Why We Test Before We Take Over
A new managed IT relationship with us normally starts with a penetration test. Not a questionnaire, not a scan you never see the results of – an actual attempt to get in from outside, and an actual attempt to move around once inside. Pen testing has been part of our managed services from the start, because the alternative is taking responsibility for an environment we have not looked at properly.
What turns up is rarely exotic. A remote access tool a former vendor installed and nobody removed. An admin account belonging to someone who left years ago. A firewall rule opened for a weekend project that is still open. Each one is small. Chained together, they are how most breaches actually happen.
Testing Shows Where You Stand. Compliance Keeps You There.
A pen test is a snapshot. The week after it finishes, someone adds a user, changes a firewall rule, or installs a new application, and the snapshot starts to age. Compliance is the discipline that keeps the picture current between tests: written policies, scheduled risk assessments, and evidence that the controls you say you have are still working.
Most businesses do compliance in a panic once a year, the week before an audit or an insurance renewal. Because we already run the systems the evidence comes from, we collect it as we go. When your auditor, a client’s security questionnaire, or your cyber insurance carrier asks a question, the answer is a report we can pull, not a project.
Frameworks we support
- HIPAA – risk analysis, safeguards, and documentation for healthcare and dental practices. See HIPAA-compliant IT.
- CMMC and NIST 800-171 – control implementation, SSP and POA&M upkeep, and assessment readiness for defense suppliers. See CMMC compliance.
- PCI DSS – segmentation, access control, and the annual and after-change testing the standard requires, ahead of your QSA or self-assessment.
- SOC 2 – readiness and continuous evidence for the controls your CPA firm will examine.
- FTC Safeguards Rule – the written information security program, risk assessment, and testing it requires of financial service businesses.
- Cyber insurance – accurate, evidence-backed answers on carrier questionnaires and renewals.
Built by Our Own Software Team
Parliament Labs is the software arm of ROI Technology. It exists because running a managed security practice kept exposing gaps no off-the-shelf tool covered. SentryOwl, now in early access, came out of exactly this work: it finds unauthorized remote access tools on Windows endpoints, which is one of the first things we look for in every test. We are building our own compliance platform the same way, so the evidence trail behind your program is something you can see rather than something you have to take on trust. See our brands.