Skip to main content
IG-Smart — Governance, Risk & Assurance

Cyber Resilience & Supplier Assurance

Cyber Governance & Assurance for Boards and Regulated Buyers

Turn cyber security activity into clear ownership, defensible evidence and decision-ready assurance.

Talk to a Senior PractitionerStill defining the requirement
Submit a RequirementDefined scope, tender or RFP

IG-Smart helps regulated and high-consequence organisations govern cyber risk, test resilience, strengthen supplier assurance and demonstrate whether security arrangements are operating as intended.

We connect technical security activity to executive accountability, procurement evidence, audit readiness and board-level decision-making.

Cyber governance consultancy helps organisations establish clear ownership of cyber risk, connect cyber strategy to business objectives, test resilience and give boards, regulators and customers defensible assurance that material risks are understood and controlled.

When organisations engage us

When organisations engage us

  • Board visibility is weak

    Technical reports exist, but leaders cannot clearly see material risk, ownership or residual exposure.

  • Procurement is demanding evidence

    Customers or buyers expect credible cyber governance, resilience or certification-readiness evidence.

  • ISO 27001 is approaching

    Governance, ISMS evidence or control ownership needs to be assessed and strengthened.

  • Supplier risk is increasing

    Critical third-party dependencies exist without proportionate ongoing assurance.

  • An incident exposed governance gaps

    Escalation, decision-making, communications or recovery arrangements need strengthening.

  • Audit or regulatory scrutiny is increasing

    The organisation needs defensible evidence of how cyber risk is governed and assured.

  • The cyber function needs independent challenge

    Management wants assurance beyond self-assessment.

What we help solve

Security activity is not the same as cyber assurance

Organisations can invest heavily in cyber security and still struggle to answer basic governance questions:

  • Who is accountable for each material cyber risk?
  • Which systems, services and suppliers are genuinely business-critical?
  • What level of cyber risk has the organisation agreed to tolerate?
  • Which controls are operating effectively?
  • Which findings remain unresolved?
  • Are supplier dependencies understood?
  • Has incident decision-making actually been tested?
  • Can the board distinguish activity metrics from meaningful risk indicators?
  • Can evidence be produced quickly for regulators, customers, auditors or procurement teams?

The underlying issue

The gap is often not another security tool. It is governance, evidence and assurance.

Boards, regulators and customers need to know who owns the risk, whether the controls work, what remains exposed and what evidence supports that conclusion.

What the engagement involves

Govern, test and evidence the cyber position

  • 01

    Cyber Security Governance

    Establish board-level ownership, risk appetite, governance structures, oversight and evidence around cyber risk.

  • 02

    Cyber Resilience Assessment

    Assess whether the organisation can prevent, withstand, respond to and recover from material cyber disruption.

  • 03

    ISO 27001 Readiness

    Prepare governance, risk management, ISMS arrangements, controls and evidence for an independent ISO/IEC 27001 certification process.

  • 04

    ISO 27001 Gap Analysis

    Compare the current security-management position against relevant ISO/IEC 27001 requirements and identify evidence, ownership and remediation gaps.

  • 05

    Board Cyber Reporting

    Turn technical information into decision-ready reporting on material risk, trends, exceptions, remediation and residual exposure.

  • 06

    Cyber Incident Tabletop Exercise

    Test executive decisions, escalation, communications and recovery under a realistic simulated cyber incident.

  • 07

    Supplier Assurance

    Build proportionate evidence that key suppliers and technology partners are appropriately governed, resilient and understood.

  • 08

    Third-Party Risk Assessment

    Assess material cyber, governance and dependency risk before onboarding suppliers or when existing relationships need stronger assurance.

Talk to a Senior Practitioner

IG-Smart supports ISO/IEC 27001 readiness and implementation. Certification is carried out by an independent certification body.

Definition

What is cyber governance?

Cyber governance is the system of accountability, decision-making, risk ownership and oversight through which an organisation directs and assures cyber security. It connects cyber strategy, risk appetite, people, suppliers, incident readiness, controls and reporting so leaders can understand whether material cyber risks are being managed effectively.

Cyber governance is not the same as cyber security operations

The three overlap and depend on each other. Each answers a different question for leadership.

