TrustLock:
Managed Compliance.
A bank, a tender panel or a client's procurement team sends a security questionnaire, and only a handful of the questions on it get a confident answer straight away. TrustLock is Executive Solutions' continuously managed cyber security compliance service, built on the Spotica ISMS platform with a named Digital CISO, keeping your ISO 27001 and POPIA position current instead of stale.
The Three Ways Compliance Work Done Once Quietly Goes Stale
Most Johannesburg SMEs we work with have done compliance before. A POPIA manual exists somewhere. A risk register was built years ago for a specific tender. The problem isn’t that the original work was bad. It’s that compliance work stops the moment it’s signed off. The business adds suppliers, systems, and staff underneath it, so by the time the next questionnaire, audit, or tender lands, what’s on file no longer matches what’s running.
The Questionnaire You Can Only Half Answer
A client questions encryption, sub-processors, incident response, and backup testing. The business can confidently answer a third of it, and the deal stalls while you look for the rest.
The POPIA Manual Written For One Tender
A POPIA manual gets drafted once, usually under deadline, then filed away. Two years later it still lists a supplier the business no longer uses, and says nothing about the system added since.
Compliance With No Named Owner
The risk register sits between multiple people, so a direct question from a client or the Information Regulator finds people assuming someone else has the answer.
The Renewal That Asks The Same Questions
Insurers ask nearly the same security questions a bank does at renewal time, and a lapsed control can mean a higher premium, or a declined claim later.
An Audit Finding Nobody Tracked
A past audit or client assessment raised findings that got logged and never revisited. When the auditor comes back, the same gaps are still sitting open.
TrustLock exists for the gap between those two points: the day the paperwork was finished and the day someone next asks for proof. It sits alongside the rest of our Cyber Security services, because a compliance gap and a security gap are usually the same weakness looked at from two different desks.
The Six Things Included In Fully Managed Compliance
TrustLock runs on the Spotica ISMS platform and covers ISO 27001, ISO 27701, GDPR and POPIA from one system, not six different spreadsheets. Here is what’s included every month.
A Digital CISO Without The Full-Time Salary
You get access to security leadership expertise, without carrying a full-time Chief Information Security Officer on payroll. It’s the same strategic oversight, at a fraction of what a permanent hire would cost.
Your Compliance Status In Plain Language
The Spotica interface shows where you stand in plain English, not buried inside a spreadsheet only one person understands. Anyone in the business can open it and see the current position.
Real-Time Risk Reporting, Not An Annual Scramble
Risk data updates as it changes, so you’re working from a live picture instead of the once-a-year compliance exercise most Johannesburg SMEs are used to doing under the usual deadline.
Meeting ISO 27001, GDPR And POPIA
Regulatory support means translating what each standard actually requires for a business your size, in South Africa. No handing over a generic international checklist.
Fully Managed, Not Just Set Up And Left
ES handles the ongoing administration: updating the risk register, reviewing controls and keeping documentation current, rather than configuring the platform once off.
ISO 27001 Readiness, when needed
Where the business wants the actual ISO 27001 certificate, the evidence pack is built up front, so the certification body’s Stage 1 and Stage 2 audits are a formality.
How Ongoing Governance Actually Works Once You're Live
Once TrustLock is live, the work doesn’t stop at the policy pack. A Digital CISO keeps the risk register current and the evidence ready, on a cycle rather than whenever someone remembers to check.
A Set Review Cycle, Not A Yearly Scramble
The Digital CISO checks the risk register, control evidence and open actions on that cycle, and flags anything that’s drifted before it becomes the finding an auditor raises.
Evidence Pulled From A Live System, Not Assembled
When a client, bank or vendor sends a questionnaire, the answers and supporting documents come straight out of the live ISMS. Nobody is opening old folders or rewriting the same POPIA manual every year.
Documentation Written For How You Actually Operate
Your information security policy, risk treatment plan and incident response plan are drafted around your suppliers, your systems and your staff, not filled in from a generic template with your logo added to the front page.
Updated Every Time Something In The Business Changes
A new supplier, system, or hire changes what the risk register needs, so it gets updated then, not at the next review. The same discipline sits behind our 24/7 managed cyber security monitoring: nothing waits for a fixed date.
What Actually Decides The Cost Of Keeping Your Compliance Position Current
There is no flat price, because publishing one would misrepresent the job. POPIA alignment alone is a smaller scope than POPIA, ISO 27001 and GDPR combined for a business trading with European customers. Cost depends on how much of your risk register, policies and evidence already exist in usable form, rather than scattered across old files, and on whether you want the ISO 27001 certificate itself, sitting a formal audit, or ongoing Digital CISO governance and alignment without certification.
01Which Compliance Standards Actually Apply To You
02 Certification Versus Ongoing Alignment And Digital Governance
03 How Much Of Your Documentation Already Works
Who This is For
This fits Johannesburg businesses that know POPIA and ISO 27001 apply to them, and are facing a live questionnaire from a client, bank or tender they can only partly answer, or a POPIA manual written once and never reopened. It is not for a business that wants a single static policy pack, or one that already runs its own ISMS and needs certification audit support alone.
How it works
frequently asked questions
Do we need full ISO 27001 certification, or is alignment enough?
It depends on what is actually being asked of you. Many clients and tenders only need proof that you are aligned to ISO 27001 and POPIA, with evidence behind it. Where a contract calls for the certificate itself, we build your risk register and Statement of Applicability inside Spotica so the certification audit becomes a formality, not a scramble.
How is this different from paying a consultant for a once-off policy pack?
A policy pack gives you documents on the day they are written, then nothing happens to them again. TrustLock keeps your asset register, risk register and controls live inside Spotica, with a Digital CISO reviewing them on a set cycle every time something changes: a new supplier, a new system, a new hire.
Who is our Information Officer, and does ES supply that role?
POPIA requires every business that processes personal information to appoint an Information Officer and register them with the Information Regulator. That appointment sits inside your business. TrustLock and your Digital CISO give that person the current policies, live risk register and evidence they need to answer for it when asked.
Does this help with our cyber insurance application too?
Often, yes. Insurers ask many of the same due diligence questions as a bank or client sending a security questionnaire: what controls you run, how you handle an incident, whether staff are trained. Because your evidence already lives inside Spotica, you can answer an insurance application from the same source you use for any other compliance demand.
Stop Redoing Compliance From Scratch Every Time It's Asked For
TrustLock keeps your risk register, policies and evidence current in Spotica so every questionnaire, audit or tender gets answered.