Case study · Telecoms infrastructure

Infrastructure controls that held their shape under inspection

CyPro helped FreshWave stand up secure configuration and access controls its infrastructure could sustain, the same class of controls a cloud security assessment examines, so its certifications survived reassessment and opened public sector work.

Client

FreshWave

FreshWave logo

Outcome

Certifications that unlocked public sector contracts

A buyer that inspects the plumbing, not just the paperwork

FreshWave sells into public sector buyers who want assurance over the infrastructure before they will contract, and in that market the inspection recurs. Cyber Essentials Plus is reassessed each year and looks at the systems themselves, ISO 27001 brings its own surveillance audits, and secure configuration bolted on for one assessment date rarely survives the next, which tends to arrive just as a contract turns on it.

Hardening treated as engineering, not annotation

A senior CyPro practitioner shaped FreshWave’s controls around what the business could genuinely keep running. Secure configuration, access management and the discipline of keeping systems patched were built as engineering rather than filed as recommendations, so the state an assessor inspects came out of everyday operation instead of a scramble before each audit. Certification followed on the back of that, and the public sector contracts the company was chasing followed with it.

Where this meets cloud security

FreshWave’s engagement produced certifications, but the controls underneath them are the same ones a cloud security assessment reads across a live estate. Identity and access kept tight, services configured to a hardened baseline, network paths controlled, and logging that would actually show you what happened: these are the pillars whether the workload sits on physical infrastructure or in an AWS, Azure or GCP account. An assessor of either kind is looking for the same thing, evidence that the controls are real and maintained rather than described. This was a certification programme and not a dedicated cloud security assessment, but the lesson a cloud buyer can take from it stands: secure infrastructure is a product of configuration and access discipline that lives in the running estate, and a report that claims it any other way is worth very little.

"Their new ISO 27001 and Cyber Essentials Plus certifications won them more public sector work."
Tom Bennett , CTO, FreshWave
Rocket above the cloud security Consultancy call to action

See what your cloud is exposing

Find out what a cloud security assessment would surface

The scoping call is free, lasts 45 minutes and is taken by a consultant, not a salesperson. It covers your AWS, Azure or GCP estate, what an assessment checks, and the fixed fee to get a prioritised fix plan.