Your controls enforced in the systems themselves. Policy that runs the business, not a folder no one opens.
Many firms assess your governance and hand over a report. We put the controls in place, keep the records that prove they hold, and maintain both. Every permission has an owner, a reason and a review date, and the evidence is ready whenever a regulator asks.
The policy is the easy bit. Making the business follow it is the job.
You can have every policy document signed off and still fail an audit, because the gap is never the document. It is the change board that meets when someone remembers, the exception left open for eleven months, the access review that slips to next quarter. We close that gap and keep it closed, so what is written down is what actually happens on the floor.
The work suits two kinds of business: one whose controls have slipped and need restoring, and one that already runs well and wants its records kept to a standard that holds up under audit. We begin the same way for both. We learn how each department works, find where the discipline has slipped, and prove the fix with a re-run access review or a logged change rather than a sign-off.
Where control slips first, and how we take it back.
Governance goes at the edges, in change and in access, where the shortcuts feel harmless. These are the two we address first and control most closely, usually starting in your Microsoft environment.
Every change carries the reason it was made, not just a ticket number.
Routine changes run from templates we approve with you. Anything off-template stops for a senior review and goes nowhere without it. We log each one in Tallin against the service it touches, with the rationale and the sign-off attached, so a year from now your team can still see what changed, who approved it and why it was the right call.
Privileged access that someone owns, and exceptions that actually expire.
We run Entra access reviews on a schedule we set with you, each one with a named owner and a date. Every carve-out gets a verdict: closed, extended on approval, or written into policy because it is justified. The result is that temporary access no longer becomes permanent by default, which is the most common source of over-privilege.
The scope is agreed with you: a full policy rewrite, a single department, or everything from change control to lifecycle management. It is costed before work begins.
Four records that move governance out of individual memory, and onto something an auditor can read.
These are the records the discipline produces, and your team owns them from day one. They turn an audit into pulling records rather than reconstructing them, and they explain why the environment is configured the way it is.
A policy register tied to the controls that enforce it.
Every policy has an owner, a date it was last checked and the date it is next due. Where Azure Policy, Intune or Entra enforces a rule, we link it to the policy that demands it, with the live exceptions sitting alongside. This keeps the written policy and the live configuration aligned.
A change history in Tallin that records the why.
Tallin, our own service-management platform, holds the change record. Routine changes run from approved templates, and the rest carry their reasoning, their approval and the services they affect. When someone asks why a change was made two years ago, the answer is in one place rather than lost in a Teams thread.
Decision records that replace assumption with documented fact.
For the decisions that shape the environment, we write down the question, the options weighed and the choice made. When a design is challenged later, your team can see the reasoning behind it and knows exactly what would need to change to reverse it.
A lifecycle inventory with every renewal date in plain sight.
Servers, identities, certificates, integrations and licences, each tracked with the date it needs refreshing or renewing. Where Purview retention applies, we record it, so what you retain and what you delete is a documented decision rather than an oversight.
When exceptions outnumber the rules, the exceptions are effectively your policy.
Send us what you have, in whatever state it is in. We will tell you what to address first and whether we are the right firm to do it.
What we settle before we touch anything, so nothing comes apart later.
First we read what you already have, the policy register, the exceptions, the change history and any decision records, then we sit with the people who run each department day to day. That shows us where the gaps are and gives you a plain plan for ownership, access reviews, change control and lifecycle tracking.
From there we put the agreed controls in place and enforce them, keeping every decision in the same records your team carries on with after we hand over.
Settled before we begin
-
Where you actually stand
Which policies still apply, which exceptions are justified and which are no longer warranted, and who owns each one.
-
Who holds each control
Who chairs the reviews, who attends, and how often they run, set to the work rather than a fixed calendar.
-
Where the evidence lives
Where policy, change history and lifecycle dates are kept, so the whole environment can be understood without relying on any individual's private tracker.
Factor1's vCISO writes the policies, keeps them current and represents them in audits.
Governance is one piece. We look after the whole.
Under one agreement, the estate is watched, maintained and documented as a single thing, by the team behind this page.
…and everything between.
Tell us where control has slipped, including the records you no longer rely on.
You will get a clear assessment of what we would bring under control first and whether we are the right firm to do it.
