For regulated firms without an IT department
Access control
your auditor accepts.
You already have good security. What you don’t have is a way to prove it. Norrtrust reads the systems you already run and produces the document your auditor asks for — continuously, not once a year.
Twenty minutes to connect · read-only · no charge for the first assessment
The question every regulated firm gets asked
“Show me that only the right people can reach client data, and that you would notice if something went wrong.”
Today that means paying a consultant to dig through logs, or someone in the office spending a fortnight taking screenshots and hoping it is enough. The frustrating part is that the security is usually fine. It is the evidence that is missing.
How it works
- 1
Connect what you already have
Google Workspace, Cloudflare Zero Trust, Tailscale. Read-only, about twenty minutes, nothing to install and nothing changes for your staff.
- 2
It watches quietly
Who your people are, what devices they use, and who signed in from where. Checked every hour, so the answer is current rather than as of the morning someone ran a report.
- 3
You get a document
Sealed, dated, and traceable to named records. Hand it to your auditor, attach it to a client’s security questionnaire, or file it against your DORA obligations.
What a finding looks like
Effective revocation of access rights
One access grant was recorded for a revoked identity four days after offboarding.
→ Investigate immediately: confirm session invalidation and token revocation at the provider.
former.analyst@yourfirm.isAlso cited under SOC 2 CC6.2Not “MFA coverage is 94%” but the specific person, and the specific date. Auditors reject conclusions they cannot follow back to records.
One connection, four rulebooks
Your auditor asks about ISO 27001. Your regulator asks about DORA. A client’s security questionnaire asks about SOC 2. They are largely the same questions in different words — so 12 underlying checks answer 28 controls across all 4 frameworks at once.
- DORA (Regulation (EU) 2022/2554)7 controls
- NIS2 (Directive (EU) 2022/2555)3 controls
- ISO/IEC 27001:20226 controls
- SOC 2 (Trust Services Criteria)12 controls
What we can see
- Who your people are, and their roles
- Whether each has two-factor enrolled
- What devices they use, and those devices’ state
- Sign-in records: who, when, from where
- Your email
- Your files and documents
- What anyone browses
- Your network traffic
Access is read-only throughout. We hold no write credentials, so we could not change your access controls even if we wanted to. Your data stays in the EEA.
What it does not do
A vendor who only lists strengths is not credible to anyone who reads regulatory text for a living.
- It assesses access control, not your whole security programme. Physical security, asset disposal, malware defences and incident response are outside it — and the report names each gap rather than leaving you to find them.
- Where a provider cannot report something, the control reads “not evidenced” rather than passing. We will not claim a control on data we do not have.
- It is not a certification. It is evidence you present; the judgement remains your auditor’s.
Á íslensku
Norrtrust les aðgangsskrár úr kerfum sem fyrirtækið notar nú þegar — Google Workspace og Cloudflare — og býr til skjal sem endurskoðandi tekur gilt: hverjir hafa aðgang, hverjir eru með tveggja þátta auðkenningu, og hvort aðgangur fyrrverandi starfsmanna var í raun afturkallaður.
Aðgangurinn er einungis til lestrar. Við sjáum hvorki tölvupóst, skjöl né netumferð. Fyrsta úttektin kostar ekkert.
Find out what your access records actually say
The first assessment is free. Twenty minutes of read-only access, and a report within a week. If it is useful we can talk about keeping it running — if not, no obligation.
Email Hörður