Skip to content
The Fig Group approach

Security, compliance and certification.
Working together.

A finding is useful only when someone can act on it. Fig Group brings the software, specialist services and certification support together so your team can manage the work from the first review to the next assessment.

One partner for connected security and compliance work.

Use the platform to manage day-to-day activity, bring in specialist testing where you need it, and work with Fig Group for certification. Each service has a clear scope and a direct route to the team delivering it.

Manage and monitor

Bring client oversight, security and compliance monitoring, risks, policies, remediation tasks and reporting together on the Fig Group platform.

Explore the platform

Find security weaknesses

Specialist vulnerability scanning, device and cloud reviews, public exposure checks, code reviews and penetration testing, with findings your team can act on.

Explore security testing

Get certified

Cyber Essentials, Cyber Essentials Plus and Defence Cyber Certification Level 0 and Level 1, delivered through Fig Compliance Ltd.

Explore certification

Review risk in the context of your environment.

Bring the discussion back to the assets, findings and dependencies behind a priority, with a shared view for the people responsible.

Fig asset mind map connecting internet exposure, identity, sensitive data, endpoints and critical suppliers
Fig mobile app Home screen showing framework compliance, monitoring coverage and device posture
Fig platform · Asset mind map

From requirements to accountable action.

Connect governance to IT service management (ITSM): the operational work of assigning, approving and resolving tasks. Policies and commitments from a due diligence questionnaire (DDQ) should inform that work, not sit in a separate document.

  1. Agree what needs to be delivered

    Start with your clients, internal policies, contractual commitments and certification requirements. Confirm the platform capabilities, integrations and specialist services needed for that scope.

  2. Connect the information to the work

    Bring findings, policies and evidence into the relevant workflows. Define owners, review points and approvals so the team can see what needs to happen next.

  3. Review progress and close the loop

    Track actions and retain evidence of the outcome. Use that record in client reviews, internal oversight and assessment preparation, with open issues still visible.

For MSPs and their clients

Your client relationship. A broader service behind it.

Offer Fig Group’s platform, security testing and certification services under your brand while keeping the client relationship. We agree branding, delivery responsibilities and client communications with you. Certification remains subject to scheme rules: required certification-body details, scheme marks and client declarations are retained.

Internal teams can also work directly with Fig Group, or share oversight with their existing MSP. Agree responsibilities, permissions and reporting before delivery begins.

Compare the service you will actually receive.

The right choice depends on your requirements. Ask to see the relevant workflows and confirm what is included before deciding.

Coverage and integrations

Which client activities can move into the platform, what systems remain, and how will data move between them?

Plan tool consolidation

Delivery and assessment boundaries

Who reviews findings, approves actions and delivers testing? Which certification assessment is required, and what remains the client’s responsibility?

Review specialist services

Evidence behind the claims

Review our certification credentials, published pricing and guarantee terms. Platform access is not a certificate or a guarantee that security incidents cannot occur.

Read our claim evidence

Questions about working with Fig Group

What is included, what stays with your team and how to get started.

What does Fig Group bring together?

Fig Group combines a cybersecurity and compliance platform with specialist security testing and compliance certification services. You can use the relevant services for your organisation or deliver them to clients through an MSP partnership.

Do we have to replace all our existing tools?

No. Start by reviewing your required workflows and integrations with Fig Group. Some work can be consolidated in the platform, while specialist or operational systems may remain in place. Agree coverage before changing your stack.

Does automation guarantee that we remain compliant?

No. Automation helps teams monitor requirements, assign work and retain evidence. People still need to configure the service, review findings and decisions, and complete outstanding work. Certification requires its own assessment.

Can an MSP white-label the services?

Offer Fig Group’s platform, security testing and certification services under your brand while keeping the client relationship. We agree branding, delivery responsibilities and client communications with you. Certification remains subject to scheme rules: required certification-body details, scheme marks and client declarations are retained.

How long does onboarding take?

The timeline depends on the agreed scope, integrations, data and access arrangements. We confirm the onboarding plan with you before delivery; platform setup and certification assessment are separate activities.

See how Fig Group fits your organisation.

Tell us what you need to manage and the services you want to deliver. We will walk through the relevant platform workflows and delivery options.

Discuss your requirements
Fig Group compared with a disconnected, checklist-led workflow
CapabilityFig GroupA disconnected approach
What it isSecurity and compliance platform with separately scoped specialist servicesSeparate tools and evidence repositories
Compliance approachConnect policies, controls, evidence and responsible ownersReconcile policy documents and checklists manually
Integration modelConnect supported tools to findings and follow-up workMove evidence between tools and reports
Policy managementDraft, approve, distribute and track policy acknowledgementMaintain versions and acknowledgements separately
MSP and client alignmentAgree access, responsibilities and client workflowsReconcile separate client and provider records
Event handlingRoute relevant findings into assigned remediation workflowsReview alerts and create follow-up tasks manually
Responsibility trackingRecord owners, deadlines and evidence of completionTrack ownership across spreadsheets and messages
Data modelConnect client, asset, control and risk records in the agreed scopeCombine separate inventories and reports
Gap managementMake unresolved findings and evidence gaps visible for follow-upFind gaps when separate records are reconciled

The comparison describes two operating approaches, not a claim that every competing platform lacks these capabilities. Features and integrations depend on the selected Fig package; no platform guarantees that gaps cannot occur.