Social Care Wales is the national regulator responsible for the oversight of registered social care professionals. The organisation operates across multiple regional offices located within UK Government hub sites and maintains an internationally certified Information Security Management System (ISMS) aligned to ISO/IEC 27001. Given the sensitivity of its work, robust information security, data protection, privacy, and technical system management are essential.
In April 2024, following a competitive open-market tender, Apprilis was appointed to deliver ISMS Internal Audit Services, providing assurance and advisory capability to strengthen the organisation’s security posture.
Although the ISMS had been certified for several years, operational risks had begun to impact compliance and posed potential risks to ongoing certification. At the same time, the organisation was undergoing significant change, which required:
The customer sought a trusted partner to bring rigour, independence, and proven expertise in ISMS auditing and advisory services.
Apprilis mobilised quickly, balancing on-site and remote delivery as the project launched at the tail end of the COVID-19 lockdown. We initiated the engagement with a detailed ISMS gap analysis, which informed a comprehensive programme of work including:
Delivering comprehensive and collaborative services worldwide for lasting impact