B://ASSESS19Digital Compliance
Evidence, not
assurances.
Digital compliance work maps your obligations, whether regulatory, contractual, or insurance, against what you actually have in place, then closes the gap in a way you can evidence. It is for organisations answering security questionnaires, renewing cyber cover, or entering a regulated sector.
THE PROBLEM
The gap between what an organisation believes it complies with and what it can evidence is usually wide, and is normally discovered under pressure.
The cost of leaving this alone is rarely one visible failure. It is the slow accumulation: the workaround that became the process, the thing only one person knows, the renewal nobody questioned.
Our starting point is always the same: establish what is actually true today, then decide what to change. Work scoped against an assumption tends to solve a problem you do not have.
- 01Nobody owns itIt sits with whoever touched it last, which is not the same as being managed.
- 02No current pictureWhat you have, what it costs, and who has access are all slightly out of date.
- 03Only handled when it breaksAttention arrives after the disruption rather than before it.
WHAT YOU GET
What the engagement covers
Scoped before it starts, so you know what is included and what is not.
- 01
Every common framework
ISO 27001, SOC 2, Essential Eight, the NIST Cybersecurity Framework, NZISM, PCI DSS, and the Privacy Act 2020. We work to whichever one your customer, insurer, or regulator is actually asking about, and map across them where more than one applies.
- 02
Obligation register
Every requirement you are genuinely subject to, in one list, with its source, so you stop complying with things nobody asked for.
- 03
Gap assessment
What is met, what is partly met, and what is not, with the evidence attached rather than asserted.
- 04
Remediation and evidence pack
A plan ranked by risk and effort, and the artefacts an auditor, insurer, or customer will ask for, assembled once and kept current.
HOW WE WORK
Scope, assess, report, support
Four stages with a written output at each one. You always know which stage you are in and what comes next.
- 01Week 1
Scope
We agree what is being examined and what a useful answer looks like, so the work is not open-ended.
- 02Weeks 2 – 3
Assess
Evidence gathered from your systems and your people, because the documented process and the real one rarely match.
- 03Week 4
Report
Findings written for a decision maker: what is true, what it means, and what we would do about it, ranked.
- 04As needed
Support
We can hand the report over and step back, or stay and deliver the remediation. Both are normal.
WHAT CHANGES
What you should expect
- Someone other than you owns it, with that written down.
- The current state is documented and stays documented.
- Cost is planned ahead rather than discovered at renewal.
- Decisions are made against evidence rather than assumption.
FAQ
Questions we get asked
01What is digital compliance?
Digital compliance work maps your obligations, whether regulatory, contractual, or insurance, against what you actually have in place, then closes the gap in a way you can evidence. It is for organisations answering security questionnaires, renewing cyber cover, or entering a regulated sector.
02Which security framework should we be working towards?
Whichever one your customers and insurers are asking about, which is usually a shorter list than it appears. ISO 27001 is the common request in tenders. SOC 2 comes up when you sell software to North America. Essential Eight is a practical baseline that maps neatly onto Microsoft 365. NZISM applies if you handle government information. Starting with a framework nobody has asked you for is a common and expensive mistake.
03How long does ISO 27001 certification take, and is it worth it?
Realistically most organisations spend the better part of a year getting ready, then go through a two-stage external audit. It is worth it when it unlocks revenue, which usually means a customer or a tender has made it a condition. It is rarely worth it purely as a security exercise, because the same controls can be implemented and evidenced without the certificate at a fraction of the cost. We will tell you honestly which situation you are in.
04Our insurer sent a cyber questionnaire we cannot honestly answer. What now?
This is one of the most common reasons we get called, and it is a good reason. The questions are usually specific and answerable: multi-factor authentication everywhere, tested backups, endpoint detection, an incident response plan, patching timeframes, and staff training. We establish where you genuinely stand, close the gaps that matter to the policy, and give you documented answers. Answering optimistically is worse than answering honestly, because a misrepresentation can void the cover at exactly the moment you need it.
05A customer sent us a security questionnaire. Do we have to complete it?
If you want the contract, generally yes, and they are getting longer every year. The efficient approach is to build the evidence pack once, keep it current, and answer from it rather than treating every questionnaire as a fresh research project. Organisations that do this answer in a day. Organisations that do not lose a week of senior time per questionnaire.
06What is the difference between being compliant and being secure?
Compliance is evidence that you meet a defined set of requirements at a point in time. Security is whether you would survive an actual attack. They overlap substantially and neither guarantees the other. We aim at both, but where the two genuinely diverge we will tell you which one a given piece of work is buying.
07How much does digital compliance cost in New Zealand?
We quote after scoping rather than before. Anyone pricing this work without looking at your environment is guessing, and the guess is rarely in your favour. Scoping itself is quick, and we tell you what it costs before we start it.
08How long does it take to get started with digital compliance?
A first conversation takes about half an hour and costs nothing. Scoping is usually a week or two of our time depending on the size of the environment, and we agree the delivery dates with you before anything is booked in.
09Can you deliver digital compliance alongside our existing IT team or provider?
Yes, and it is common. We are happy to work as an extra pair of hands under your internal team, or alongside an incumbent provider on a defined piece of work. We will set out in writing where the responsibilities split, so nothing falls between us.
10Do we have to use Atlas for the work the report recommends?
No. This can be delivered as a standalone piece of work for an organisation we have never worked with before, or folded into a managed agreement if you already have one with us. Plenty of clients use us for one thing and keep everything else where it is.
11Do you work with organisations outside Auckland?
Our team is based in Auckland and we attend sites across the wider region. Most of this work is delivered remotely, so we support organisations throughout New Zealand, and we will say up front where being on site genuinely matters.
12Who does the assessment, and who presents the findings?
Named people, not a queue. You get a lead who knows your environment and stays with it, which is the difference between explaining your business once and explaining it every time you make contact.
13What do we actually receive at the end?
You keep the documentation regardless, and anything registered in your name stays in your name. Whether we stay involved is your call. Some clients take it in house from there, others move it onto an ongoing agreement with us. We would rather you left cleanly than stayed because leaving was difficult.
Start with a conversation.
Tell us what you are dealing with and we will tell you whether this is the right service for it, and what it would take.
← All services