In short: EtherAssist generates the policies, procedures and SOPs around your real context, your sector, your systems and the framework you are targeting, rather than starting from a generic blank, and lets you run a self-assessment on demand to see where you stand. It is the engine behind our compliance packs service. The honest limit: generating a policy does not make you compliant. Documents are the evidence layer, and the controls behind them still have to be in place and working.
- A customer, insurer or tender has asked you to evidence something
- You bought a template pack and it is still half-rewritten in a folder
- You are targeting Cyber Essentials, ISO 27001, SOC 2 or the NHS DSPT
- Your documents were accurate once and your estate has moved since
The worst time to discover a gap is when somebody else finds it: an assessor mid-certification, an insurer at renewal, or a prospect three questions into a security questionnaire that is now holding up the deal.
Generated, not templated
You describe the business, the sector, the systems you run and the framework you are targeting, and it produces the documents written around that.
Because they are generated rather than copied, they are internally consistent, they reference your real environment, and they map to the standard you are being assessed against. Not as [INSERT DETAILS HERE] placeholders, but as documents that already fit.
It also fixes the shelf-life problem, which templates never do. When something in your estate changes you regenerate, rather than hunting through thirty documents for every stale reference. The pack stays a living thing instead of a snapshot that was accurate for one afternoon.
The part that matters more than the documents
Being able to audit yourself on demand, in seconds, whenever you want.
A self-assessment tells you where you stand against the framework right now, rather than after a consultant has spent a week and sent an invoice. You surface the gaps on your own schedule, get a prioritised, plain-English list of what to fix first, and generate the evidence to close each one, all before it becomes somebody else's finding.
Two disciplines make it worth the time. Audit against evidence rather than against memory, because asking whether you do something reliably produces the answer yes. And re-run it after the estate changes, not annually.
What it does not do
It does not make you compliant, and we would rather say that plainly than let the tool imply otherwise.
Documents are the evidence layer. Real compliance also needs the controls behind them to be in place and working: MFA actually enforced, backups actually tested, access actually reviewed. What generation and self-audit do is take the slowest, most demoralising part of the job, the paperwork and the where-do-we-even-stand question, and compress it from weeks into an afternoon.
The technical remediation still has to happen. That is the part we do as a service, and it is the part worth paying for.
What we do with EtherAssist
- Generate the pack around your estate and the framework you are actually being assessed against
- Run the self-audit with you and turn the output into a prioritised remediation list
- Close the technical gaps it surfaces, which is where the real work is
- Assemble the evidence an assessor asks for: registers, logs, records and review dates
- Re-run it when the estate changes, so the pack does not quietly go stale
Related
Frequently asked
Does generating a policy make us compliant?
No, and any tool that implies otherwise is selling you something. A policy is a statement of what your organisation has decided; compliance is whether the controls behind it are in place and working, and whether you can evidence that. What generation removes is the weeks of writing, and what self-audit removes is the uncertainty about where you stand. Both are real savings on the slowest part of the job. Neither replaces enforcing MFA, testing a restore or reviewing access, which is where certifications are actually won and lost.
Which frameworks does it cover?
The ones an SME is realistically asked for: Cyber Essentials and Cyber Essentials Plus, ISO 27001, SOC 2 and the NHS Data Security and Protection Toolkit. The useful question before starting is which one your contracts actually require, because that decision changes the scope considerably and assuming the wrong one costs weeks. If a customer or insurer has asked, work backwards from what they asked for rather than certifying to the most impressive-sounding standard.
We already have a template pack. Is this worth switching to?
It depends on whether your pack is finished and current. If it is written around your business, somebody keeps it up to date and you could evidence any of it this afternoon, you have what you need and this would not add much. In practice most template packs are two thirds rewritten, reference a business that has since changed, and have not been opened since the day they were bought. If that sounds familiar, the honest comparison is not template against generated, it is between a document set you trust and one you do not.
Other vendors we support
- Progress Kemp LoadMaster support, licensing and lifecycle
- SonicWall firewall support, and what End of Support means for your model
- WatchGuard Firebox support and lifecycle: when you actually need to move
- Altaro is now Hornetsecurity: VM Backup and 365 Total Backup
- Nakivo Backup & Replication: what it covers and how it is licensed
- Do you still need Mimecast if you have Microsoft Defender for Office 365?
- Exclaimer or native Microsoft 365 signatures: which one you actually need
- EtherApps Forge: capture and repackage an application you have lost the installer for
- EtherInsights: see what your Microsoft and Azure estate is actually doing
Not sure where you stand with EtherAssist?
Tell us what you are running and we will tell you plainly whether it needs action, including when the answer is that it does not.
