MediSync Health · 2025
Certification without pausing the product roadmap
ISO 27001 readiness delivered in twelve weeks, with zero major non-conformities at external audit and eleven engineering days per quarter reclaimed from manual evidence gathering.
- Industry
- Health technology
- Location
- Dublin, Ireland
- Engagement
- 12 weeks
- Team
- 2 NordsCode engineers, 4 client engineers
Outcomes
- 0Major non-conformities at external audit
- The Stage 2 assessment returned three minor observations, all closed within the four week window. Certification was issued seven months after the engagement began.
- 11 daysEngineering time reclaimed per quarter
- Access reviews, backup verification and vulnerability reporting now generate on a schedule. The previous quarterly evidence collection consumed roughly eleven engineer-days of manual work.
- 94%Reduction in standing production credentials
- From 68 long-lived access keys and 31 broadly privileged accounts to 4 break-glass credentials with alerting on use, replaced by short-lived federated access everywhere else.
The challenge
What we found when we arrived.
MediSync Health provides appointment and patient communication software to private clinics across Ireland and the United Kingdom. Two hospital group prospects, together worth roughly EUR 400,000 in annual recurring revenue, had made ISO 27001 certification a condition of signature, with a deadline nine months out.
The engineering team of nine had built the product carefully but the environment had grown without an access model. There were 68 long-lived access keys across three cloud accounts, production database credentials in a shared password manager entry used by most of the team, and no record of who had accessed what. Evidence for the audit did not exist in any collectable form. The board's concern was straightforward: certification work would consume the roadmap for a quarter and the hospital deals would slip anyway.
Our approach
What we did, in the order we did it.
Sequence matters more than tooling on engagements like this one. Each step below existed because the previous one produced something the next one needed.
- 01
Separate what matters from what merely scores badly
The initial posture review produced 213 findings. Ranked against MediSync's actual threat model and the certification scope, 19 were genuinely urgent. Publishing that distinction early stopped the team from spending its first month on low-severity noise.
- 02
Close the credential problem first
Single sign-on, role-based access and short-lived federated credentials, rolled out account by account with a break-glass path tested at each step. The 68 standing keys were reduced to 4 audited break-glass credentials over five weeks without locking anyone out of production.
- 03
Make evidence a by-product, not a project
Access reviews, change approvals, backup restoration tests and vulnerability scans wired to run on a schedule and write their output to an evidence store. What used to be assembled by hand each quarter now accumulates continuously.
- 04
Write policies describing the real environment
Every policy statement was checked against a control that actually existed. Where the two disagreed we changed the environment rather than softening the wording, which is the reason the Stage 2 assessment found nothing major.
The results
What changed, and how we know.
MediSync passed Stage 2 with zero major non-conformities and three minor observations, all closed inside the four week window. Certification was issued seven months after the engagement started, comfortably ahead of the nine month contractual deadline, and both hospital group contracts were signed.
The ongoing cost is the part the team notices most. Quarterly evidence collection that previously consumed around eleven engineer-days now runs on a schedule and requires review rather than assembly. Product delivery did not stop: the team shipped its two largest planned features during the twelve week engagement, because the security work was engineering rather than committee time.
What it was built on
- AWS
- AWS IAM Identity Center
- HashiCorp Vault
- Terraform
- Trivy
- GitHub Actions
Engagement type
Security and ComplianceRecognise any of this?
Most engagements start with a call describing a situation that sounds a lot like one of these. Tell us yours and we will say plainly whether we can help.