The controls we run inside our own business, mapped to NIST CSF 2.0 and CIS Controls v8.1, self-assessed and openly labelled as such.
At Alpha IT Solutions, security is built into how we operate, not bolted on for clients. We run our own business against the international best practices defined by the NIST Cybersecurity Framework 2.0 and the CIS Controls, and we work to the same standards we implement for the businesses we look after.
The five Cyber Essentials controls are covered by the safeguards below. We have not yet sat the external assessment. When we do, it will appear in our credentials with a link to the certificate.
Frameworks
The two frameworks we work to
NIST Cybersecurity Framework 2.0
Published by the US National Institute of Standards and Technology in February 2024. Version 2.0 organises security into six Functions: Govern, Identify, Protect, Detect, Respond and Recover. Govern was added in this version to put accountability first. It is free to download and designed to be self-applied by organisations of any size.
CIS Controls v8.1
Eighteen prioritised controls from the Center for Internet Security, broken into 153 individual safeguards. These are grouped by Implementation Group, and we work to IG1: the foundational 56 safeguards that CIS describes as essential cyber hygiene, and the right baseline for a business of our size.
NIST CSF 2.0 · Govern
Govern
Who is accountable, and against what.
Security decisions sit with a named director. We are small enough that this is a person, not a committee.
Published policies covering privacy, cookies and terms of business, reviewed annually.
Registered with the Information Commissioner's Office as a data controller, reference ZC214066. The entry is public, so you can check it on the ICO register rather than take our word for it.
We assess the platforms we place clients on, meaning Microsoft 365, AWS and Azure, rather than reselling blind.
NIST CSF 2.0 · Identify
Identify
You cannot protect what you have not counted.
Hardware and software inventory for every managed endpoint, collected by our own client management platform.
A documented picture of our own estate: the platform, the VPS that runs our services, and our Microsoft 365 tenant.
Data flows recorded for the personal data we hold, which is what the ICO registration is built on.
NIST CSF 2.0 · Protect
Protect
The controls that stop the common attacks.
Multi-factor authentication on administrative accounts, with day-to-day work done from non-privileged logins.
Managed antivirus and endpoint detection across our own devices, the same tooling we deploy for clients.
Operating system and application patching on a defined cadence rather than when someone remembers.
Encrypted backups, with credentials and API keys held server-side only and readable by root alone.
This website carries TLS 1.2/1.3 only, HSTS, nosniff, frame and referrer policies, and no third-party analytics or tracking scripts of any kind.
NIST CSF 2.0 · Detect
Detect
Noticing before the client does.
24/7 proactive monitoring across managed endpoints and our own infrastructure.
Security alerting from our platform, surfaced in real time rather than in a monthly report.
Managed detection and response available on our Complete tier, and running on our own estate.
NIST CSF 2.0 · Respond
Respond
What happens in the first hour.
A defined escalation path with named contacts, so nobody is working out who to call during an incident.
A one-hour response target, which is the same commitment we publish on our Complete tier.
Breach notification procedures aligned to UK GDPR timescales.
NIST CSF 2.0 · Recover
Recover
Backups you have actually restored from.
Backup verification, because an unmonitored backup is a guess.
Disaster recovery testing on an annual cycle. It is the same test we run for Complete-tier clients.
Documentation handed to clients as a matter of course, so a recovery never depends on us being reachable.
Straight answer
What this page is not
This is a self-assessment. We have worked through the controls and published what we run. No external assessor has audited it.
That distinction matters, so we are stating it rather than burying it. There is a meaningful difference between a company that has implemented a framework and a company that has been independently certified against a scheme. On this page we are the former.
Where we do hold something externally verified, it is listed on our credentials, each one linking to the public register it came from. Cyber Essentials is not on that list yet. It is externally assessed by a certification body appointed by IASME, it is the natural next step for us, and we would rather you heard that from us than noticed the gap.
If a provider ever tells you they are “NIST certified”, ask who certified them. There is no such certification.
Case study
What a day looks like on a server we run
Everything above is what we say we do. This is what it looked like when we
turned the same check on ourselves, with the numbers we actually measured.
1,241password attempts in 24 hours
470addresses already blocked
20 minto fix it, once found
We ran our audit tool against one of our own production servers from outside
the network, and it found a door on the latch: the server would take a password
instead of demanding a key, and it would let the administrator account log
straight in. Both were build defaults. Nobody had looked.
The part worth repeating is what nearly went wrong. We changed the setting,
the configuration test passed, and password logins were still enabled, because a
second file written when the server was built was quietly overriding the one we
had edited. The only way to catch that is to ask the running service what it
actually decided instead of trusting the file in front of you.
No client data, and no addresses published: an IP address can be
personal data under UK GDPR.
Rather than repeat it here, the full write-up sits on our case studies page,
with the numbers, the three checks we ran to confirm the fix, and a second audit
that found four more ordinary problems.