Security Consultancy - Assurance
Zenzero's experienced GRC Consultancy Team conducts information security assurance activities such as internal auditing and scenario-based testing to determine the accuracy, completeness, and usability of systems and processes. This helps to provide client organisations with confidence in their current information systems or general approach to protecting their organisation.
Features
- Robust security testing through formal audits and immersive scenarios
- Combining with technical security testing can provide holistic security overview
- Professional level ISO/IEC auditing as conducted by UKAS-accredited certification bodies
- Measurement and monitoring of security effectiveness for organisations
- Identification of control efficacy, assess value, and improve security alignment
- Proactive security risk identification, recommendations for improvement activities
- Workshops supporting business continuity, disaster recovery, and incident response planning
- Collection of simulation outputs and provide key findings and recommendations
- Collaborative attendee / facilitator interactions to gather current response processes
- Post-Incident Analysis Report formally captures analysis and future recommendations
Benefits
- Checks alignment to key compliance requirements or security standards
- Supports continuous accreditation and internal assurance efforts
- Increased security assurance with clarity of effectiveness of controls
- Improvement opportunities prior to external audits with objective review
- Experienced security consultants leading facilitation & identification of improvement opportunities
- Accurately test security controls in a risk free environment
- Improved response processes, client team cohesion, roles and responsibilities
- Multi-sector experience, expertise and detailed knowledge of assurance processes
- Decreased incident response times learned from practice and continuous improvement
- Scenarios tailored to business environment and information systems
Pricing
£800 to £1,250 a unit a day
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
9 5 5 3 4 6 9 1 1 4 8 7 2 8 4
Contact
ZENZERO SOLUTIONS LIMITED
Adam Crossling
Telephone: 03333209900
Email: tenders@zenzero.co.uk
Planning
- Planning service
- Yes
- How the planning service works
-
Zenzero's security consultancy teams (inclusive of GRC Consultancy, Penetration Testing, and Managed Assurance) work collaboratively to assist clients with assurance on the security of their cloud environment(s).
This particular Assurance service provides non-technical auditing of cloud governance (i.e., process testing, scenario-based risk assessment, desktop exercises) against set Scope, Objective(s), and Criteria to determine the efficacy of security controls.
The GRC Consultancy team in particular will predefine Scope, Objectives, and Criteria with Client organisations to best fulfil assurance activities in relation to organisational risk, inclusive of cloud security management. - Planning service works with specific services
- No
Training
- Training service provided
- No
Setup and migration
- Setup or migration service available
- No
Quality assurance and performance testing
- Quality assurance and performance testing service
- No
Security testing
- Security services
- Yes
- Security services type
-
- Security risk management
- Cyber security consultancy
- Security audit services
Ongoing support
- Ongoing support service
- No
Service scope
- Service constraints
- N/A
User support
- Email or online ticketing support
- No
- Phone support
- No
- Web chat support
- No
- Support levels
- N/A
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Up to Developed Vetting (DV)
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- 28/09/2023
- What the ISO/IEC 27001 doesn’t cover
- All sites outside of London & Coventry.
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber essentials plus
- No
- Other security certifications
- Yes
- Any other security certifications
-
- ISO 27001 Lead Auditor
- ISO 27001 Lead Implementer
- ISACA Certified Information Security Manager (CISM)
Social Value
- Social Value
-
Social Value
Fighting climate changeFighting climate change
Zenzero is actively engaged in Environmental, Social, and Governance (ESG) work, demonstrating a strong commitment to sustainability and ethical practices. They are in the final stages of being a certified B Corporation, which means they meet high standards of social and environmental performance, accountability, and transparency. As part of their ESG efforts, Zenzero has joined the Tech Zero taskforce, aligning with other tech companies to tackle the climate crisis and drive progress towards net zero carbon emissions. They have pledged to become carbon neutral by 2027 and are implementing measures such as an electric vehicle salary sacrifice scheme and cycle to work schemes to reduce their travel emissions.
Pricing
- Price
- £800 to £1,250 a unit a day
- Discount for educational organisations
- Yes