✉ [email protected]
Accredited Certification Body · IAS & IAF Member · Certificates Verifiable Online
Home›Standards›Cyber Security

Get Your Cyber Security Quote

A specialist responds within 2 business hours ·

Cyber Security · Framework-Based Assessment & CertificationGlobal

We measure the security controls your customers keep asking about

A vulnerability scan only tells you what was open last Tuesday. SIS measures your patching, access control, logging and awareness training against a recognised framework, evidences what works, and hands you a ranked roadmap for what does not.

  • !A customer’s security questionnaire has arrived with ninety questions, a deadline, and nobody who owns the answers.
  • !Your cyber insurance renewal now asks for evidence of MFA, tested backups and endpoint detection before it will quote.
  • !A contractor system needs approval before it is allowed to connect to a government or defence network.
  • !The board asked for a security posture report and got a scan output nobody in the room could read.
  • !An incident happened, and the internal review found controls that existed on paper only.
  • !Procurement at a large account wants a third-party assessment, not another self-declaration on your letterhead.
What it is

A structured review of an organisation’s security controls - network, endpoint, identity, cloud, supplier and people - against a recognised control framework, producing a rated picture of current posture and a ranked list of what to fix first.

Who issues it

SIS performs the assessment and issues an assessment report and certificate of conformity. This is an assessment against a framework, not an accredited management-system certification like ISO/IEC 27001.

Validity

Findings describe posture on the assessment dates. Certificates are normally issued for one year, with reassessment as the estate and threat picture change.

Who can apply for ISO/IEC 22000 Certification?

Contractors connecting to customer networks, IT and telecom providers, banks, hospitals and public bodies asked to evidence posture rather than intentions.

5of 25 industries

Industries that require ISO 22000 Certification

Cyber Security is applicable across 5 of the 25 industries SIS covers. The pages below set out the specific reason it comes up in each one.

Defence IndustryPublic SectorTelecommunication IndustryInformation Technology IndustryBanking and Finance

What Cyber Security Actually Requires

An organisation must understand the requirements for ISO 22000 certification to implement it effectively.

1
Asset and scope inventory

A current list of systems, applications, cloud tenants, data stores and third-party connections. Assessment against a framework is meaningless if half the estate is missing.

2
Identity and access

Named accounts, multi-factor authentication on remote and privileged access, joiner-mover-leaver records, and evidence that dormant accounts actually get disabled rather than merely flagged.

3
Patch and configuration discipline

Documented build standards, a patching cadence with dates you can show, and a way to prove that critical fixes reached servers, laptops and network devices.

4
Logging and detection

Central log collection from key systems, retention long enough to investigate, alerting that reaches a human, and a record of what was done with each alert.

5
Backup and recovery

Backups isolated from the production domain, restore tests with results written down, and stated recovery time and recovery point targets the business has actually agreed.

6
Response and awareness

A plan naming who decides, who notifies and who talks to customers, plus phishing simulation and training records for the staff who click.

How Cyber Security Assessment Works

A clear, step-by-step process from your first call to a completed engagement.

Scoping & Framework Selection

We agree which entities, networks, cloud tenants and applications are in scope, and which control framework the assessment runs against, based on what your customers and regulators are asking for.

2–5 days

Evidence Collection

The access review is usually the one that stalls. Somebody has to prove dormant accounts were disabled, and the export shows leavers from two years ago still enabled.

1–3 weeks

Control Testing & Interviews

Assessors validate evidence against reality - sample configurations, review privileged accounts, walk through a past incident with the team, and test whether written controls are actually operating.

1–2 weeks, remote and on site

Report, Roadmap & Certificate

Procurement reads the rating and stops there. The board reads the roadmap. The certificate of conformity is what goes into the vendor portal, and it carries the assessment dates.

Report in 1–2 weeks; annual reassessment
A first assessment across a mid-sized estate runs six to ten weeks end to end; where a contract date drives it, evidence collection is split across teams and testing runs alongside, which takes most of the slack out of the longest step.

