Cyber Resilience & Supplier Assurance
Cyber Governance & Assurance for Boards and Regulated Buyers
Turn cyber security activity into clear ownership, defensible evidence and decision-ready assurance.
IG-Smart helps regulated and high-consequence organisations govern cyber risk, test resilience, strengthen supplier assurance and demonstrate whether security arrangements are operating as intended.
We connect technical security activity to executive accountability, procurement evidence, audit readiness and board-level decision-making.
- Board-Level Governance
- Independent Assurance
- Cyber Resilience
- Supplier & Third-Party Risk
- Evidence for Scrutiny
Cyber governance consultancy helps organisations establish clear ownership of cyber risk, connect cyber strategy to business objectives, test resilience and give boards, regulators and customers defensible assurance that material risks are understood and controlled.
When organisations engage us
When organisations engage us
Board visibility is weak
Technical reports exist, but leaders cannot clearly see material risk, ownership or residual exposure.
Procurement is demanding evidence
Customers or buyers expect credible cyber governance, resilience or certification-readiness evidence.
ISO 27001 is approaching
Governance, ISMS evidence or control ownership needs to be assessed and strengthened.
Supplier risk is increasing
Critical third-party dependencies exist without proportionate ongoing assurance.
An incident exposed governance gaps
Escalation, decision-making, communications or recovery arrangements need strengthening.
Audit or regulatory scrutiny is increasing
The organisation needs defensible evidence of how cyber risk is governed and assured.
The cyber function needs independent challenge
Management wants assurance beyond self-assessment.
What we help solve
Security activity is not the same as cyber assurance
Organisations can invest heavily in cyber security and still struggle to answer basic governance questions:
- Who is accountable for each material cyber risk?
- Which systems, services and suppliers are genuinely business-critical?
- What level of cyber risk has the organisation agreed to tolerate?
- Which controls are operating effectively?
- Which findings remain unresolved?
- Are supplier dependencies understood?
- Has incident decision-making actually been tested?
- Can the board distinguish activity metrics from meaningful risk indicators?
- Can evidence be produced quickly for regulators, customers, auditors or procurement teams?
The underlying issue
The gap is often not another security tool. It is governance, evidence and assurance.
Boards, regulators and customers need to know who owns the risk, whether the controls work, what remains exposed and what evidence supports that conclusion.
What the engagement involves
Govern, test and evidence the cyber position
- 01
Cyber Security Governance
Establish board-level ownership, risk appetite, governance structures, oversight and evidence around cyber risk.
- 02
Cyber Resilience Assessment
Assess whether the organisation can prevent, withstand, respond to and recover from material cyber disruption.
- 03
ISO 27001 Readiness
Prepare governance, risk management, ISMS arrangements, controls and evidence for an independent ISO/IEC 27001 certification process.
- 04
ISO 27001 Gap Analysis
Compare the current security-management position against relevant ISO/IEC 27001 requirements and identify evidence, ownership and remediation gaps.
- 05
Board Cyber Reporting
Turn technical information into decision-ready reporting on material risk, trends, exceptions, remediation and residual exposure.
- 06
Cyber Incident Tabletop Exercise
Test executive decisions, escalation, communications and recovery under a realistic simulated cyber incident.
- 07
Supplier Assurance
Build proportionate evidence that key suppliers and technology partners are appropriately governed, resilient and understood.
- 08
Third-Party Risk Assessment
Assess material cyber, governance and dependency risk before onboarding suppliers or when existing relationships need stronger assurance.
IG-Smart supports ISO/IEC 27001 readiness and implementation. Certification is carried out by an independent certification body.
Definition
What is cyber governance?
Cyber governance is the system of accountability, decision-making, risk ownership and oversight through which an organisation directs and assures cyber security. It connects cyber strategy, risk appetite, people, suppliers, incident readiness, controls and reporting so leaders can understand whether material cyber risks are being managed effectively.
Cyber governance is not the same as cyber security operations
The three overlap and depend on each other. Each answers a different question for leadership.
Focus of this page
Cyber Governance
- ownership
- risk appetite
- strategy
- oversight
- assurance
- executive reporting
Cyber Security Operations
- protection
- monitoring
- vulnerability management
- configuration
- detection
- response
Cyber Assurance
- testing
- evidence
- review
- challenge
- audit readiness
- residual-risk visibility
Board-level reference point
What should effective board-level cyber governance cover?
The UK Government's Cyber Governance Code of Practice (opens in a new tab), developed with the NCSC, is built around five key governance principles for boards and directors.
- 01
Risk Management
Identify critical technology, information and services; assign senior risk ownership; define cyber risk appetite; understand supplier exposure; keep assessments current.
- 02
Strategy
Maintain a cyber strategy aligned with organisational objectives, risk appetite, regulatory obligations and resource decisions.
