Voltek ITVoltek
← All posts

The Compliance Questions You Should Be Able to Answer

Voltek Engineering3 min read
Cybersecurity

Audits don't usually go wrong because of some exotic technical gap. They go wrong because someone asks a simple question and the room goes quiet.

The questions below aren't hard. That's the point - if you can't answer one from memory or find it documented in under five minutes, it's a gap, and it's better to find it now than in front of an auditor.

Who has access to customer data right now?

Not who should. Who does.

The gap between those two lists is where most findings come from. It grows every time someone changes role, every time a contractor finishes a project, every time a service account is created for a one-off migration and never removed.

If your answer starts with "well, it depends which system" - that's the finding.

What happens when someone leaves?

There should be a list. Not in someone's head: a real, written list of every system a departing employee touches, and who is responsible for closing each one.

The test isn't whether offboarding works when HR gives you two weeks' notice. It's whether it works on the Friday afternoon when someone leaves suddenly and nobody's in the mood for a checklist.

When did you last restore from backup?

Almost everyone has backups. Far fewer have restores.

A backup you have never restored is a hypothesis, not a plan.

An untested backup is a guess about the future dressed up as a safeguard. The only way to know it works is to have done it. Recently. On purpose.

Where does your data actually live?

Every system, every region, every third party. This one catches people out because the answer sprawls quietly:

  • The SaaS tool one team signed up for with a company card
  • The analytics platform that receives more than anyone realized
  • The backup copy sitting in a different jurisdiction than the primary
  • The spreadsheet export someone made in 2023 that's still in a shared drive

Can you prove any of this?

This is the one that separates a good answer from a passing one. Auditors don't grade intentions - they grade evidence. Logs, policies with dates on them, tickets showing the review actually happened.

"We do that" is worth nothing. "We do that, here's the record" is worth everything.

What to do with this

Take the five questions above into your next team meeting and try to answer them out loud. The ones that produce a pause are your roadmap - and they're considerably cheaper to fix on a Tuesday than during an audit.

If you'd rather not run that exercise alone, we'll run it with you. Our assessment covers exactly this ground, and you keep the documentation either way.

Keep reading

Managed IT3 min read

Scaling IT Without the Chaos

Most growing companies don't decide to have messy IT - they arrive there one reasonable shortcut at a time. Here's how that happens, and what it costs.

Luis Marcelino
Cloud3 min read

Moving Email Without Losing a Day

Email migrations have a reputation for going badly. They mostly go badly for the same three reasons - all of which are avoidable with a week of preparation.

Voltek Engineering
AI Assistant

Questions? Just ask.

Let's look at your setup

A free assessment maps what you're running, flags the risks worth caring about, and gives you a plan with clear pricing attached.