Ask a security team to enumerate their controls and they will show you an architecture: firewalls, endpoint detection, identity management, encryption at rest. All necessary. Yet walk through any serious breach post-mortem and you will find, alongside the technical failures, a human one — something seen that should not have been seen, something said that should not have been said, access granted on familiarity rather than principle.
An IT provider occupies a peculiar position of trust. Its engineers hold administrative keys to everything: the chief executive's mailbox, the board's shared drive, the unreleased results, the dispute with a supplier conducted entirely over email. No contract clause fully governs what a person with that access notices. What governs it is culture — and culture is a control that must be selected for, trained, and enforced like any other.
In practice, discretion decomposes into habits. Engineers who read only what the task requires. Screens locked in meeting rooms as a reflex. Client names never traded as social currency, in a sector where name-dropping is endemic. Access reviewed and surrendered when a mandate changes shape. Incidents described to outsiders — including to us, in our own marketing — in terms that identify no one.
None of this appears on a compliance certificate, though it underwrites every one of them. ISO clauses and GDPR articles assume, at their base, an organisation whose people can be trusted with what they inevitably see.
When we say discretion is a pillar of our standard, this is what we mean: not a promise of silence, but an operational discipline, practised daily, by people hired partly for their ability to practise it. In environments where reputation is the client's most valuable asset, it is not a soft virtue. It is a hard control.
Vercorro · The Journal