Case study · FinTech

Two audits satisfied from one risk-ranked queue

CyPro established the true state of Pactio's controls over the customer data it holds, sequenced every gap by the risk it posed, and used one evidence base to clear ISO 27001 and SOC 2 side by side.

Client

Pactio

Pactio logo

Outcome

ISO 27001 and SOC 2 secured in a single seven-month push

Scrutiny arriving before the headcount

A young FinTech gets asked to demonstrate how it looks after data well before it has spare hands to do the demonstrating. Enterprise buyers wanted confidence in Pactio’s controls ahead of any signature, deals across the Atlantic assumed SOC 2, and investors were running diligence of their own on top. Three separate forms of scrutiny turned up together, at a business that needed its engineers on the product.

A single queue, worst risk first

CyPro began by pinning down what was genuinely true. A senior consultant reviewed the controls as they actually stood and gathered every shortfall into one list, ordered by the damage it could do rather than the clause it breached. Fixing followed that order from the top, so the sharpest exposure closed soonest. Each remedy was evidenced a single time and tied to both frameworks, which let ISO 27001 and SOC 2 advance together instead of running as two separate efforts. Both were in place inside seven months, and Pactio’s overall risk came down as the work went on.

Prioritisation is where the value sits

This is the same discipline our data protection work turns on. An assessment can throw up a long catalogue of gaps, and left as a raw list it can bog a team down as readily as it helps them. The worth lies in a consultant judging which gaps genuinely threaten the people whose data is held, which ones a customer or auditor will raise, and which can safely wait, then passing over a short list that repays the effort. Pactio’s engagement was a wider information security programme rather than a GDPR project, but the engine that made it work, one risk-ordered backlog serving several exacting audiences at once, is precisely what sound data protection governance should deliver: accountability you can evidence, worked through in the order that cuts exposure quickest.

"Within 7 months Pactio achieved both ISO and SOC2 compliance, as well as reduced overall cyber risk."
Sophie Fallen , Operations Lead, Pactio
Rocket above the GDPR Consultancy call to action

Get your GDPR sorted

Find out exactly where your GDPR compliance stands

The scoping call is free, lasts 45 minutes and is taken by a data protection consultant, not a salesperson. It covers where you are, what a gap analysis or audit would surface, and the fixed fee to put it right.