Assurance
Prove your security to customers, auditors, insurers and investors, with tested controls, answered questionnaires and an evidence pack you can reuse.
Service Details
Cyber security assurance gives you the evidence to prove your security to the people who ask for it: customers, auditors, insurers and investors. We test whether your controls work, help you answer security questionnaires accurately and build an evidence pack you can reuse instead of starting from scratch each time.
Assurance is part of our strategy and advisory services, which cover the advice, planning and assurance behind your security decisions. Where those services help you decide what to do, assurance shows others that you have done it.
INFO
Falx is not a certification body or a CPA (Certified Public Accountant) firm. We do not issue ISO 27001 certificates or SOC 2 reports. We get you ready for the organisations that do, and give you evidence you can stand behind.
When someone asks you to prove it
A prospective customer sends a long security questionnaire. Your insurer wants confirmation that multi-factor authentication (MFA) is enforced everywhere. An investor’s adviser asks for your last penetration test. Each request lands on someone who already has a day job.
Assurance turns those requests into a routine. Your answers are checked against how your systems actually run, and the supporting evidence is ready before anyone asks for it.

What assurance covers
Evidence and testing for the audiences that judge your security:
Security Questionnaires
Accurate answers to customer and procurement questionnaires, backed by a library of approved responses.
Evidence Packs
A reusable set of policies, test summaries and certificates, ready to share or publish in a trust centre.
Cyber Insurance
Insurance proposal answers checked against your real configuration before you sign and submit them.
Supplier Assurance
Questionnaires and reviews of your own suppliers, so their weaknesses do not become your exposure.
Independent Control Testing
Sample-based testing that shows whether your controls operate as your policies say they do.
SOC 2 Readiness
Gap assessment and evidence preparation ahead of a SOC 2 audit by a licensed CPA firm.

How we work
You get an honest picture of what you can prove today, then a plan to prove the rest.
- Scope — We agree who needs the evidence, what they have asked for and which frameworks or questionnaires apply.
- Test — We check your controls against your policies and the request, sampling records and configurations rather than taking answers on trust.
- Report — You receive risk-rated findings, with clear notes on what you can claim now and what you cannot yet.
- Package — We organise the evidence into a pack and answer library your teams can reuse for the next request.
Evidence shaped for each audience
A board, an insurer and a procurement team read the same controls differently. We present your evidence in the form each one expects, so it is understood the first time.
Customers
Questionnaire answers and a shareable evidence pack
Auditors and Insurers
Tested controls with sampled records behind them
Boards and Investors
A plain-English summary of risk and assurance gaps
How assurance differs from related services
Compliance support helps you meet a regulation or standard, from gap analysis through implementation to certification. Assurance starts from a different question: who needs proof, and can you give it to them? Many clients build controls with compliance support and use assurance to evidence them.
Security posture reviews give you a maturity baseline across the whole organisation. Assurance goes narrower and deeper, testing the specific controls an audience cares about. For investment deals, technical due diligence covers the buyer’s side; assurance prepares the company being assessed.
Services that work alongside
Assurance draws on evidence from other work. Penetration testing gives you independent test results to share, and risk management provides the risk register auditors and insurers expect to see. If a certificate is the goal, our ISO 27001 and Cyber Essentials services prepare you for the certification body. For boards that want regular, independent reporting, see board advisory.
Assurance requests are frequent in financial services, insurance and private equity backed businesses.
Frequently asked questions
Show them your security works
Tell us who is asking for proof, whether that is a customer, an insurer or an investor. We will tell you what evidence you already have, what is missing and how to close the gap.