Security Audit & Compliance Programme for a Malta-Based Financial Services Firm
Financial Services Firm, Malta · Financial Services / Fintech

Certified
ISO 27001
Achieved in 8 months, 1 month early
0 major
Non-conformities
At Stage 2 audit
1.4M EUR
Contract retained
Renewed for 3 years
The Challenge
A Malta-based payment processing company operating under an MGA licence needed to achieve ISO 27001 certification within nine months as a contractual requirement from their largest enterprise client. Their internal IT team of two had no information security background. A gap analysis by their external auditor identified 61 non-conformities across access control, incident response, change management, and supplier risk. With the contract worth 1.4M EUR at stake, they needed a partner who could close the gaps technically while also preparing the documentation and evidence trail the auditors would require.
Our Solution
We embedded a senior security engineer with the client's team four days per week for six months. Technical remediations included: implementing SSO with MFA across all internal systems, deploying a SIEM solution for centralised log management, building an automated patch management pipeline, hardening all cloud infrastructure against CIS benchmarks, and creating a secure software development lifecycle (SSDLC) process. We authored 23 information security policies, trained all 34 staff on security awareness, and ran a tabletop incident response exercise. We attended the Stage 2 certification audit alongside the client's team.
Want results like these?
Let's talk about your project and what success looks like for you.