Industries That Need Cyber Security

🛡️
Defence Industry
Open full page →
Why it applies hereBeyond a one-off test, defence buyers want evidence of continuous security posture: monitoring, patch discipline, secure configuration and staff awareness. A cyber security assessment benchmarks the organisation against recognised control frameworks and produces a remediation roadmap the customer can review. It is often the precondition for connecting a contractor system to a defence network.Typical trigger: Network connection approval
🏛️
Public Sector
Open full page →
Why it applies hereBeyond individual applications, departments need a defensible security posture across networks, endpoints, cloud services and staff behaviour. A cyber security assessment benchmarks controls against recognised frameworks and produces a remediation roadmap that supports budget approval and answers legislative and audit scrutiny after any incident.Typical trigger: Departmental security posture; audit
📡
Telecommunication Industry
Open full page →
Why it applies hereAs critical infrastructure, operators need demonstrable posture across network, cloud and supply chain, not just point testing. A cyber security assessment benchmarks controls against recognised frameworks and produces a prioritised roadmap that supports both regulatory reporting and board-level risk oversight.Typical trigger: Critical infrastructure oversight
💻
Information Technology Industry
Open full page →
Why it applies hereBeyond point testing, buyers want evidence of continuous posture across cloud, endpoints, identity and the supply chain. A cyber security assessment benchmarks the organisation against recognised frameworks and produces a prioritised roadmap that supports board oversight, insurance placement and customer due diligence.Typical trigger: Cyber insurance; customer due diligence
🏦
Banking and Finance
Open full page →
Why it applies hereSupervisors expect demonstrable posture across the institution and its outsourced providers, not point-in-time testing. A cyber security assessment benchmarks controls against recognised frameworks and produces a prioritised roadmap supporting board reporting, insurance placement and regulatory correspondence.Typical trigger: Board and supervisory reporting

Commonly taken alongside

VAPT tests the technology, the assessment rates the controls around it, and ISO/IEC 27001 turns both into a managed system - run together, one evidence set and one site visit covers all three.

Not Sure Which Certification You Need?

Three questions. The selector reads the same industry-to-standard mapping this whole site is built on, then shortlists what applies to you.

Question 1 of 3

Which sector best describes your organisation?

Your insurer and your biggest customer want different evidence

Which comes first - the insurance renewal, the customer questionnaire or the network connection you have been promised? The answer changes which framework we assess against, and what it costs.

Get My Free Quote →

What Cyber Security Changes for Your Business

More than a certificate — a testimony that you have raised the bar and built customer confidence.

📋

Questionnaires answered once

One assessment report covers most of what customer security questionnaires ask, so sales stops rewriting the same twelve answers for every prospect.

🔌

Network connection approval

Defence, government and large enterprise customers often require a third-party assessment before a contractor system is allowed to connect to anything of theirs.

🏦

Better insurance terms

Underwriters price on evidence. A rated posture report with dated remediation usually gets a quote where a self-declaration gets a longer list of questions.

🎯

Spend aimed at exposure

Findings ranked by exposure and effort stop the security budget going to whatever the last vendor demonstrated, and give finance a defensible order of work.

🧭

A route to 27001

The control gaps found here are the ones that raise nonconformities at an ISO/IEC 27001 audit, so you learn the distance before committing to a certification programme.

🗂️

Reporting the board reads

A rated posture with movement between assessments gives directors something to govern against instead of a list of unpatched machines.

Frequently Asked Questions

Straight answers to what buyers ask before they commit to Cyber Security.

Is this the same as ISO/IEC 27001 certification?
No. ISO/IEC 27001 is an accredited certification of a management system, audited in two stages and maintained through annual surveillance across a three-year cycle. A cyber security assessment measures your controls against a recognised framework and reports on them. It is faster and cheaper, it answers most customer questionnaires, and it is often the step organisations take before committing to certification.
How is this different from VAPT?
VAPT attacks specific applications, networks and devices under controlled conditions and tells you what an attacker could exploit today. An assessment looks at whether the controls that should prevent, detect and recover from those attacks are designed and operating. Most organisations need both: the test finds the hole, the assessment explains why nobody spotted it.
Which framework do you assess against?
That depends on who is asking. Where a customer or regulator names one, we use it. Otherwise the assessment runs against a recognised control framework mapped to the domains most questionnaires cover - governance, identity, configuration, logging, backup, supplier management and incident response - so a single report answers more than one audience.
How long does the certificate last?
Reports describe posture on the dates the assessment ran, so they age. Certificates are normally issued for one year. Insurers and procurement teams typically ask for a report no older than twelve months, and organisations under active regulatory attention often reassess after any significant change to the estate.
Do we need to fix everything before you assess?
No, and organisations that wait usually never book. The assessment establishes where you actually stand, which is the point of it. Findings are ranked by exposure and effort so you can show a customer a dated plan rather than a clean sheet you do not have. Remediation and retest follow once the roadmap is agreed.
Can SIS also fix the gaps we find?
No. SIS assesses and certifies; it does not consult on the same scope. Accreditation rules require that separation, and a customer reviewing your report should be able to see that the organisation which found the gaps did not also sell you the remedy. Your own team or an independent consultant handles remediation, and we retest.

Cyber Security certification across Ethiopia

Pick your region to see the industries concentrated there and the standards their buyers and regulators ask for most.

✉ Email Us
✉ EmailGet Quote