Assurance

Prove your security to customers, auditors, insurers and investors, with tested controls, answered questionnaires and an evidence pack you can reuse.

Service Details

Cyber security assurance gives you the evidence to prove your security to the people who ask for it: customers, auditors, insurers and investors. We test whether your controls work, help you answer security questionnaires accurately and build an evidence pack you can reuse instead of starting from scratch each time.

Assurance is part of our strategy and advisory services, which cover the advice, planning and assurance behind your security decisions. Where those services help you decide what to do, assurance shows others that you have done it.

INFO

Falx is not a certification body or a CPA (Certified Public Accountant) firm. We do not issue ISO 27001 certificates or SOC 2 reports. We get you ready for the organisations that do, and give you evidence you can stand behind.


When someone asks you to prove it

A prospective customer sends a long security questionnaire. Your insurer wants confirmation that multi-factor authentication (MFA) is enforced everywhere. An investor’s adviser asks for your last penetration test. Each request lands on someone who already has a day job.

Assurance turns those requests into a routine. Your answers are checked against how your systems actually run, and the supporting evidence is ready before anyone asks for it.

Four colleagues gathered around a laptop reviewing security controls at a wooden table

What assurance covers

Evidence and testing for the audiences that judge your security:

Security Questionnaires

Accurate answers to customer and procurement questionnaires, backed by a library of approved responses.

Evidence Packs

A reusable set of policies, test summaries and certificates, ready to share or publish in a trust centre.

Cyber Insurance

Insurance proposal answers checked against your real configuration before you sign and submit them.

Supplier Assurance

Questionnaires and reviews of your own suppliers, so their weaknesses do not become your exposure.

Independent Control Testing

Sample-based testing that shows whether your controls operate as your policies say they do.

SOC 2 Readiness

Gap assessment and evidence preparation ahead of a SOC 2 audit by a licensed CPA firm.


Two professionals reviewing evidence documents together in a bright office

How we work

You get an honest picture of what you can prove today, then a plan to prove the rest.

  • Scope — We agree who needs the evidence, what they have asked for and which frameworks or questionnaires apply.
  • Test — We check your controls against your policies and the request, sampling records and configurations rather than taking answers on trust.
  • Report — You receive risk-rated findings, with clear notes on what you can claim now and what you cannot yet.
  • Package — We organise the evidence into a pack and answer library your teams can reuse for the next request.

Evidence shaped for each audience

A board, an insurer and a procurement team read the same controls differently. We present your evidence in the form each one expects, so it is understood the first time.

Customers

Questionnaire answers and a shareable evidence pack

Auditors and Insurers

Tested controls with sampled records behind them

Boards and Investors

A plain-English summary of risk and assurance gaps


Compliance support helps you meet a regulation or standard, from gap analysis through implementation to certification. Assurance starts from a different question: who needs proof, and can you give it to them? Many clients build controls with compliance support and use assurance to evidence them.

Security posture reviews give you a maturity baseline across the whole organisation. Assurance goes narrower and deeper, testing the specific controls an audience cares about. For investment deals, technical due diligence covers the buyer’s side; assurance prepares the company being assessed.

Services that work alongside

Assurance draws on evidence from other work. Penetration testing gives you independent test results to share, and risk management provides the risk register auditors and insurers expect to see. If a certificate is the goal, our ISO 27001 and Cyber Essentials services prepare you for the certification body. For boards that want regular, independent reporting, see board advisory.

Assurance requests are frequent in financial services, insurance and private equity backed businesses.


Frequently asked questions

Show them your security works

Tell us who is asking for proof, whether that is a customer, an insurer or an investor. We will tell you what evidence you already have, what is missing and how to close the gap.