TrustLock:
Managed Compliance.

A bank, a tender panel or a client's procurement team sends a security questionnaire, and only a handful of the questions on it get a confident answer straight away. TrustLock is Executive Solutions' continuously managed cyber security compliance service, built on the Spotica ISMS platform with a named Digital CISO, keeping your ISO 27001 and POPIA position current instead of stale.

The Three Ways Compliance Work Done Once Quietly Goes Stale

Most Johannesburg SMEs we work with have done compliance before. A POPIA manual exists somewhere. A risk register was built years ago for a specific tender. The problem isn’t that the original work was bad. It’s that compliance work stops the moment it’s signed off. The business adds suppliers, systems, and staff underneath it, so by the time the next questionnaire, audit, or tender lands, what’s on file no longer matches what’s running.

The Questionnaire You Can Only Half Answer

A client questions encryption, sub-processors, incident response, and backup testing. The business can confidently answer a third of it, and the deal stalls while you look for the rest.

The POPIA Manual Written For One Tender

A POPIA manual gets drafted once, usually under deadline, then filed away. Two years later it still lists a supplier the business no longer uses, and says nothing about the system added since.

Compliance With No Named Owner

The risk register sits between multiple people, so a direct question from a client or the Information Regulator finds people assuming someone else has the answer.

The Renewal That Asks The Same Questions

Insurers ask nearly the same security questions a bank does at renewal time, and a lapsed control can mean a higher premium, or a declined claim later.

An Audit Finding Nobody Tracked

A past audit or client assessment raised findings that got logged and never revisited. When the auditor comes back, the same gaps are still sitting open.

TrustLock exists for the gap between those two points: the day the paperwork was finished and the day someone next asks for proof. It sits alongside the rest of our Cyber Security services, because a compliance gap and a security gap are usually the same weakness looked at from two different desks.

The Six Things Included In Fully Managed Compliance

TrustLock runs on the Spotica ISMS platform and covers ISO 27001, ISO 27701, GDPR and POPIA from one system, not six different spreadsheets. Here is what’s included every month.

A Digital CISO Without The Full-Time Salary

You get access to security leadership expertise, without carrying a full-time Chief Information Security Officer on payroll. It’s the same strategic oversight, at a fraction of what a permanent hire would cost.

Your Compliance Status In Plain Language

The Spotica interface shows where you stand in plain English, not buried inside a spreadsheet only one person understands. Anyone in the business can open it and see the current position.

Real-Time Risk Reporting, Not An Annual Scramble

Risk data updates as it changes, so you’re working from a live picture instead of the once-a-year compliance exercise most Johannesburg SMEs are used to doing under the usual deadline.

Meeting ISO 27001, GDPR And POPIA

Regulatory support means translating what each standard actually requires for a business your size, in South Africa. No handing over a generic international checklist.

Fully Managed, Not Just Set Up And Left

ES handles the ongoing administration: updating the risk register, reviewing controls and keeping documentation current, rather than configuring the platform once off.

ISO 27001 Readiness, when needed

Where the business wants the actual ISO 27001 certificate, the evidence pack is built up front, so the certification body’s Stage 1 and Stage 2 audits are a formality.

How Ongoing Governance Actually Works Once You're Live

Once TrustLock is live, the work doesn’t stop at the policy pack. A Digital CISO keeps the risk register current and the evidence ready, on a cycle rather than whenever someone remembers to check.

A Set Review Cycle, Not A Yearly Scramble

The Digital CISO checks the risk register, control evidence and open actions on that cycle, and flags anything that’s drifted before it becomes the finding an auditor raises.

Evidence Pulled From A Live System, Not Assembled

When a client, bank or vendor sends a questionnaire, the answers and supporting documents come straight out of the live ISMS. Nobody is opening old folders or rewriting the same POPIA manual every year.

Documentation Written For How You Actually Operate

Your information security policy, risk treatment plan and incident response plan are drafted around your suppliers, your systems and your staff, not filled in from a generic template with your logo added to the front page.

Updated Every Time Something In The Business Changes

A new supplier, system, or hire changes what the risk register needs, so it gets updated then, not at the next review. The same discipline sits behind our 24/7 managed cyber security monitoring: nothing waits for a fixed date.

What Actually Decides The Cost Of Keeping Your Compliance Position Current

There is no flat price, because publishing one would misrepresent the job. POPIA alignment alone is a smaller scope than POPIA, ISO 27001 and GDPR combined for a business trading with European customers. Cost depends on how much of your risk register, policies and evidence already exist in usable form, rather than scattered across old files, and on whether you want the ISO 27001 certificate itself, sitting a formal audit, or ongoing Digital CISO governance and alignment without certification.

01Which Compliance Standards Actually Apply To You

02 Certification Versus Ongoing Alignment And Digital Governance

03 How Much Of Your Documentation Already Works

Who This is For

This fits Johannesburg businesses that know POPIA and ISO 27001 apply to them, and are facing a live questionnaire from a client, bank or tender they can only partly answer, or a POPIA manual written once and never reopened. It is not for a business that wants a single static policy pack, or one that already runs its own ISMS and needs certification audit support alone.

How it works

1
Assessment
Current policies and risk register checked against POPIA.
2
Deployment
Your risk register built inside the Spotica ISMS.
3
Policy & Documentation
Every required policy drafted for how you operate.
4
Ongoing Governance
A Digital CISO reviews and updates it continuously.

frequently asked questions

Do we need full ISO 27001 certification, or is alignment enough?

It depends on what is actually being asked of you. Many clients and tenders only need proof that you are aligned to ISO 27001 and POPIA, with evidence behind it. Where a contract calls for the certificate itself, we build your risk register and Statement of Applicability inside Spotica so the certification audit becomes a formality, not a scramble.

A policy pack gives you documents on the day they are written, then nothing happens to them again. TrustLock keeps your asset register, risk register and controls live inside Spotica, with a Digital CISO reviewing them on a set cycle every time something changes: a new supplier, a new system, a new hire.

POPIA requires every business that processes personal information to appoint an Information Officer and register them with the Information Regulator. That appointment sits inside your business. TrustLock and your Digital CISO give that person the current policies, live risk register and evidence they need to answer for it when asked.

Often, yes. Insurers ask many of the same due diligence questions as a bank or client sending a security questionnaire: what controls you run, how you handle an incident, whether staff are trained. Because your evidence already lives inside Spotica, you can answer an insurance application from the same source you use for any other compliance demand.

Stop Redoing Compliance From Scratch Every Time It's Asked For

TrustLock keeps your risk register, policies and evidence current in Spotica so every questionnaire, audit or tender gets answered.