Self-assessment first. Every customer journey opens with the guided IASME 54-question Cyber Essentials self-assessment. Trust precedes premium.
IASME is the assessor — we are not. Never imply cyber.law issues certifications. We prepare, route, and stamp — IASME's approved assessors certify.
Article 32 framing wherever possible. UK GDPR Article 32 is the regulatory hook for every cyber control.
Vulnerability scanning is orchestrated, not built. Route through NCSC-approved partners; don't roll our own.
Breach response is regulated-adjacent. ICO 72-hour notification + insurance disclosure must be paired with Supreme Capital and gdpr.law. trained QA reviewer mandatory.
trained QA reviewer on every CE submission. IASME acceptance rate is the KPI.
gdpr.law cross-sell at every breach signal. Cyber events almost always trigger GDPR consequences.
form.law month-6 trigger. First enterprise tender = highest-intent moment. Wire to that, not to schedule.