- 03
People
Establish accountability, cyber literacy, positive security behaviours and effective training across the organisation.
- 04
Incident Planning, Response & Recovery
Maintain and exercise response and recovery plans, clarify executive responsibilities and learn from incidents and exercises.
- 05
Assurance & Oversight
Embed cyber within wider governance, establish formal reporting and metrics, maintain executive dialogue and integrate cyber into internal and external assurance.
IG-Smart uses the Code as one reference point where appropriate. It is not a certification scheme, and following it does not by itself establish regulatory compliance.
Board assurance
What should the board be able to see?
Critical services
What technology, information and suppliers matter most?
Risk ownership
Who is accountable for material cyber risks?
Risk appetite
What exposure has the organisation agreed to tolerate?
Control effectiveness
What evidence shows that important controls are actually working?
Resilience
Can the organisation respond to and recover from serious disruption?
Residual risk
What remains unresolved, and who has accepted it?
Good board reporting should enable decisions, not merely describe security activity.
Operating model
Connect governance, operations and assurance
Assurance is most useful when it feeds governance decisions — remediation, risk acceptance and investment — rather than running as an isolated audit exercise.
IG-Smart works alongside the CISO, security team and technical providers. It does not replace them unless specifically contracted to perform an appropriate function.
- Board / Audit & Risk Committee
- Executive Cyber Ownership · CISO · CIO
- Delivery:
- Cyber Strategy
- Risk
- Controls
- Operations
- Suppliers
- Incident Readiness
- Independent Review · Testing · Internal Audit · External Assurance
- Board reporting · Remediation · Risk acceptance
Supplier & third-party assurance
Your cyber position includes the organisations you depend on
Supplier risk should not be a procurement questionnaire completed once and forgotten. Assurance should be proportionate to criticality and continue across the life of the relationship.
Strong supplier governance considers
- Service criticality
- Access to systems or information
- Data-processing role
- Concentration and dependency risk
- Security evidence
- Contractual controls
Show all considerations (11)Hide detail
- Incident notification
- Resilience and recovery
- Material subcontractors
- Ongoing assurance
- Exit and contingency planning
Cyber resilience
Cyber resilience is more than prevention
An absence of incidents is not proof of effective cyber security. Mature governance considers whether the organisation can continue to deliver its critical services through disruption, and learn from it.
- 01Understand
- 02Protect
- 03Detect
- 04Respond
- 05Recover
- 06Learn
01Cyber Governance
Sets direction and accountability
Ownership, risk appetite, policy and Board oversight
02Cyber Security Operations
Implements and runs controls
Day-to-day technical controls, run by your teams or operational providers
03Cyber Assurance
Evaluates evidence and effectiveness
Independent evidence that controls operate as intended
Assurance findings inform
- Remediation
- Risk Acceptance
- Investment
- Board Decision
Dashed layer: security operations — including SOC, MDR and incident-response operations — remain with the organisation or its operational providers unless specifically included in an agreed engagement.
Framework and regulatory context
Which cyber frameworks and requirements can the work support?
Depending on scope, sector and buyer requirements, relevant reference points may include:
- Cyber Governance Code of Practice (UK Government / NCSC) (opens in a new tab)
- NCSC guidance, including the Cyber Security Toolkit for Boards (opens in a new tab)
- NCSC Cyber Assessment Framework (CAF 4.0), where relevant (opens in a new tab)
- ISO/IEC 27001:2022
- Cyber Essentials / Cyber Essentials Plus, where appropriate
Show all reference points (9)Hide detail
- The NIS Regulations 2018, for organisations within scope (opens in a new tab)
- Sector-specific regulatory or contractual requirements
- NHS cyber and DSPT requirements, where applicable
- Customer and procurement assurance requirements
Not every framework applies to every organisation, and guidance is not legislation. Scope is agreed for each engagement.
How we deliver
How IG-Smart approaches a cyber governance and assurance engagement
- 01
Assess
Establish the cyber-risk context, critical services, governance model, supplier dependencies, control environment, evidence and material gaps.
- 02
Build
Define governance structures, risk ownership, assurance mechanisms, reporting, policies, control improvements and remediation priorities.
- 03
Manage
Support the operating rhythm: governance forums, risk reviews, supplier assurance, remediation tracking and executive reporting.
- 04
Assure
Test whether governance, controls, resilience and evidence operate as intended through independent review, technical testing or other appropriate assurance.
- 05
Improve
Close findings, strengthen resilience, update evidence and adapt the governance model as technology, suppliers, threats and requirements change.
Improvement feeds the next assessment cycle, keeping the cyber assurance position current rather than rebuilding it from scratch.
What you receive
What does a cyber governance and assurance engagement produce?
Depending on scope, outputs may include:
- 01Current-state assessmentA documented view of material cyber governance, resilience and assurance gaps.
