Client story

Desucla: from strong foundations to independent security assurance.

Desucla provides technology for managing tax representation, filing and payments across jurisdictions. The engagement covered Cyber Essentials, CE+ and ISO 27001 certification — with ongoing security consultancy continuing today.

www.desucla.com
Engagement summary
Outcome
CE + CE+ + ISO 27001 certified
Engagement
Full certification pathway + ongoing ISMS
Sector
Financial technology / tax compliance

The situation.

Desucla operates a platform supporting tax compliance across multiple jurisdictions and works with organisations that expect a high level of confidence around the way information is managed. Security was already an established consideration within the business when the formal assurance work began.

The next step was to bring greater structure around the existing approach, align the organisation with recognised standards, and build towards independent certification. Rather than treat each requirement as a separate exercise, YDC worked with Desucla to build a security management system that could support the business more broadly.

What the engagement involved.

The outcome.

Desucla now holds Cyber Essentials, Cyber Essentials Plus, and ISO 27001 certification. More importantly, there is a working security management system behind those certifications. Risks are reviewed. Responsibilities are understood. Evidence is collected. Controls are tested. Security decisions have a clear place to live.

Certification was a milestone. It was never intended to be the end of the work. We continue to work with Desucla as an ongoing security consultancy partner.

Desucla — cross-jurisdictional tax compliance technology

Do you need Cyber Essentials before ISO 27001?

Not necessarily. They solve different problems and the right route depends on what the business needs. For Desucla, Cyber Essentials and CE+ provided useful independent technical assurance alongside the broader ISO 27001 programme. Another organisation may take a different route.

What does ISO 27001 implementation actually involve?

Quite a lot more than writing policies. The organisation needs to understand its risks, decide how those risks will be managed, operate the required controls, and produce evidence that the system is working. Done properly, it becomes part of how the business is managed rather than something that only gets looked at before an audit.

Similar situation?

Security assurance gets easier when the work joins up.

Cyber Essentials, CE+, ISO 27001, customer questionnaires and supplier reviews should not all create separate security programmes. We help organisations build one sensible system that supports all of them.

Related reading.