Skip to content
SEC

Security and compliance

Controls that survive an audit because they are enforced in the pipeline, not described in a document.

  • DORA
  • NIS2
  • ISO 27001
  • Threat modelling
  • Evidence automation
  • Access review
Code
SEC
Class
B · 6 to 11 months
Engagement
TYPICAL 4-9 MONTHS · FIXED-PRICE ASSESSMENT
Stages
05
Deliverables
06
Sections
06

Overview

Compliance work fails when the control lives in a policy document and the evidence is assembled by hand the week before an audit. We implement controls where they execute — in the build pipeline, the infrastructure definitions and the access model — so evidence becomes a by-product of running the system rather than a project of its own. Pillarstone closed 41 of 47 DORA readiness findings in a single quarter and went into their ISO 27001 surveillance audit with evidence pulled automatically.

Benefits

05 points
  • Evidence generated continuously by the systems themselves, so an audit request is a query rather than a fortnight of screenshots.

  • Controls enforced at deploy time. An unencrypted store, a publicly reachable bucket or an unreviewed dependency fails the build instead of appearing in next quarter’s report.

  • Threat models on the systems that matter, written down and revisited, so a security decision still has a recorded rationale when someone asks about it two years later.

  • Access that shrinks: joiner-mover-leaver automation and time-bound elevation, with quarterly recertification an owner can complete in under an hour.

  • Overlapping regimes implemented once. DORA, NIS2, ISO 27001 and SOC 2 share most of their control surface, so we build the control once and map its evidence to each framework that asks.

Workflow

05 stages
  1. Control and gap assessment

    Your obligations mapped against what is genuinely enforced today, separating controls that exist in a document from controls a system would stop you violating. The output is a findings register with severity, owner and effort.

  2. Threat modelling

    Structured modelling of the systems carrying the most risk — trust boundaries, abuse cases and the mitigations already in place — so remediation is prioritised against real attack paths rather than a generic checklist.

  3. Control implementation

    Policy as code in the pipeline and the infrastructure: encryption, egress restriction, dependency and secret scanning, and deployment approvals that cannot be granted by the person requesting them.

  4. Evidence automation

    Each control emits its own evidence — logs, attestations, pipeline records — collected into an audit-ready store with retention matched to the obligation it serves.

  5. Rehearse and hand over

    A mock audit run against the real evidence, plus breach-notification rehearsal against the statutory clocks, then handover to your security function with the findings still open for them to close.

Deliverables

06 items
  • Control gap register mapped to your applicable frameworks, with severity, owner and effort estimate.
  • Threat models for the highest-risk systems, versioned in-repo alongside the code they describe.
  • Policy-as-code guardrails enforced in CI and at deploy time, with documented break-glass procedures.
  • Automated evidence collection with retention aligned to each obligation.
  • Access model with joiner-mover-leaver automation and a quarterly recertification pack.
  • Mock audit findings and a breach-notification runbook rehearsed against statutory deadlines.

Questions

04 entries
  • We can get you ready and we work alongside your auditor, but we cannot certify you. Certification comes from an accredited body, and any consultancy claiming to deliver it is describing something else. What we do is implement and evidence the controls, then run a mock audit against the real evidence so the certification audit contains no surprises.

  • Whichever one is legally binding for you, then map the rest onto it, because the overlap is large. A European financial entity starts with DORA. An operator of essential services starts with NIS2. An organisation selling to enterprises usually needs ISO 27001 or SOC 2 commercially. We implement each control once and map its evidence to every framework that asks for it.

  • Badly implemented ones will, which is why we put them in the pipeline rather than in a review board. A scan that fails a build in ninety seconds costs less than a security review that queues for a week, and it catches more. Pillarstone’s median deployment lead time was unchanged after implementation, while the pre-deployment review queue disappeared.

  • They get compensating controls and a dated remediation plan, which is what auditors expect for systems that genuinely cannot be brought up to standard. We record what the residual risk is, who accepted it and when it is next reviewed. An accepted and documented risk is defensible; an undocumented one is a finding.

Start a project

02 locations

Enterprise systems consultancy

  • Manchester, United Kingdom
  • Oslo, Norway