Why we publish our own gaps
We hold data about your systems. Here is our own security posture, and honestly, what we have not fixed yet.
It would be easy to write a page claiming we are flawless, and you would be right not to believe it. We hold information about your systems, so you are entitled to know how we look after our own - not the polished version, the real one, including the parts that are still on our list. A security company that pretends it has no gaps is telling you the one thing that should worry you most.
So here is the honest shape of it. The controls we tell you to have, we have: named logins for everyone, multi-factor authentication on every account, encrypted laptops, automatic updates, and backups we actually test on a schedule rather than assume. We hold Cyber Essentials and we mean it, not as a badge for the website but as a floor we do not drop below. That is the part we are comfortable standing behind in public.
And here is what is not finished. There are older records we have not yet reviewed for how long we still need to keep them, a supplier or two whose own security we are still assessing properly, and a couple of internal processes that rely more on the right person remembering than on a system enforcing it. None of it is on fire. All of it is the kind of thing that, left unwritten, quietly becomes tomorrow's incident.
We publish this for two reasons. The first is that you deserve to judge us on the same terms we judge others - if we would flag a leaver's live account in your business, you should be able to see how quickly we close ours. The second is that writing our gaps down is how they get fixed, because a gap on a public list has a way of getting attention that a private worry never does.
If any of the above changes your mind about trusting us with your systems, that is a fair response, and we would rather earn the trust than assume it. Ask us how we are getting on with the list. Holding us to it is exactly the relationship we are trying to build.
- ✓Ask any supplier who holds data about you to show their own security posture in writing.
- ✓Check they hold Cyber Essentials and actually test their backups, not just run them.
- ✓Expect an honest list of unfixed gaps - a claim of none is a warning sign.
- ✓Set a reminder to ask again in six months how their outstanding items are progressing.
- Cyber Essentials: the five technical controls NATIONAL CYBER SECURITY CENTRE ↗
- Supply chain security guidance NATIONAL CYBER SECURITY CENTRE ↗
- Data retention and holding personal data INFORMATION COMMISSIONER'S OFFICE ↗
- Choosing a security supplier you can trust WHICH? ↗
Links open each publisher’s live coverage of this topic.