Devlique
Back to work
security

Security Audit & Compliance Programme for a Malta-Based Financial Services Firm

Financial Services Firm, Malta · Financial Services / Fintech

Security Audit & Compliance Programme for a Malta-Based Financial Services Firm

Certified

ISO 27001

Achieved in 8 months, 1 month early

0 major

Non-conformities

At Stage 2 audit

1.4M EUR

Contract retained

Renewed for 3 years

The Challenge

A Malta-based payment processing company operating under an MGA licence needed to achieve ISO 27001 certification within nine months as a contractual requirement from their largest enterprise client. Their internal IT team of two had no information security background. A gap analysis by their external auditor identified 61 non-conformities across access control, incident response, change management, and supplier risk. With the contract worth 1.4M EUR at stake, they needed a partner who could close the gaps technically while also preparing the documentation and evidence trail the auditors would require.

Our Solution

We embedded a senior security engineer with the client's team four days per week for six months. Technical remediations included: implementing SSO with MFA across all internal systems, deploying a SIEM solution for centralised log management, building an automated patch management pipeline, hardening all cloud infrastructure against CIS benchmarks, and creating a secure software development lifecycle (SSDLC) process. We authored 23 information security policies, trained all 34 staff on security awareness, and ran a tabletop incident response exercise. We attended the Stage 2 certification audit alongside the client's team.

Want results like these?

Let's talk about your project and what success looks like for you.