  • Focus of this page

    Cyber Governance

    • ownership
    • risk appetite
    • strategy
    • oversight
    • assurance
    • executive reporting
  • Cyber Security Operations

    • protection
    • monitoring
    • vulnerability management
    • configuration
    • detection
    • response
  • Cyber Assurance

    • testing
    • evidence
    • review
    • challenge
    • audit readiness
    • residual-risk visibility

Board-level reference point

What should effective board-level cyber governance cover?

The UK Government's Cyber Governance Code of Practice (opens in a new tab), developed with the NCSC, is built around five key governance principles for boards and directors.

  1. 01

    Risk Management

    Identify critical technology, information and services; assign senior risk ownership; define cyber risk appetite; understand supplier exposure; keep assessments current.

  2. 02

    Strategy

    Maintain a cyber strategy aligned with organisational objectives, risk appetite, regulatory obligations and resource decisions.

  3. 03

    People

    Establish accountability, cyber literacy, positive security behaviours and effective training across the organisation.

  4. 04

    Incident Planning, Response & Recovery

    Maintain and exercise response and recovery plans, clarify executive responsibilities and learn from incidents and exercises.

  5. 05

    Assurance & Oversight

    Embed cyber within wider governance, establish formal reporting and metrics, maintain executive dialogue and integrate cyber into internal and external assurance.

IG-Smart uses the Code as one reference point where appropriate. It is not a certification scheme, and following it does not by itself establish regulatory compliance.

Board assurance

What should the board be able to see?

  • Critical services

    What technology, information and suppliers matter most?

  • Risk ownership

    Who is accountable for material cyber risks?

  • Risk appetite

    What exposure has the organisation agreed to tolerate?

  • Control effectiveness

    What evidence shows that important controls are actually working?

  • Resilience

    Can the organisation respond to and recover from serious disruption?

  • Residual risk

    What remains unresolved, and who has accepted it?

Good board reporting should enable decisions, not merely describe security activity.

Operating model

Connect governance, operations and assurance

Assurance is most useful when it feeds governance decisions — remediation, risk acceptance and investment — rather than running as an isolated audit exercise.

IG-Smart works alongside the CISO, security team and technical providers. It does not replace them unless specifically contracted to perform an appropriate function.

Cyber assurance operating model
  1. Board / Audit & Risk Committee
  2. Executive Cyber Ownership · CISO · CIO
  3. Delivery:
    • Cyber Strategy
    • Risk
    • Controls
    • Operations
    • Suppliers
    • Incident Readiness
  4. Independent Review · Testing · Internal Audit · External Assurance
  5. Board reporting · Remediation · Risk acceptance

Supplier & third-party assurance

Your cyber position includes the organisations you depend on

Supplier risk should not be a procurement questionnaire completed once and forgotten. Assurance should be proportionate to criticality and continue across the life of the relationship.

Strong supplier governance considers

  • Service criticality
  • Access to systems or information
  • Data-processing role
  • Concentration and dependency risk
  • Security evidence
  • Contractual controls
Show all considerations (11)
  • Incident notification
  • Resilience and recovery
  • Material subcontractors
  • Ongoing assurance
  • Exit and contingency planning

Cyber resilience

Cyber resilience is more than prevention

An absence of incidents is not proof of effective cyber security. Mature governance considers whether the organisation can continue to deliver its critical services through disruption, and learn from it.

  1. 01Understand
  2. 02Protect
  3. 03Detect
  4. 04Respond
  5. 05Recover
  6. 06Learn
Governance sets direction and accountability; security operations implement and run controls; assurance evaluates evidence and effectiveness; assurance findings inform remediation, risk acceptance, investment and Board decisions.
  1. 01Cyber Governance

    Sets direction and accountability

    Ownership, risk appetite, policy and Board oversight

  2. 02Cyber Security Operations

    Implements and runs controls

    Day-to-day technical controls, run by your teams or operational providers

  3. 03Cyber Assurance

    Evaluates evidence and effectiveness

    Independent evidence that controls operate as intended

Assurance findings inform

  • Remediation
  • Risk Acceptance
  • Investment
  • Board Decision

Dashed layer: security operations — including SOC, MDR and incident-response operations — remain with the organisation or its operational providers unless specifically included in an agreed engagement.

Framework and regulatory context

Which cyber frameworks and requirements can the work support?

Depending on scope, sector and buyer requirements, relevant reference points may include:

Show all reference points (9)

Not every framework applies to every organisation, and guidance is not legislation. Scope is agreed for each engagement.

