Security and compliance
Controls that survive an audit because they are enforced in the pipeline, not described in a document.
- DORA
- NIS2
- ISO 27001
- Threat modelling
- Evidence automation
- Access review
- Code
- SEC
- Class
- B · 6 to 11 months
- Engagement
- TYPICAL 4-9 MONTHS · FIXED-PRICE ASSESSMENT
- Stages
- 05
- Deliverables
- 06
- Sections
- 06
Overview
Compliance work fails when the control lives in a policy document and the evidence is assembled by hand the week before an audit. We implement controls where they execute — in the build pipeline, the infrastructure definitions and the access model — so evidence becomes a by-product of running the system rather than a project of its own. Pillarstone closed 41 of 47 DORA readiness findings in a single quarter and went into their ISO 27001 surveillance audit with evidence pulled automatically.
Benefits
05 pointsEvidence generated continuously by the systems themselves, so an audit request is a query rather than a fortnight of screenshots.
Controls enforced at deploy time. An unencrypted store, a publicly reachable bucket or an unreviewed dependency fails the build instead of appearing in next quarter’s report.
Threat models on the systems that matter, written down and revisited, so a security decision still has a recorded rationale when someone asks about it two years later.
Access that shrinks: joiner-mover-leaver automation and time-bound elevation, with quarterly recertification an owner can complete in under an hour.
Overlapping regimes implemented once. DORA, NIS2, ISO 27001 and SOC 2 share most of their control surface, so we build the control once and map its evidence to each framework that asks.
Workflow
05 stagesControl and gap assessment
Your obligations mapped against what is genuinely enforced today, separating controls that exist in a document from controls a system would stop you violating. The output is a findings register with severity, owner and effort.
Threat modelling
Structured modelling of the systems carrying the most risk — trust boundaries, abuse cases and the mitigations already in place — so remediation is prioritised against real attack paths rather than a generic checklist.
Control implementation
Policy as code in the pipeline and the infrastructure: encryption, egress restriction, dependency and secret scanning, and deployment approvals that cannot be granted by the person requesting them.
Evidence automation
Each control emits its own evidence — logs, attestations, pipeline records — collected into an audit-ready store with retention matched to the obligation it serves.
Rehearse and hand over
A mock audit run against the real evidence, plus breach-notification rehearsal against the statutory clocks, then handover to your security function with the findings still open for them to close.
Deliverables
06 items- Control gap register mapped to your applicable frameworks, with severity, owner and effort estimate.
- Threat models for the highest-risk systems, versioned in-repo alongside the code they describe.
- Policy-as-code guardrails enforced in CI and at deploy time, with documented break-glass procedures.
- Automated evidence collection with retention aligned to each obligation.
- Access model with joiner-mover-leaver automation and a quarterly recertification pack.
- Mock audit findings and a breach-notification runbook rehearsed against statutory deadlines.
Questions
04 entriesWe can get you ready and we work alongside your auditor, but we cannot certify you. Certification comes from an accredited body, and any consultancy claiming to deliver it is describing something else. What we do is implement and evidence the controls, then run a mock audit against the real evidence so the certification audit contains no surprises.
Whichever one is legally binding for you, then map the rest onto it, because the overlap is large. A European financial entity starts with DORA. An operator of essential services starts with NIS2. An organisation selling to enterprises usually needs ISO 27001 or SOC 2 commercially. We implement each control once and map its evidence to every framework that asks for it.
Badly implemented ones will, which is why we put them in the pipeline rather than in a review board. A scan that fails a build in ninety seconds costs less than a security review that queues for a week, and it catches more. Pillarstone’s median deployment lead time was unchanged after implementation, while the pre-deployment review queue disappeared.
They get compensating controls and a dated remediation plan, which is what auditors expect for systems that genuinely cannot be brought up to standard. We record what the residual risk is, who accepted it and when it is next reviewed. An accepted and documented risk is defensible; an undocumented one is a finding.
Start a project
02 locationsEnterprise systems consultancy
- Manchester, United Kingdom
- Oslo, Norway