DataAigis

Nobody asks whether you do data security

They ask: an inspection lands next month and I cannot answer these checklist items; we finished classification two years ago and nobody has maintained it since; head office wants every branch assessed and someone has to set the basis. So we break the work into concrete deliverables, each stating when you need it, what happens, and what you receive — so you can match it against wherever you are stuck.

Banking data security risk assessment

When you need it

Regulatory self-inspection, annual review, before a new system goes live, or when head office wants branches assessed on one basis.

What happens

  • Assess control design and operation against banking data security requirements and national standards
  • Core systems, data warehouses, outsourcing and third-party connections carry the weight — not just what policy says
  • Findings ranked by risk, with the ones that must close before an inspection called out

Deliverables

  • Risk assessment report
  • Findings and remediation list with owners and deadlines
  • An index of supporting evidence

Insurance data security risk assessment

When you need it

Against insurance data security requirements, or after a dispute in underwriting, claims or the agent channel.

What happens

  • Insurance data chains run longer than banking — underwriting, claims, reinsurance, agents and brokers all move personal data
  • The channel side, agents and brokers and third-party platforms, is where responsibility most often blurs
  • Health declarations and claims files carry heavy sensitive data and are assessed separately

Deliverables

  • Risk assessment report
  • Channel-side responsibility mapping and contract clauses
  • Sensitive data remediation list

Regulatory inspection readiness

When you need it

When an inspection notice arrives, or a self-inspection is mandated. The window is usually short.

What happens

  • Work the self-inspection checklist against reality and separate genuine compliance from documentary compliance
  • Assemble evidence — an inspection tests whether you can produce it, not whether you once wrote it
  • Rehearse the interview: who answers, what they say, and what to do when they cannot

Deliverables

  • Self-inspection report
  • An evidence pack organised by checklist item
  • Interview response handbook and rehearsal record

PIPL compliance audit

When you need it

Required periodically for handlers above the regulatory threshold; when an audit is ordered by the regulator; or when investment, M&A or customer due diligence asks for an audit conclusion.

Audit scope, frequency and method are governed by the current text of the PIPL compliance audit measures and by regulator requirements.

What happens

  • Work through the audit guidance under the PIPL compliance audit measures — notice and consent, minimisation, rights response, entrusted processing and sharing, cross-border provision, security measures, incident handling
  • What gets tested is operating evidence, not policy text: was consent actually captured, how long did rights requests take, is there an agreement behind each sharing arrangement
  • We can issue the audit conclusion as an independent third party, or support your team through a self-audit

Deliverables

  • Audit report and conclusion
  • Findings and remediation list with owners and deadlines
  • Remediation verification and re-review records

On-site data governance service

When you need it

After the policies exist — the real problem is that nobody maintains them day to day.

On-site engineers run governance operations. That is not a 24/7 SOC watch, and we do not describe it as one.

What happens

  • Security engineers based at your site handle ongoing classification upkeep, risk disposal and change review
  • New systems, new data sources and new third-party sharing go through review rather than being fixed afterwards
  • Support for internal and external inspections, drills and incident handling

Deliverables

  • Monthly operations report
  • Risk disposal and change review records
  • Iterated policies and procedures

Data classification implementation

When you need it

When a data catalogue must be filed, or governance has stalled at "we graded it and nobody uses it".

What happens

  • Label against national standards and industry templates; financial and automotive templates can be adopted then trimmed
  • Scan results need human confirmation and locking — that step decides whether the register stays trustworthy
  • Grades have to reach access control, masking and approval workflows, or they are just a spreadsheet

Deliverables

  • Asset register with grading results
  • A tailored industry classification template
  • An integration plan for access control and masking

Data security management system

When you need it

Starting from nothing, or when existing policies contradict each other and never reach the desk.

