Audit-Ready IT: How UK SMEs Evidence ISO 27001 and Cyber Essentials Through Disaster Recovery, Dynamics 365 Jump Start and IBM i Management

  • 7 hours ago
  • 0

For many UK SMEs, compliance begins with a document sprint.

Policies are written. Registers are populated. Procedures are approved. Someone creates a folder called “ISO 27001 Evidence” and hopes it will behave like a control environment.

It will not.

Cyber Essentials and ISO 27001 are not primarily document exercises. They are evidence regimes. They ask whether controls exist, whether they are appropriate to the organisation’s risks and, crucially, whether they operate in practice.

That distinction matters. A beautifully formatted policy cannot demonstrate that backups restore, access is reviewed, software is patched or critical systems can be recovered. If the technology layer cannot produce reliable evidence on demand, the paperwork is mostly theatre with better typography.

This is where a consultancy-first approach adds value. The role of the Fractal IT Director is to connect business strategy, risk, systems and infrastructure into one operating model. Managed services then become bolt-on execution: useful, measurable and aligned to the wider plan.

Compliance is proof that the system is working

The National Cyber Security Centre’s Cyber Essentials guidance is built around five technical controls:

  • Firewalls
  • Secure configuration
  • Security update management
  • User access control
  • Malware protection

An organisation completing Cyber Essentials must be able to answer questions about how those controls apply to its environment. Cyber Essentials Plus goes further by testing whether the controls work technically.

ISO 27001 takes a broader management-system view. It expects an organisation to understand its information security risks, select appropriate controls, operate them, review performance and improve over time.

In both cases, the evidence is operational:

  • An asset register that reflects the actual estate
  • Access reviews showing who approved and removed access
  • Patch reports showing updates were applied within policy
  • Change records demonstrating controlled implementation
  • Security logs that are retained and reviewable
  • Backup records and restore-test results
  • Internal audit and management review outputs
  • Incident records that lead to corrective action

A policy says what should happen. Evidence shows what did happen.

That is the dividing line between audit readiness and document production.

Disaster Recovery: the business continuity proof

Disaster Recovery is often discussed as an insurance policy for a bad day. It is more useful than that. Properly designed, it is a measurable demonstration that the business understands its critical services and can recover them.

Start with two questions:

  • What is the Recovery Time Objective (RTO)?
  • What is the Recovery Point Objective (RPO)?

The RTO defines how quickly a service must be restored. The RPO defines how much data the business can afford to lose, measured in time.

These figures should not be selected because they sound reassuring. They should be agreed with business owners and linked to the financial, operational and regulatory impact of an outage.

A recovery plan should then evidence:

  1. Which services are critical
  2. Which systems and suppliers they depend on
  3. Where the recoverable data is held
  4. Who owns each recovery decision
  5. How the recovery process is initiated
  6. How success is validated
  7. What happens when the target is missed

The NCSC response and recovery guidance is clear on the practical principle: organisations should know how to restore backups and test that the process works.

A successful backup job is not a successful recovery. The difference is usually discovered at the least convenient possible moment.

For audit purposes, each restore test should record the date, scope, scenario, backup point, measured RTO, measured RPO, technical outcome, business validation and any corrective actions. Repeatable testing turns Disaster Recovery from a policy into evidence.

Abstract dark infrastructure forms connected by a precise gold bridge, representing tested recovery and business continuity

Dynamics 365 Jump Start: controlled implementation rather than rushed deployment

A Dynamics 365 Business Central implementation can improve financial control, reporting and operational visibility. It can also create a new compliance problem if implemented without governance.

That is why a Dynamics 365 Jump Start should not mean “configure a few screens and hope for the best”. It should be a scoped implementation engagement with clear decision rights and evidence built into the design.

The key controls include:

Role-based access

Users should receive access according to their responsibilities, not because someone copied yesterday’s permissions into today’s system. Permission sets, approval roles and segregation of duties need to be agreed before go-live.

A person able to create a supplier, approve a payment and release the transaction has a convenient workflow. They also have a control failure.

Environment strategy

Production, testing, sandbox and user acceptance environments should have defined purposes. Access to each environment should be restricted, reviewed and documented.

Changes should follow a simple lifecycle:

Request → assess → configure → test → approve → deploy → review

That sequence creates a useful audit trail and reduces the risk of untested changes reaching live operations.

Data migration governance

Microsoft provides supported migration paths for Business Central, Dynamics NAV, Dynamics GP, Dynamics SL and other SQL-based sources. Its Business Central data migration guidance highlights the importance of selecting an appropriate migration route and preparing the source environment.

