Skip to content

Security and compliance

ISO 27001 and Cyber Essentials readiness

ISO 27001 is the international standard for information security management; Cyber Essentials and Cyber Essentials Plus are the UK government-backed baseline controls. Readiness work builds the technical controls, policies and evidence needed to certify. Hexploits delivers the engineering side: access, devices, patching, logging, backups and secure development, mapped to the standard and evidenced for the auditor.

A named engineer replies within one working day. A written scope and an indicative price within two.

  • Businesses told by a customer or tender that certification is required.
  • IT directors preparing for a first certification or a renewal.
  • Vendors selling into regulated firms who audit their suppliers.

Deliverables, not slogans. Each one appears in the statement of work.

  • A gap analysis against the chosen standard with a prioritised plan.
  • Technical controls implemented: identity and MFA, device management, patching, logging, backups, network and cloud configuration.
  • Policies and procedures written to reflect how you actually operate.
  • An evidence pack organised by control for the auditor.
  • Support during the assessment.

Our engineers work across the major languages, frameworks and cloud platforms. We build on the stack you already run, with technology choices explained in writing before work begins.

The same four stages as every Hexploits engagement, applied to this capability.

  1. Stage 1

    Gap analysis

    Current state against every control, with the effort to close each gap.

  2. Stage 2

    Implement

    Controls built into systems and processes, not written into a binder.

  3. Stage 3

    Evidence

    Screenshots, logs, records and policies collected as the controls run.

  4. Stage 4

    Assess and maintain

    Support during the audit, then ongoing maintenance of controls under managed support.

Every engagement agrees its measures and the measurement period in writing before work starts.

  • Certification achieved, or a dated plan to it.
  • Controls evidenced continuously rather than annually.
  • Supplier questionnaires answered from the evidence pack.

Case studies with numbers, and reviews linked to Google where they were left there.

  • Director, IO Solutions

    Fantastic to work with. High level of attention to detail and flawless communication throughout. Would recommend to anyone looking to develop or improve a software product.

    Christian LorzaDirector, IO SolutionsRead the review
  • Director, Lothbury

    Top quality delivery, and reasonable price. Will be using again.

    Peter DentonDirector, LothburyRead the review
Do you certify us?
No. Certification is by an accredited body. We do the engineering and evidence work so that the assessment passes.
Which should we do first, Cyber Essentials or ISO 27001?
Cyber Essentials Plus is faster and is often what a customer actually asked for. ISO 27001 is broader and is expected in regulated supply chains. The gap analysis recommends a sequence.
Does Hexploits hold these certifications?
Not today. We build to ISO 27001-aligned controls and do the readiness engineering for clients; we do not claim a certificate we do not hold. Our insurance, security practices and subprocessors are on the trust page.

Request a proposal.

Tell us about the system and the sector. A named engineer replies within one working day. A written scope and an indicative price within two working days of a short scoping call.