Assurance the buyer keeps rechecking
FreshWave sold into public sector buyers who insisted on assurance before they would sign, and in that market the checking never stops. Cyber Essentials Plus comes round for reassessment every year, ISO 27001 carries its own surveillance audits, and controls thrown together for one inspection date rarely survive the next, which tends to land just as a contract hangs on it.
Controls that lived in the day job
A senior CyPro practitioner built FreshWave’s controls to fit what the organisation could realistically sustain. Hardening and governance were treated as genuine engineering rather than as notes filed in a report, so the proof an auditor looks for came out of everyday running instead of a last-minute scramble. Certification arrived on the back of that, and the public sector contracts the company was chasing arrived with it.
Where this meets data protection
FreshWave earned information security credentials, yet they rest on the very foundation the UK GDPR expects. Article 32 calls for appropriate technical and organisational measures to keep personal data secure, and an ISO 27001 management system is the established route to putting those measures on a documented, audited basis. The access controls, secure configuration, patching discipline and supporting records an assessor probes are the same things that show a client, or the ICO, that personal data is guarded by design rather than by claim. This was a certification programme and not a GDPR engagement, but the point a data protection buyer can take from it holds firm: security assurance and data protection assurance grow from one set of governed controls, and evidence produced any other way counts for very little.