Find the tools for
the work you need to do.
Explore how Fig Group supports security, compliance and day-to-day governance. The capabilities below work together in the platform; specialist testing and certification are available alongside it.
Start with your priority.
Choose an area below, then explore the individual capability for more detail.
Discover
Understand your environment
Identify the assets, data and configurations that sit within your scope.
Asset Discovery
Build a governed asset register with automated discovery, ownership tracking, and audit-ready evidence.
Data Discovery & Classification
Locate, classify, and monitor sensitive data across endpoints, cloud, and storage.
Configuration Management
Track configuration baselines, detect drift, and maintain audit-ready documentation.
Protect
Manage security and operational risk
Prioritise weaknesses, review suppliers and keep changes, continuity and access under control.
Vulnerability Scanning
Consolidate scanner output, prioritise by exploit likelihood, and track remediation.
Threat Intelligence
Contextual threat feeds mapped to your asset inventory and risk register.
Supplier Risk Monitoring
Continuous third-party monitoring with control assessments and risk scoring.
Exposure Modelling
Model aggregate risk exposure and scenario impact across your portfolio.
Change Management
7-state change workflow with AI-assisted risk scoring, approval gates, and policy compliance checks.
Business Continuity & DR
Business impact analysis, service dependency mapping, and DR exercise management.
People Lifecycle
Joiner-mover-leaver automation with HRIS sync, access provisioning, and secure offboarding.
Respond
Coordinate the response
Give incidents and remediation a clear owner, workflow and record of decisions.
Incident Management
Structured incident workflows with evidence capture and regulatory notification tracking.
Agentic Remediation
Policy-governed remediation with configured approvals, execution and verification.
Vulnerability Disclosure
Public intake, approved disclosure policy and governed vulnerability handling.
Prove
Organise controls and evidence
Connect policies, audits, training and governance work to the requirements you need to demonstrate.
Compliance Automation
Map controls to 65+ frameworks. Collect evidence automatically. Stay audit-ready.
Policy Management
Automate policy lifecycle from drafting through approval, distribution, and attestation.
Audit Management
Plan, execute, and report on audits with structured evidence packs and findings tracking.
Staff Training
Assign, track, and evidence compliance training across your workforce.
Privacy & Data Protection
ROPA, DPIA, DSAR, consent management, breach notification, and Privacy by Design.
Quality Management
ISO 9001 QMS with CAPA, process mapping, internal audits, and management review.
Evidence
Prepare evidence for external review
Bring records together for sharing with the people who need to assess them.
Beyond software
Testing and certification, delivered with Fig Group.
Commission a security test or work towards a certification alongside your platform activity. MSPs can offer these services under their own brand and keep the client relationship.
Choosing your scope
How to combine the platform with your existing tools and specialist services.
How do these capabilities fit together?
Fig Group connects assets, findings, policies, controls and evidence. Your team can manage related work in the same platform rather than moving each activity into a separate tracker.
Do we need every capability?
No. Start with your priorities and confirm the appropriate scope with our team. We will discuss the integrations, workflows and access your organisation needs.
Does the platform replace certification or penetration testing?
No. Platform workflows, scheme assessments and specialist testing serve different purposes. Fig Group can provide certification and security testing alongside the platform, with the scope of each engagement agreed separately.
Can an MSP use Fig Group for several clients?
Yes. MSPs use Fig Group to manage client security and compliance work and can white-label services while retaining the customer relationship. Fig Group also works with MSPs to certify their clients.
Not sure where to start?
Tell us about your clients, current systems and the work you want to bring together. We will help you define the right scope.