Chapter 6Handbook

How we prove it

The evidence chain

Most IT reporting is a screenshot of a dashboard nobody reads. It proves a tool is running. It does not prove your business is in a defensible position.

The test we use is simpler. If you cannot produce it, it does not exist.

The folder

Construction already has this. The site file. The ITPs, the sign-offs, the certificates, the handover pack. Nobody argues about whether that paperwork is worth doing, because everyone has been on the wrong end of a job where it was missing.

IT needs the same thing, and almost nobody builds it.

  • Asset and ownership register: every system, service and account, with a name against each
  • Licence and subscription register, with renewal dates
  • Network and site documentation: diagrams, addressing, ISP and circuit details
  • Backup configuration and restore test results, with dates
  • Patch compliance
  • Access review: who has what, and when it was last checked
  • Onboarding and offboarding records
  • Incident log
  • Risk register: open risks, owner and status
  • Vendor and support contacts, with account numbers
  • Monthly service reports, archived
  • The exit pack, if you ever leave

None of that is assembled when someone asks for it. It is built as the work happens, which is the only way it is true when you need it.

Why we build it as we go

Because the alternative is assembling it the week your insurer asks, and by then it is too late to be true.

A few years back I was running operations at a managed service provider with a hard deadline to get ISO 27001 certified. Miss it, lose contracts. And like every business that has ever had a compliance deadline, we had put it off. Repeatedly.

So it came down to me and one other person, and about twelve weeks. That is not how long that normally takes.

I want to be careful here, because the reason we made it is not that we are heroes. We made it because the business was already doing the work. The onboarding process existed. The procedures existed. There was a library of guides and videos, because we had built one on the principle that if you are going to do something more than twice you write it down.

We changed almost nothing. What we actually spent twelve weeks doing was proving what was already true.

The certification is not the work. The evidence is the work. If you are already operating properly, you are mostly just documenting it. And if you are not, there is no amount of paperwork at the end that saves you.

Which is why we build the evidence as we go rather than assembling it the week your insurer or your head contractor asks for it.

What you can ask us for, any day

The list of every system, service and account, and whose name is against each.

The date of your last full restore test, and the result.

What is currently unpatched, and why.

Who has access to what, and when it was last reviewed.

None of that needs notice. If a provider needs three weeks to answer any of those, that is the answer.

Hold points, not a stack you buy

Cyber security is not a stack you buy. It is procedures with hold points. A control nobody follows is not a control.

Name the two or three steps in your business where money or access moves, and put a hold point on each. Verify the change, not the invoice. The tooling supports the procedure. It does not replace it.