A buyer that inspects the plumbing, not just the paperwork
FreshWave sells into public sector buyers who want assurance over the infrastructure before they will contract, and in that market the inspection recurs. Cyber Essentials Plus is reassessed each year and looks at the systems themselves, ISO 27001 brings its own surveillance audits, and secure configuration bolted on for one assessment date rarely survives the next, which tends to arrive just as a contract turns on it.
Hardening treated as engineering, not annotation
A senior CyPro practitioner shaped FreshWave’s controls around what the business could genuinely keep running. Secure configuration, access management and the discipline of keeping systems patched were built as engineering rather than filed as recommendations, so the state an assessor inspects came out of everyday operation instead of a scramble before each audit. Certification followed on the back of that, and the public sector contracts the company was chasing followed with it.
Where this meets cloud security
FreshWave’s engagement produced certifications, but the controls underneath them are the same ones a cloud security assessment reads across a live estate. Identity and access kept tight, services configured to a hardened baseline, network paths controlled, and logging that would actually show you what happened: these are the pillars whether the workload sits on physical infrastructure or in an AWS, Azure or GCP account. An assessor of either kind is looking for the same thing, evidence that the controls are real and maintained rather than described. This was a certification programme and not a dedicated cloud security assessment, but the lesson a cloud buyer can take from it stands: secure infrastructure is a product of configuration and access discipline that lives in the running estate, and a report that claims it any other way is worth very little.