Case study: Halco and Securious
Securious has been working with Halco since 2018, delivering a comprehensive programme spanning PCI DSS, ISO 27001, Cyber Essentials Plus, ASV and internal vulnerability scanning, and targeted penetration testing.
About Halco
Halco is the UK’s no.1 independent supplier of cigalikes, dedicating more than a decade to helping people quit smoking – and stay quit. The company has an established ISO 9001 quality management system and wanted to strengthen information security and cardholder data protection across its operations.
About Securious
Securious is the South West’s leading Payment Card Industry Qualified Security Assessor and cyber security company. We help clients with Governance, Risk and Compliance (PCI DSS, ISO 27001, PCI 3DS, Cyber Essentials and Cyber Essentials Plus); we offer a Managed Detection and Response service (helping clients stay secure with live 24/7 monitoring and visibility of their environments, threat detection and automated alerts, which are overseen by our analysts), and penetration testing services.
The objective
Halco set out to meaningfully improve their cyber security, not just pass an assessment. They wanted confidence that the right controls were in place across the business and that cardholder data was properly protected as they grew.
They brought in Securious to help design and deliver a joined-up programme covering PCI DSS, an information security management system built around ISO 27001 (alongside their existing ISO 9001), Cyber Essentials Plus, and practical vulnerability management (ASV external scanning, internal scanning and targeted web application penetration testing).
The challenge
This was not a single project but an ongoing task of bringing several strands together so they reinforced one another. PCI DSS activity had to sit neatly alongside day-to-day operations and ISO management work, with ISO 27001 implemented and merged with the existing ISO 9001 into a single, integrated system. Ownership needed to stay clear across teams, including Halco’s own web function, as requirements evolved.
Just as importantly, the programme had to identify opportunities for improvement – from tightening processes and evidence to refining scanning and testing cycles – so security kept moving forward.
The solution
Securious completed a full PCI DSS assessment in 2019 and has supported Halco’s PCI each year since, covering assessment activity and evidence, ASV external scanning, internal vulnerability scanning and, where required, web application penetration testing. The engagement has always been practical and local: on-site when helpful, quick answers when things change, and a single-team approach that keeps decisions moving.
Halco joined Securious’ in-person ISO Academy and, with our guidance and materials, implemented ISO 27001 in a way that complemented their existing ISO 9001 certification, before certifying in 2020. Because ISO 9001 was already mature, we worked with Halco to help them align relevant controls and mandatory documents rather than duplicating effort, bringing information security into the same plan-do-check-act cycle the business already used. In 2021 they achieved Cyber Essentials Plus, adding clear technical assurance alongside PCI and ISO.
Throughout, the relationship has been close, local and responsive. The team call on us between milestones for practical advice, and we operate as an extension of their team to keep momentum.
The results
Halco are now in a strong position. PCI DSS is maintained year on year without unnecessary disruption, supported by regular ASV and internal vulnerability scanning and targeted web application testing. ISO 27001 was merged with Halco’s ISO 9001 as a single, integrated management system, and Cyber Essentials Plus provides clear technical assurance.
The programme runs smoothly because ownership is clear, evidence is tidy and up to date, and improvement opportunities are picked up and acted on. With a local, collaborative relationship and quick access to practical advice, Halco treat Securious as an extension of their team.
Darren, QSA at Securious, comments:
“Halco set the tone from day one. They wanted to be in genuinely good shape, not just scrape through an assessment, and they have stayed true to that. Our work together spans PCI DSS, ISO 27001 alongside ISO 9001, Cyber Essentials Plus, regular ASV and internal vulnerability scanning, and targeted web application testing. Because we are local, we can jump on site when it helps and keep decisions moving. The result is a programme with clear ownership, tidy evidence and steady improvements year after year. It feels less like a supplier relationship and more like being the team at the end of the corridor.”
Clare Nickson, COO at Halco, comments:
“We wanted confidence that we were doing this properly across the board. Securious helped us make sense of the moving parts, align ISO 27001 with our ISO 9001, and keep PCI practical without creating extra paperwork. They keep the scanning and testing on track, explain what matters and why, and are close by when we need them. It is collaborative and straightforward. We get quick answers, sensible recommendations and a clear path forward, which means we can focus on running the business knowing our security is in good shape.”
Learn more about Halco at their website
If you are interested in PCI DSS Compliance, click here to read more or get in touch using the contact form below