How we deliver

How IG-Smart approaches a cyber governance and assurance engagement

  1. 01

    Assess

    Establish the cyber-risk context, critical services, governance model, supplier dependencies, control environment, evidence and material gaps.

  2. 02

    Build

    Define governance structures, risk ownership, assurance mechanisms, reporting, policies, control improvements and remediation priorities.

  3. 03

    Manage

    Support the operating rhythm: governance forums, risk reviews, supplier assurance, remediation tracking and executive reporting.

  4. 04

    Assure

    Test whether governance, controls, resilience and evidence operate as intended through independent review, technical testing or other appropriate assurance.

  5. 05

    Improve

    Close findings, strengthen resilience, update evidence and adapt the governance model as technology, suppliers, threats and requirements change.

Improvement feeds the next assessment cycle, keeping the cyber assurance position current rather than rebuilding it from scratch.

What you receive

What does a cyber governance and assurance engagement produce?

Depending on scope, outputs may include:

  1. 01Current-state assessmentA documented view of material cyber governance, resilience and assurance gaps.
  2. 02Prioritised cyber-risk and remediation planActions sequenced by risk, dependency, effort and accountable owner.
  3. 03Governance and accountability modelDefined roles, decision rights, escalation routes and oversight responsibilities.
  4. 04Board / executive assurance reportingDecision-ready visibility of risk, control effectiveness, findings and residual exposure.
  5. 05Supplier assurance evidenceStructured assessment of material supplier dependencies and outstanding concerns, where in scope.
  6. 06Incident-readiness findingsDecision, escalation, communications and recovery observations from reviews or exercises, where commissioned.
  7. 07Assurance evidence packRelevant evidence prepared for audit, procurement, customer or regulatory scrutiny.

Scope

Independent governance and assurance, with technical depth where required

IG-Smart supports

  • Cyber governance and cyber-risk oversight
  • Board reporting
  • ISO 27001 readiness and gap analysis
  • Cyber resilience assessment
  • Supplier assurance and third-party risk assessment
  • Incident tabletop exercises
  • Audit and procurement evidence
  • Remediation oversight
  • Technical testing, where included in scope

Not provided by default

  • 24/7 SOC monitoring
  • Managed detection and response
  • Endpoint administration
  • Firewall management
  • General IT support
  • Accredited ISO certification
  • Guaranteed penetration-test outcomes
  • Guaranteed regulatory compliance

Where specialist technical testing is delivered with expert partners, the delivery model is set out transparently in the proposal.

Distinctions

Governance, resilience and technical testing answer different questions

Strong assurance connects all three without confusing them.

Relevant evidence

Selected cyber governance and assurance engagements

Published engagements covering security maturity and readiness, supplier assurance and routine technical testing.

Explore all case studies →Request Relevant Evidence →

Common engagement models

Readiness, assurance or ongoing oversight?

  • Governance and readiness review

    A defined-scope assessment of cyber governance, control effectiveness or ISO/IEC 27001 readiness, with prioritised findings.

    Suits

    Organisations preparing for certification, a customer audit or a board review.

  • Supplier assurance

    Assessment of critical suppliers against agreed criteria, delivered as a project or a managed cycle according to supplier population and depth.

    Suits

    Organisations that need defensible evidence of third-party cyber risk.

  • Phased assurance programme

    Multi-workstream governance, resilience and assurance work planned in stages with board reporting.

    Suits

    Larger or regulated organisations strengthening cyber oversight across several areas.

Typical investment

Indicative investment

  • Cyber Governance / ISO readiness

    Starting investment: £10,000 + VAT

    Typical investment: £12,500–£35,000+ + VAT

    Model: Defined-scope engagement

    Usually increases investment: Scope of the management system; Number of sites and systems; Existing control maturity

  • Supplier Assurance

    Model: Project or managed service, priced according to supplier population and depth of assessment

Scope, deliverables, assumptions and fees are agreed in writing before work begins. What changes the fee is set out on the investment page; the exact fee is confirmed after scoping.

How engagements and investment work

FAQ

Frequently asked questions

Standards and legislation references reviewed September 2026. This page is reviewed every 6 months.

Discuss a cyber assurance requirement

Need a clearer, more defensible view of your cyber position?

Whether the requirement starts with governance, resilience, suppliers, ISO readiness or a defined assurance exercise, begin with the position you need to understand or demonstrate.