Security Audits & Compliance
Pass the security audit your client just asked for.
A security questionnaire from an enterprise client. Cyber Essentials Plus as a condition of a contract. An insurer asking for proof. We take Mac-first businesses from that email to a passed audit: gap analysis, remediation, evidence, and the certificate. We hold Cyber Essentials Plus ourselves and take clients through the same process we passed.
Why This Lands On Your Desk
Security proof is now part of winning work
The audit request rarely comes from inside. It comes from the people you want to say yes to you.
Enterprise procurement
Bigger clients audit their suppliers before a contract is signed. A security questionnaire or a Cyber Essentials requirement is standard in UK enterprise and public-sector procurement, and "we'll sort it later" loses the deal.
Insurers
Cyber insurance applications now ask for specifics: MFA coverage, endpoint protection, update management. Weak answers mean higher premiums or refused cover, and a false answer can void a claim.
Your own clients' auditors
If you handle client data, media, or pre-release content, their security team's standards become yours. Creative and production businesses meet this the moment a broadcaster or studio reviews them.
How It Works
From questionnaire to certificate
Cyber Essentials Plus typically runs 4 to 8 weeks from gap analysis to certificate. You don't sit the audit until the gap analysis says you'll pass.
Gap analysis
We audit your estate against the standard you're facing: Cyber Essentials Plus, a client questionnaire, or an insurer's requirements. You get a written report: what passes today, what fails, and what each fix involves.
Remediation
We fix the gaps in priority order: MDM-enforced encryption and screen lock, MFA on every account, firewall and secure configuration, update management, and access control. Staged rollouts, no downtime.
Evidence
Auditors accept proof, not promises. We gather the evidence as we go: policy screenshots, MDM compliance reports, and the documentation an assessor or procurement team expects to see.
Assessment and pass
We book the audit only when the gap analysis says you'll pass, sit alongside you through it, and handle any assessor questions. Then the certificate does its job: winning you the client.
Documented Result
Phishing-resistant MFA across a ~110-person company, enforced in under two weeks
An AI software company's enterprise customer required phishing-resistant MFA before a contract. We enforced it across their entire Google Workspace and GitHub estate with Okta and hardware-bound Okta Verify FastPass: no password to steal, no code to relay, a biometric on every sign-in.
Read the full case study100%
of in-scope staff on phishing-resistant MFA
<2 wks
from kickoff to full enforcement
196
Google and GitHub identities secured
AAL3
NIST authenticator assurance met
What Gets Fixed
The controls auditors check, in Mac terms
Audit frameworks are written Windows-first. We translate every control into how a managed Apple estate proves it, so the assessor sees compliance instead of a platform they don't recognise. Managed through Jamf, evidenced automatically by the Stabilise Platform.
Need the ongoing discipline rather than a one-off pass? That's our Enterprise Security service.
- MFA enforced on every account, phishing-resistant where the requirement demands it
- Full-disk encryption (FileVault) enforced and escrowed through MDM
- Firewall, secure configuration, and screen-lock policy applied fleet-wide
- Managed software updates with compliance reporting
- Endpoint protection with central visibility
- Access control: joiners, leavers, and admin rights done properly
- The written policies and evidence pack assessors ask for
FAQ
Security audit questions, answered
A client sent us a security questionnaire. Where do we start?
Start by separating what you already satisfy from what needs work, before you answer a single question. We run a gap analysis against the questionnaire itself, answer honestly on your behalf where you already pass, and give you a remediation plan with timescales for the rest. Answering "yes" to controls you don't have is the one thing you must not do: enterprise clients audit their suppliers, and a false answer discovered later does far more damage than a remediation plan submitted up front.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a self-assessment against the UK government scheme's five control areas. Cyber Essentials Plus covers the same controls but adds an independent technical audit: an assessor verifies your firewalls, secure configuration, access control, malware protection, and update management are really in place. Enterprise clients and insurers increasingly ask for Plus specifically because it is verified rather than self-declared.
Does an all-Mac office make an audit easier or harder?
Easier in substance, harder in paperwork. macOS gives you strong foundations: FileVault encryption, Gatekeeper, and rapid security updates. But most audit frameworks and assessors are written Windows-first, so the evidence needs translating: proving MDM-enforced disk encryption, screen-lock policy, and update compliance in Mac terms. That translation is exactly the work we do, and why Mac-first businesses come to us rather than a generalist.
How long does audit readiness take?
Cyber Essentials Plus typically takes 4 to 8 weeks from gap analysis to certificate, depending on how much remediation your environment needs. A phishing-resistant MFA rollout can be enforced across a whole organisation in under two weeks, as our case study shows. A client security questionnaire can usually be answered credibly within days once we know your estate.
What happens if we fail the audit?
You don't sit the audit until you're ready to pass it. The gap analysis tells us exactly which controls would fail today, we fix those first, and we only book the assessment once the evidence is in place. That is why most of our clients pass first time. If an assessor does flag something, remediation windows exist within the schemes and we handle the fix and re-test.
Will getting audit-ready disrupt the team?
Most of the work is invisible to your staff: MDM policy, firewall configuration, update enforcement, and evidence gathering happen in the background. The visible parts, like MFA enrolment, are rolled out in stages with clear instructions rather than switched on overnight. Your team keeps working throughout.
Find out where you'd fail, before the assessor does
A free 30-minute audit of your setup against the standard you're facing, followed by a written gap report. No obligation, no sales pitch.