Most organisations start with a spreadsheet. It's fast, free, and flexible. The problem is not the spreadsheet — it's what happens when someone asks to see your evidence, your audit trail, or your board report.
Where spreadsheets break down
A spreadsheet records what you typed. It cannot tell an auditor when a control was implemented, what evidence exists for it, or who verified it. When the ICO or a certification body asks to see your working, "it's in column G" is not an answer.
Compliance is not just a checklist — it is documented proof. Screenshots, policy documents, configuration exports, training records. On a spreadsheet these live in email threads, shared drives, and local folders. Reconnecting them during an audit is a scramble.
A spreadsheet is passive. It does not tell you that your patch management control has drifted, that a policy is overdue for review, or that a new threat has emerged that your current controls don't address. You have to look. Most teams don't look often enough.
The person who built the spreadsheet understands it. Everyone else opens it with hesitation. When they leave, or are unavailable during an audit, the programme goes with them. A platform keeps the programme institutional, not personal.
You start with Cyber Essentials. Then a client asks for ISO 27001. Then you need GDPR documentation. Then DORA. Each framework adds more rows, more tabs, more version control problems. Spreadsheets grow in complexity faster than programmes grow in maturity.
Producing a board-level summary of your security posture from a spreadsheet means copying data into a presentation manually. In Fortify, quarterly posture reports are generated automatically — with trend data and AI-written narrative.
Feature by feature
| Capability | Spreadsheet | Fortify |
|---|---|---|
| Risk register | Manual rows, no scoring logic | Structured register with likelihood/impact scoring and AI-guided identification |
| Evidence management | Links to external files, often broken | Attached to individual controls in the portal, auditable and exportable |
| Audit trail | Who edited a cell, if version history is on | Full timestamped history of control status changes and evidence uploads |
| Policy management | A column with a file path | Policies stored, versioned, and linked to the controls they support |
| Gap identification | You have to know what to look for | AI-guided assessment across digital resilience, GDPR, CE+, ISO 27001, and more |
| Board reporting | Manual: copy data to a slide deck | Auto-generated quarterly report with RAG status and trend commentary |
| Multi-framework mapping | New tab per framework, maintained separately | Controls mapped across frameworks — fix once, evidence applies everywhere |
| Incident management | A log, if you have one | Structured incident lifecycle with ICO reporting decision record |
| Vendor risk | A list of supplier names | Vendor register with questionnaire dispatch, DPA tracking, and risk scores |
| Access control | Shared file, hope nobody edits the wrong thing | Role-based access — admin, editor, viewer, per-org |
| AI assistance | — | Ask Alex and Jacob — AI trained on your programme, not generic answers |
| Certification support | You write the SoA yourself | Assessment output maps directly to CE+, ISO 27001, DSPT, and DORA frameworks |
When a spreadsheet is fine
When to switch to Fortify
The free Digital Resilience Assessment gives you a scored baseline across five key areas, a prioritised action plan, and a PDF report — no account required. When you are ready to move to the portal, your assessment carries over.