The Technology Framework

The evidence

Cyber Essentials Plus implementation. Then ISO if the buyer asks.

Walk into the insurance renewal with a pack they can read.

Cyber Essentials and Cyber Essentials Plus for the form that keeps coming back. ISO 27001 when you sell to enterprise, PE, or the public sector. We implement the controls. An accredited assessor certifies.

The next cyber form comes back with questions nobody can answer. That is the cost of waiting.

Cyber Assurance Evidence Pack binder, control checklist and risk dashboard on a desk

Who this is for

Who this is for

Finance directors and managing directors who have become the IT department. Professional services of 50-200. South West wealth, IFA, and SIPP firms. PE-backed businesses that need evidence in the data room.

You need a pack the insurer can read.

What we do

What we do

We implement. We do not certify.

  • Scope the estate. What is in. What is out. Who owns each control.
  • Cyber Essentials and CE+ control work. Patching, access, MFA, backups, the boring things insurers actually ask for.
  • ISO 27001 when the buyer or the fund requires it. Policy, risk, evidence, the ISMS an assessor can walk through.
  • An insurance cyber questionnaire answered with documents, not adjectives.

PCI DSS appears in our proof because it was implemented in a live estate, in twelve months, alongside ISO 27001. It is a fact. It is not a sixth offer. The assurance we sell here is CE, CE+, and ISO 27001.

How it runs

How it runs

01 Diagnose. We sit with the people who actually run the estate. We read the last insurer form, the last buyer questionnaire, and the last "we will do that next quarter".

02 A 90-day sprint. Board-readable outcome: a control pack, a gap list that has been closed or owned, and a date with an accredited assessor if you are ready.

03 Then a retainer if the seat still needs filling. Someone has to keep the pack alive. That is the fractional Head of IT seat. Or we leave the place stronger and you run the cycle yourselves.

What you leave with

What you leave with

  • A pack an insurer, a PE house, or an enterprise buyer can read.
  • Controls implemented, with owners.
  • A path to CE, CE+, or ISO 27001 certification through an accredited assessor. We are not that assessor.
  • Fewer questions that bounce to the FD.

Questions

FAQs

Do you certify Cyber Essentials or ISO 27001?

No. The Technology Framework is not a certification body. We implement the controls. An accredited assessor certifies CE, CE+, and ISO 27001.

What is the difference between Cyber Essentials and CE+?

Cyber Essentials is the self-assessed baseline most insurers now expect. CE+ adds a hands-on technical test by an assessor. If the renewal or the buyer asks for Plus, plan for Plus.

When do we need ISO 27001 as well?

When you sell to enterprise, PE, or the public sector, and they ask for it in the contract or the data room. We implement. The assessor certifies.

Will this help with the insurance cyber questionnaire?

That is the point of the sprint. The renewal pack is documents, owners, and dates. Not a paragraph of intent.

Can this run while we keep our MSP?

Yes. You keep the MSP if it works. We sit above it and make the controls real. The MSP often does the tickets that the controls create.

Do you sell a separate vCISO product?

No. Board cyber sits inside the Head of IT seat and this sprint. We do not sell a standalone vCISO line.

Book a conversation

Book a conversation.

Book a conversation.

Telephone
0117 456 5486