The Questions We Get Asked Most
If yours is not here, ask us directly — we would rather answer than have you guess.
Most of our clients are mid-market organisations between roughly 50 and 5,000 staff, often in regulated sectors such as healthcare, finance, legal and manufacturing. We also support smaller businesses that have a specific compliance obligation to meet.
Scoping usually takes a short call plus a written proposal within a few business days. Testing engagements typically begin within two to four weeks; incident response support is available immediately for retained clients.
ISO 27001, SOC 2, NIST CSF and 800-171, PCI DSS, HIPAA, GDPR and CMMC. Where obligations overlap we map controls once, so a single control can satisfy several frameworks.
Both. We can hand findings to your team with implementation guidance, or we can carry out the remediation ourselves. Retesting after fixes is included in our testing engagements.
By scope and effort rather than by headcount. After a short scoping conversation we issue a fixed-price proposal covering the testing window, the reporting, and the retest.
We agree rules of engagement, testing windows and escalation contacts before any work begins. Destructive testing is never carried out without explicit written authorisation.
Yes. We work under mutual NDA as standard and carry professional indemnity and cyber liability cover. Certificates are available on request.
Yes. Many clients move to a retainer covering managed detection, vulnerability management, advisory hours and periodic testing.
Book a Consultation
Tell us what is keeping you up at night — an audit deadline, a cloud migration, a board asking hard questions. We will tell you honestly whether we can help, and what it takes.
Talk to the right desk
- General enquiriesinfo@palettech.com
- Contracts & administrationadmin@palettech.com
- Billing & paymentspayments@palettech.com
- Training & awarenesstraining@palettech.com