Security Assurance · GRC · Secure AutomationRemote delivery for growing technology businesses
Services

Security assurance, GRC and secure automation services.

Choose a bounded assessment, a readiness project, or an ongoing managed GRC programme. The service design separates advisory work from independent assurance where required.

Primary

Security Assurance & GRC

The primary service line for organisations that need to understand, build, test and maintain information-security controls.

ISO 27001 Gap Assessment

Current-state assessment against the agreed ISO/IEC 27001 scope, with evidence review, prioritised gaps and remediation roadmap.

ISO 27001 Readiness

ISMS scope, risk methodology, risk treatment, Statement of Applicability support, policies, control ownership and evidence readiness.

Internal Audit

Audit planning, sampling, interviews, evidence review, findings and corrective-action tracking where independence and competence requirements are satisfied.

Managed GRC

Risk-register maintenance, evidence calendar, policy reviews, access/vendor oversight, corrective actions, management review support and surveillance readiness.

Security Risk Assessment

Risk identification and treatment focused on business processes, information assets, cloud services, suppliers and technical exposure.

Supplier Security Assessment

Structured due diligence, evidence review, risk classification, exceptions and remediation tracking for critical suppliers.

Technical security and control assurance

Use technical inspection to determine whether a documented control is actually operating.

Microsoft 365 Security & Controls

Entra roles, MFA, Conditional Access, privileged access, account lifecycle, SharePoint, Intune, BitLocker, Defender and audit evidence.

Endpoint Security Posture

Encryption, patching, endpoint protection, local privilege, firewall, inventory and security configuration evidence.

Cloud & Infrastructure Controls

Identity, logging, privileged access, backups, network exposure, change control and evidence across Azure, AWS, Linux and network environments.

Secure automation remains part of the model.

Automation is used when it makes a control more reliable or evidence easier to retain. It is not presented as proof of compliance by itself.

Evidence Workflows

Scheduled evidence collection, naming, approval and retention workflows for recurring controls.

Governance Workflows

Access reviews, policy acknowledgements, exception approvals, corrective-action reminders and management reporting.

Operational Automation

M365 and Google Workspace automation for onboarding, offboarding, reporting and controlled administrative workflows.

What Tech Turn does not sell.

Clear boundaries are part of the service.

Tech Turn is not an ISO certification body. Tech Turn can prepare clients for certification, perform readiness and gap work, conduct internal audit work where appropriate, support remediation and operate managed GRC. Formal ISO/IEC 27001 certification remains with an appropriate certification body.