All expertise

08

Compliance and continuity

Compliance is not a folder of documents written the month before the audit. It is a set of controls running every day and producing their own evidence — the document is the by-product, not the work.

From requirement to technical control

Every measure a standard asks for has to become something that exists in the system: who has access to what, what gets recorded, where the backups are and how you prove they work. The mapping between the clause and the piece of infrastructure that satisfies it must be written and maintained, or by the second audit nobody remembers it.

In practice a large share of the controls is infrastructural: when the layer underneath is already covered, the company can concentrate on the organisational controls — policies, training, processes — that remain its own.

Evidence that collects itself

Append-only event log, incident history with what was done and when, security score and a periodic report generated by the system. If producing evidence needs a person exporting by hand, that evidence will arrive late and contestable.

How long until we are back up

Recovery objectives declared per service (how much time, how much data) and periodic drills that actually measure them. A number written in a plan and never verified is a wish; a number that came out of a drill is a commitment.

Important decisions leave a short record: context, alternatives, choice, consequences. That is what lets you change your mind in an informed way three years later.

Portfolio

What I did on this, project by project.

Orbitas

Compliance-ready infrastructure for companies pursuing certification

  • Mapping of ISO 27001 Annex A controls and NIS2 art. 21 measures onto real infrastructure components: security agent on every machine, least-privilege policies, configuration management, verified backups, logging and monitoring, network security, secure development, change management.
  • A recovery-objective matrix per service and scheduled restore drills.
  • Monthly coordinated patching across the cluster, with a declared window and verification afterwards.
  • A register of architecture decisions and incidents as searchable operational memory.
  • Customer dashboard with security score, uptime against target, incident history and a downloadable monthly report.
  • ISO 27001
  • NIS2
  • Wazuh
  • Vault
  • RTO/RPO
  • DR drills
  • ADR

SOS Bollette

Personal data in a multi-company CRM

  • GDPR requirements taken as a design constraint: what reaches the database and what does not, anonymisation, a register of data subject requests.
  • Automated weekly verification that the restore works and that data protections really come back on after it.
  • GDPR
  • PostgreSQL RLS
  • audit
  • verified backups

Manora

Audit package for external reviewers

  • Thirteen documents prepared for auditors: threat model, architecture, contract interactions, formal verification results, deployment procedure, emergency runbook, backup and recovery.
  • An independent external audit set as a mandatory condition before going to mainnet.
  • threat model
  • audit package
  • runbook
  • formal verification

Need this?

Tell me the problem and I'll tell you how I would tackle it — and if it isn't worth doing, I'll tell you that too.

Let's talk