Supplier Data Assurance Diagnostic
Could your controlled information, supplier data and sensitive project information withstand a cyber incident, audit or AI rollout without exposing hidden control gaps?
15 questions • 5 control areas
Supplier assurance, controlled information and Cyber Essentials Plus are baseline expectations in defence and public sector supply chains. We provide UK-sovereign support with demonstrable security controls, clear access governance and the accountability high-assurance clients require.
Select a pressure to see where control often starts to drift.
Clients and primes increasingly require evidence of cyber controls — Cyber Essentials Plus, access management and data handling — before awarding or renewing contracts.
Clients and primes increasingly require evidence of cyber controls — Cyber Essentials Plus, access management and data handling — before awarding or renewing contracts.
Organisations in this sector that close the gaps typically follow the same pattern.
Data access is documented, governed and auditable — providing the assurance evidence that contracts and oversight bodies require.
Third-party access is controlled, time-limited and documented — so the supply chain strengthens rather than weakens your assurance posture.
Devices, communications tools and mobile access are configured to match the environment's security requirements and reporting expectations.
Permissions, external sharing and Teams configuration are aligned with programme requirements and auditable against policy.
Data access is documented, governed and auditable — providing the assurance evidence that contracts and oversight bodies require.
Third-party access is controlled, time-limited and documented — so the supply chain strengthens rather than weakens your assurance posture.
Devices, communications tools and mobile access are configured to match the environment's security requirements and reporting expectations.
Permissions, external sharing and Teams configuration are aligned with programme requirements and auditable against policy.
Choose one of three short diagnostics. Each is a 15-question check shaped around your sector. You will see your results immediately and receive a downloadable PDF report with practical analysis and prioritised next steps as soon as you finish.
Need help interpreting the results? You can talk them through with our team afterwards.
Built around CSMv4 and Defence Cyber Certification where relevant, Cyber Essentials Plus, supplier assurance and controlled information.
Could your controlled information, supplier data and sensitive project information withstand a cyber incident, audit or AI rollout without exposing hidden control gaps?
15 questions • 5 control areas
Are your managed devices, mobile access and high-assurance communication routes creating an unseen cyber, leaver or data-access gap?
15 questions • 5 control areas
Is Microsoft 365 controlled well enough for secure collaboration, external access, Copilot and automation?
15 questions • 5 control areas
Five service areas, each shaped around the pressures and priorities of this sector.
We support organisations where uptime, security, access, communication and data control matter to day-to-day operations. Sector-specific customer stories are in preparation.
Customer stories in preparation
Sector-specific customer stories are being prepared. These will show how similar organisations approach support, security, Microsoft, communications and data control.
A story focused on sensitive information handling, access control and assurance evidence for a defence supply chain organisation.
A story focused on managed devices, communication routes and high-assurance expectations in a sensitive operational environment.
A story focused on secure collaboration, external sharing controls and governance evidence for a defence-adjacent organisation.
Our own assurance
How assurance expectations in the defence supply chain are evolving — and what Cyber Essentials Plus actually requires from a practical technology perspective.
In preparation for this sectorThe Microsoft 365 configuration decisions that matter most for organisations handling controlled or sensitive information — and the defaults you should not leave in place.
In preparation for this sectorComplete a 2-minute review first, or speak to us if you already know where the pressure is.