Illuminate Technology on independent verification
Amanda Stewart, CEO and CTO of Illuminate Technology, on why the Scottish MSP wanted its security and operational controls verified independently, and what changed.
Why Illuminate Technology chose independent verification
Illuminate Technology is a Scottish managed service provider supporting more than 60 client organisations across Scotland and the UK. Amanda Stewart is its CEO and CTO. We asked her why an MSP already doing the work would want an outside party checking it.
The market has no referee
"There's currently no formal regulation in the MSP industry. Almost anyone can call themselves an IT provider and claim they're secure, or say they follow best practices, with really no independent oversight on those claims. Which is why independent continuous verification is so important. It helps clients separate genuine operational excellence from marketing claims." - Amanda Stewart, CEO and CTO, Illuminate Technology
"We're kind of a little bit fed up of doing all the best stuff in the background and nobody really knowing about it." - Amanda Stewart, CEO and CTO, Illuminate Technology
A certificate tells you what was true on the day
"Like most MSPs, we relied on a combination of industry certifications, security accreditations, policies, procedures, client references, case studies, and service reporting. All of those things still have value. The challenge is that most of them are just snapshots in time. A certificate tells you what was true when it was issued, a tender response tells you what a supplier says they do, but neither necessarily tells you what's happening today." - Amanda Stewart
"Assurix gives us a way to move beyond the statements and provide continuous verifiable proof." - Amanda Stewart, CEO and CTO, Illuminate Technology
What the assessment actually found
"One of the most interesting things was, in the process, it wasn't really about discovering major weaknesses. We already had strong governance, security, and operational practices in place. But the Assurix assessment gave us a new perspective on how the controls are owned, evidenced, monitored, and continually improved." - Amanda Stewart
"It reinforced that good businesses aren't defined by never having issues. They're defined by how quickly you can identify them, how transparently we deal with them, and how effectively we can improve." - Amanda Stewart
The bar is moving
"The expectations placed on MSPs are changing. Boards are becoming more aware of cyber risk. Procurement teams are carrying out deeper due diligence, and cyber insurers are asking more questions, so clients want evidence, not just assurance." - Amanda Stewart
"If you genuinely believe you're delivering a high-quality secure service, which a lot of us are, then independent verification shouldn't be anything to fear. It should be something you're proud of." - Amanda Stewart
The standard is maintained, not collected
There are 64 controls in the Trustmark and all 64 have to pass. Assessment happens annually, with continuous monitoring in between. If a control fails, the MSP has 30 days to fix it, and the Trustmark is publicly suspended if they don't.
"Gaining Assurix isn't the end goal. It's really the start. The real value of Assurix isn't achieving the standard once, it's maintaining it every day through continual assurance and ongoing accountability." - Amanda Stewart, CEO and CTO, Illuminate Technology
"Looking ahead, I'd like to see more MSPs embrace this level of transparency." - Amanda Stewart, CEO and CTO, Illuminate Technology