News

Security as Standard: Why Governance Matters When Choosing an IT Provider

Looking Beyond IT Support

When choosing an IT provider, ask three questions:

  • How is their own business secured?
  • Who independently verifies their controls?
  • What happens when something goes wrong?

Businesses naturally look at response times, technical expertise, service levels and cost. But there’s another question that deserves just as much attention: how does your IT provider manage its own security?

Your technology partner may have privileged access to some of the most sensitive parts of your organisation – including email, Microsoft 365, user accounts, servers, backups, cloud services and business data. That makes the security of your IT provider part of your own security posture. Your IT provider is an important part of your security supply chain, and that level of access should come with clear evidence that security is taken seriously.

Proving Security, Not Just Talking About It

Almost every IT company will tell you that security is important. The harder question is how that claim can be demonstrated.

Independent certification and recognised security frameworks give customers a way to distinguish between good intentions and controls that have actually been assessed.

At PC Comms, we’ve deliberately built our security programme around recognised standards and external assurance – not because certificates look good on a website, but because we believe the company responsible for protecting customers’ technology should be prepared to apply the same standards to itself.

“Cyber security shouldn’t simply be something an IT provider sells. It should be embedded into the way that provider operates.”

Cyber Essentials Plus: Putting Controls to the Test

One important part of our security programme is Cyber Essentials Plus.

Cyber Essentials provides an independently verified assessment against five core technical controls, while Cyber Essentials Plus goes further by including independent technical testing of those controls.

That distinction matters. Rather than relying solely on what an organisation says it has implemented, Cyber Essentials Plus provides additional assurance through hands-on verification that security measures are operating in practice.

For customers trusting an IT provider with privileged access to their systems, that independent scrutiny provides valuable additional assurance.

 

IASME Cyber Assurance: Looking Beyond Technology

Technical controls are only part of effective cyber security.

PC Comms has also achieved IASME Cyber Assurance Level One, a verified self-assessment reviewed by an independent assessor that considers a broader range of security, privacy and organisational controls.

This broader approach matters because many security failures aren’t caused by missing technology. They can result from unclear responsibilities, poorly understood risks, inadequate processes, or failures in how organisations respond when something goes wrong. Good cyber security depends on governance and accountability as well as firewalls, endpoint protection and other technical controls.

What Does This Mean for Our Customers?

For our customers, these certifications aren’t badges. They’re evidence that PC Comms is prepared to subject its own security arrangements to external scrutiny – and that we’re willing to hold ourselves to the standards we recommend to our customers.

That matters because an IT provider can occupy an unusually trusted position within an organisation. We may manage administrative accounts, Microsoft 365 environments, networks, backups, security products and other systems fundamental to a customer’s operations. Security within an IT provider has a direct relationship with the security of the organisations it supports.

Going Further with the Cyber Assessment Framework

Certification isn’t the end of the process. Technology changes, threats evolve, and organisations themselves continually change – maintaining a strong security posture requires continual review and improvement.

Our next stage is aligning our security and governance programme with the principles of the NCSC Cyber Assessment Framework (CAF). The CAF provides a structured approach to assessing cyber security and resilience, extending beyond preventative technical controls into areas including security governance, risk management, detection, response and recovery.

For us, this is particularly valuable because resilience is about more than preventing an incident. It means understanding our risks, detecting problems quickly, responding effectively, and ensuring that both PC Comms and the customers who depend on us can continue to operate.

Looking Ahead to ISO 27001

Our longer-term roadmap also includes ISO/IEC 27001 certification, the internationally recognised standard for Information Security Management Systems (ISMS). It provides a structured approach to establishing, maintaining and continually improving the management of information security risk.

For PC Comms, ISO 27001 represents another step in formalising the security governance, risk management and continual improvement processes we’re already developing. Cyber Essentials Plus, IASME Cyber Assurance, our ongoing work with the NCSC Cyber Assessment Framework, and our ISO 27001 roadmap aren’t separate exercises – they’re different parts of the same security strategy.

Security as Standard

Choosing an IT provider involves a considerable amount of trust. You’re entrusting another organisation with access to systems, information and infrastructure that your business relies on every day.

We believe that trust should be supported by evidence. That’s why PC Comms continues to invest in independent assurance, recognised security frameworks, and the development of our own internal security and governance programme. Our objective is straightforward: the security standards we recommend to our customers should also be reflected in the way we run our own business.

Security isn’t an additional service bolted onto what we do.

It is part of the standard.

0
Survey Score (out of 10)
0
Response Time (mins)
0
Trained Technicians
0
Current Users