IT security assurance / Appleby Systems

Know whether your IT security is fit for purpose.

An independent view of the controls around your business, the important gaps, what deserves attention first and whether the measures already in place are doing the job you expect.

Support and assurance are different jobs.

Your IT provider may know your environment well and manage it effectively. Leadership still needs a way to establish whether the important controls are in place, whether responsibility is clear and whether the current level of protection makes sense for the business.

My role is to give you that independent view in business terms. The point is not to produce a long list of technical observations. It is to identify the things that materially affect risk, explain why they matter and set a sensible order for dealing with them.

Look at the whole operating picture, not a single product.

The review can cover the areas that are relevant to your business, including Microsoft 365 and identity, access and permissions, endpoints, backups and recovery, supplier dependencies, remote working, security responsibilities, policies and the evidence available to management.

The scope is agreed before work starts. If there are areas that are already well managed, the review should say so rather than finding work for the sake of it.

The output should help you make decisions.

I can work with your existing IT provider.

This is not an attempt to replace the team that supports your users and systems. They often hold important operational knowledge and are usually the right people to implement agreed improvements.

I provide the independent assessment, help the business decide what it wants to achieve and can stay involved while the remediation work is carried out. That gives management a clearer line between day-to-day support and assurance.

Common reasons for an independent review.

  • A client, insurer or board is asking for better evidence.
  • The business has changed significantly since its security arrangements were designed.
  • Microsoft 365, access or remote working has grown organically.
  • There is uncertainty about backups, recovery or ransomware readiness.
  • A recent incident or near miss has raised questions.
  • You simply want to know whether the money already being spent is addressing the right things.