For an audit-ready implementation, retain evidence of:

  • Data migration scope
  • Data cleansing decisions
  • Trial migration results
  • Reconciliation of opening balances
  • User acceptance testing
  • Cutover approval
  • Post-migration validation
  • Exceptions and remediation

The objective is not simply to move data. It is to know what moved, why it moved, who approved it and how its integrity was checked.

Minimalist modular enterprise system in matte black and gold, representing controlled ERP implementation and governance

IBM i Management: the specialised evidence challenge

IBM i estates remain central to critical workloads across financial services, freight, logistics, distribution and other operationally demanding sectors. The platform’s age is not the issue. Unexamined access, undocumented dependencies and untested recovery are the issues.

Our IBM i Management service addresses this as a high-value technical consultancy niche, particularly where the platform supports essential financial or operational processes.

An audit-ready IBM i review should consider:

  • User profiles and special authorities
  • Privileged access and least-privilege controls
  • Segregation of duties between security, operations and audit
  • Security audit journaling through QAUDJRN
  • Retention and protection of journal receivers
  • Patching and supported operating-system levels
  • Object and library authorities
  • Application dependencies
  • Backup and high-availability arrangements
  • Failover and recovery testing

IBM’s security hardening guidance emphasises active auditing, appropriate system values, retained audit journal receivers and continuous monitoring.

The evidence should be intelligible to both a technical reviewer and a business auditor. A raw journal extract may be technically accurate, but it is not a management control until someone can explain what it records, who reviews it, how exceptions are handled and where the results are retained.

Technology Expense Management is also risk management

Technology Expense Management is often introduced as a cost-saving exercise. It should be treated as a control exercise too.

A business that cannot identify its Microsoft licences, mobile contracts, cloud subscriptions, hardware estate or software renewals does not have a reliable asset register. An unreliable software asset register creates both financial waste and compliance risk.

The same questions apply to both:

  • What do we own or subscribe to?
  • Who uses it?
  • Is the use authorised?
  • Is the contract still appropriate?
  • Does the supplier support our risk requirements?
  • When is renewal due?
  • What happens when an employee leaves?
  • Is the service still necessary?

Compliance and cost discipline are the same exercise viewed from two angles. One asks whether the risk is controlled. The other asks whether the organisation is still paying for the control it actually needs.

The wider technology estate matters too. Cloud Solutions, Network Solutions, Voice and Connectivity, Helpdesk Support and Managed IT Services should all produce useful operational evidence, including configuration records, ticket histories, supplier reviews, service reports and change approvals.

These services are execution layers. Their value increases when they are governed by a clear IT strategy rather than purchased as disconnected technical commodities.

An evidence-first checklist for SME leadership teams

Before starting an audit or certification project, leadership should be able to answer the following:

  • Do we know the exact scope of our Cyber Essentials or ISO 27001 environment?
  • Does our asset register match reality?
  • Can we evidence joiner, mover and leaver access changes?
  • Are privileged accounts separately identified and reviewed?
  • Can we demonstrate patching against defined timescales?
  • Are RTO and RPO agreed for every critical service?
  • When did we last perform a documented restore test?
  • Has a business user validated the restored data?
  • Are Dynamics 365 roles, environments and changes governed?
  • Has migration data been reconciled and approved?
  • Are IBM i authorities, journaling and high-availability controls reviewed?
  • Can we explain our software, cloud, mobile and connectivity spend?
  • Are suppliers assessed according to their importance to the business?
  • Do management reviews result in actions, owners and follow-up?

If the answer to several questions is “we believe so”, the next step is not another policy. It is an evidence assessment.

A consultancy-first IT strategy should make the organisation easier to govern, easier to recover and easier to explain. That may involve Cloud Solutions, Managed IT Services or specialist bolt-on support, but the direction should come from business risk, operational priorities and return on investment.

Evestaff’s wider group services can be accessed through evestaff.co.uk, while consultancy-led technology strategy and execution are available through itandconsultancy.co.uk.

Audit readiness is not the art of producing more paperwork. It is the discipline of building systems that can show their work.

SEO tags: Compliance, Disaster Recovery, Dynamics 365 Jump Start, IBM i Management, Technology Expense Management, ISO 27001, Cyber Essentials, Cloud Solutions, Managed IT Services, Network Solutions, Helpdesk Support, Voice and Connectivity, UK SME IT consultancy, audit-ready IT, business continuity, evidence-led compliance

Join The Discussion