What happens

  • A three-tier document set — strategy, policy, operating manual — each tier resolving into specific role actions
  • Three-level review and three-level escalation, so who approves, who escalates and by when are all defined
  • Policy aligned to real processes; nothing written that cannot be done

Deliverables

  • The complete three-tier document set
  • Role responsibilities and approval matrix
  • A rollout and communication plan

MLPS classified protection (level 2 / level 3)

When you need it

Before a new system goes live, after capacity or architecture changes, and on the annual assessment cycle. Level 3 systems also face routine supervisory inspection.

The assessment report itself is issued by a licensed assessment body; our role is consulting, remediation and support.

What happens

  • Grading and filing: decide whether the system is level 2 or level 3, produce the grading report and complete police filing — getting the level wrong makes everything downstream rework
  • Gap analysis and remediation: compare current state against MLPS 2.0 technical and management requirements and produce a prioritised, costed remediation list
  • Remediation and assessment support: drive the fixes, prepare the evidence, and support the assessment body on site through to closure

Deliverables

  • Grading report and filing materials
  • Gap analysis and remediation plan
  • Remediation verification and assessment support materials

Vulnerability scanning and penetration testing

When you need it

Pre-launch security acceptance, the periodic testing required by MLPS and other regimes, after major releases, or after an incident.

What happens

  • Scanning covers hosts, middleware, web and APIs, scheduled across the asset estate rather than as a one-off sweep
  • Penetration testing follows realistic attack paths with a focus on whether data can be reached — privilege bypass, broken access control, unauthenticated interfaces
  • Every finding comes with reproduction steps and a fix, then a retest to confirm, so nothing is left as "known and unfixed"

Deliverables

  • Vulnerability scan report ranked by risk
  • Penetration test report with reproduction steps
  • Fix recommendations and retest confirmation

Incident response and drills

When you need it

When periodic drills are required, or when something has actually happened and you need someone to take it on immediately.

What happens

  • Write the plan first: what counts as an incident, who decides, how fast it must be escalated, what is said externally — most organisations stall because nobody is willing to make the call
  • Tabletop plus live drills run the plan through real people and expose where the process breaks
  • When it is real, support containment, forensics, impact assessment and regulator notification — personal data breaches carry statutory clocks

Deliverables

  • Response plan and decision criteria
  • Drill records and findings
  • Post-incident review and improvement actions

Vendor and third-party assessment

When you need it

At vendor onboarding, before renewal, or when an audit or inspection reaches this item — and it almost always does.

What happens

  • Tier vendors by how much data they touch; one questionnaire for everyone is not an assessment
  • Assess what can be verified: where the data sits, who can reach it, how it is deleted at exit, how you get told when something goes wrong
  • Back it with contract terms — processing agreement, audit rights, sub-processing limits, liability

Deliverables

  • Vendor tiering and assessment questionnaires
  • Assessment conclusions and onboarding recommendations
  • Recommended data processing agreement clauses

Data masking and test data management

When you need it

When development and test environments are running on production data. It is one of the most common inspection findings and one of the easiest to overlook internally.

What happens

  • Establish which non-production environments hold real personal data — usually more than anyone expects
  • Design masking rules per data type so the masked data remains usable for testing; otherwise developers will route around it
  • Wire masking into the data provisioning flow so that "get me a test dataset" is safe by default

Deliverables

  • Inventory of sensitive data in non-production environments
  • Masking rules and implementation plan
  • Recommended changes to the provisioning flow

Important data identification and filing

When you need it

When your sector publishes its important data catalogue, or filing is required.

What happens

  • Identify important data against sector catalogues and national standards, separating important, core and general data
  • The conclusion drives the transfer route — important data leaving the country goes through security assessment, with no alternative
  • Produce a catalogue and explanatory material ready for filing

Deliverables

  • Identification conclusions and their basis
  • A catalogue ready for filing
  • Downstream control requirements

Not seeing the one you need? Describe the situation and the deadline and we will work out where to start.

Enterprise data security services

Not the sentence "we provide data security consulting", but these eight concrete pieces of work: assessment, inspection readiness, management system build, classification rollout, and engineers on site keeping it alive.

Book a consultation