- 02Prioritised cyber-risk and remediation planActions sequenced by risk, dependency, effort and accountable owner.
- 03Governance and accountability modelDefined roles, decision rights, escalation routes and oversight responsibilities.
- 04Board / executive assurance reportingDecision-ready visibility of risk, control effectiveness, findings and residual exposure.
- 05Supplier assurance evidenceStructured assessment of material supplier dependencies and outstanding concerns, where in scope.
- 06Incident-readiness findingsDecision, escalation, communications and recovery observations from reviews or exercises, where commissioned.
- 07Assurance evidence packRelevant evidence prepared for audit, procurement, customer or regulatory scrutiny.
Scope
Independent governance and assurance, with technical depth where required
IG-Smart supports
- Cyber governance and cyber-risk oversight
- Board reporting
- ISO 27001 readiness and gap analysis
- Cyber resilience assessment
- Supplier assurance and third-party risk assessment
- Incident tabletop exercises
- Audit and procurement evidence
- Remediation oversight
- Technical testing, where included in scope
Not provided by default
- 24/7 SOC monitoring
- Managed detection and response
- Endpoint administration
- Firewall management
- General IT support
- Accredited ISO certification
- Guaranteed penetration-test outcomes
- Guaranteed regulatory compliance
Where specialist technical testing is delivered with expert partners, the delivery model is set out transparently in the proposal.
Distinctions
Governance, resilience and technical testing answer different questions
Cyber Governance
Are cyber risks owned, directed and overseen effectively?
Focus
accountability · strategy · risk appetite · reporting · oversight
Cyber Resilience
Can the organisation withstand, respond to and recover from disruption?
Focus
critical services · incident readiness · recovery · dependencies · exercises
Technical Testing
Do specific systems or controls contain identifiable technical weaknesses?
Focus
vulnerabilities · attack paths · configuration · technical control effectiveness
Strong assurance connects all three without confusing them.
Relevant evidence
Selected cyber governance and assurance engagements
Published engagements covering security maturity and readiness, supplier assurance and routine technical testing.
Cyber Governance & Assurance
A FTSE 100 organisation
Security maturity and audit readiness for a FTSE 100 organisation
Global security policies didn't reflect UK practice ahead of a third-party security maturity assessment.
The client's CTO describes the work as focused, knowledgeable and timely.
Read the case studyFinancial Services, Information Governance · Cyber Governance & Assurance
AIG
A nationwide data-governance audit of an insurer's offsite records-storage supplier
An insurer needed assurance that its offsite records-storage supplier protected client data across its UK facilities.
AIG’s Head of Client Services EMEA: “the results exceeded our expectations… The audit not only identified areas of improvement…”
Read the case studyRetail / Consumer, Cyber Governance & Assurance
The Co-operative Group
Routine penetration testing for a major national retailer and co-operative
A major national organisation needed consistent, routine testing that kept pace with its changing digital estate.
On the Group's preferred supplier list for more than two years.
Read the case study
Common engagement models
Readiness, assurance or ongoing oversight?
Governance and readiness review
A defined-scope assessment of cyber governance, control effectiveness or ISO/IEC 27001 readiness, with prioritised findings.
Suits
Organisations preparing for certification, a customer audit or a board review.
Supplier assurance
Assessment of critical suppliers against agreed criteria, delivered as a project or a managed cycle according to supplier population and depth.
Suits
Organisations that need defensible evidence of third-party cyber risk.
Phased assurance programme
Multi-workstream governance, resilience and assurance work planned in stages with board reporting.
Suits
Larger or regulated organisations strengthening cyber oversight across several areas.
Typical investment
Indicative investment
Cyber Governance / ISO readiness
Starting investment: £10,000 + VAT
Typical investment: £12,500–£35,000+ + VAT
Model: Defined-scope engagement
Usually increases investment: Scope of the management system; Number of sites and systems; Existing control maturity
Supplier Assurance
Model: Project or managed service, priced according to supplier population and depth of assessment
Scope, deliverables, assumptions and fees are agreed in writing before work begins. What changes the fee is set out on the investment page; the exact fee is confirmed after scoping.
How engagements and investment workFAQ
Frequently asked questions
Standards and legislation references reviewed September 2026. This page is reviewed every 6 months.
Related services
- Governance Assurance & Board ReportingIndependent assessment, audit readiness, Board assurance, remediation oversight and residual-risk visibility.
- Information Governance ConsultancyGovernance operating models, records lifecycle, policy frameworks, accountability and assurance.
- AI Governance & AssuranceAI governance, risk, impact assessment, regulatory readiness and independent assurance.
Discuss a cyber assurance requirement
Need a clearer, more defensible view of your cyber position?
Whether the requirement starts with governance, resilience, suppliers, ISO readiness or a defined assurance exercise, begin with the position you need to understand or demonstrate.
