Case study · Telecoms infrastructure

Evidence that stood up when the assessors returned

CyPro helped FreshWave build security the business could keep operating, so ISO 27001 and Cyber Essentials Plus stood up to inspection and won public sector work.

Client

FreshWave

FreshWave logo

Outcome

ISO 27001 and Cyber Essentials Plus opened the public sector door

A market that checks twice

FreshWave’s public sector prospects wanted certification before they would contract, and in this market certification is never a one-off event. Cyber Essentials Plus is reassessed every year, ISO 27001 brings surveillance audits, and a security posture assembled for a single assessment date tends to be found out at the next one, at exactly the moment a contract depends on it.

Hardening built into routine

A senior CyPro practitioner shaped FreshWave’s controls around what the business could genuinely keep doing. Systems were hardened as engineering work rather than as recommendations left in a report, and the evidence assessors needed grew out of normal operations instead of a scramble before each audit. The certifications followed, and with them the public sector wins the company was after.

What certification evidence rests on

Both of FreshWave’s certifications lean on demonstrable vulnerability management. A Cyber Essentials Plus assessor scans the systems in scope and expects the results to hold up, and ISO 27001 asks, through control A.8.8, for evidence that technical vulnerabilities are identified, evaluated and dealt with. Neither is satisfied by a tidy document set. They are satisfied by a scanning cadence with findings triaged, fixed and recorded, month after month, which is precisely the routine a managed scanning service leaves running between audits. FreshWave’s engagement went wider than scanning, but the principle it proves is the one a scanning buyer should hold onto: the evidence you show an assessor is a by-product of vulnerability work you actually do, and it is worth very little produced any other way.

"Their new ISO 27001 and Cyber Essentials Plus certifications won them more public sector work."
Tom Bennett , CTO, FreshWave
Rocket above the Managed Vulnerability Scanning call to action

See what your attackers see

Find out what a scan of your estate would actually surface

The scoping call is free, lasts 45 minutes and is taken by a consultant, not a salesperson. It covers the scanner you already run, what your estate exposes, and exactly what having the whole process managed would cost per month.