable price. Will be using again.”

Questions we get asked
Do you certify us?
Which should we do first, Cyber Essentials or ISO 27001?
Does Hexploits hold these certifications?
Related
Sectors where this is most often needed
More in security and compliance
Security architecture review
Identity and access management
Penetration test remediation
Data protection engineering
AI system security
Consumer Duty and FCA evidence engineering
Candidate data: one record, one chain of custody
Enterprise readiness for start-ups: SSO, audit trails, tenant isolation and the security questionnaire
Next step
Request a proposal.
Tell us about the system and the sector. A named engineer replies within one working day. A written scope and an indicative price within two working days of a short scoping call.