
Caelius Consulting specializes in Salesforce, MuleSoft, AI, automation, system integration, CRM, data analytics, and managed services. It engaged Coral eSecure to establish a structured SOC 2 program and prepare for a SOC 2 Type 2 attestation.
Phase 1 – Scope and Business Understanding
We started by understanding Caelius Consulting's services, technology environment, locations, people, customers, and applicable Trust Services Criteria (TSC) necessary to define the scope. The scope helps set a boundary. The boundary is required for risk assessment, gap analysis, and ultimately what the CPA firm will publish in its final report.
Phase 2 – Gap Analysis and Risk Assessment
We worked with each team in the organisation to discuss their scope of work and the scope of controls. They did have several controls in place. However, as with any other organisation, when you conduct a formal SOC 2 control-by-control analysis, you do come across several gaps. With their business services and information systems in scope, we also conducted a detailed risk assessment. The list of gaps and security risks became the input to their risk register.
Phase 3 – Control Design, Training, Policy Documentation and Implementation support
This phase is the foundation phase and takes much of the time. We assisted each team in scope with four-dimensional support: training and awareness, policies and procedures, risk mitigation and implementation support.
Each team member nominated underwent individual sessions to understand the ‘why’ behind the SOC 2 aspect. We customised the policies covering all security aspects, including SOC 2 requirements and those mandated by their customers and business stakeholders. An example of that is that we not only assisted in designing and defining their business continuity plans, but also assisted in testing the restoration.
In such engagement, there are several security risks and vulnerabilities. We assisted them in taking the right decisions. For those they decided to treat, we tracked them through to closure, resulting in overall enterprise risk reduction.
Phase 4 – Control Measurement
Once the implementation was completed, we had to test the effectiveness of the newly published policies. We published these reports with a score that gave stakeholders assurance that the SOC 2 governance system was not just well designed but also working well. The context moved from "we have a control" to "we can demonstrate that the control works."
Phase 5 – Internal Audit and Management Review
Finally, before the independent CPA examination, an independent team from Coral conducted an internal audit covering the applicable SOC 2 requirements. As part of this, the team conducted interviews, challenged them with 'what-if' scenarios, read documented policies, and verified implementation artifacts. Like any other audit, there were areas of improvement. The results provided management with an independent view of the SOC 2 program's effectiveness and readiness.
At this point, they had completed all baseline requirements and had an ongoing governance program in place.
Phase 6 – Independent CPA Examination Support
The CPA assessment involves three phases: interviews, document review, and testing of controls. The preparation completed during the engagement enabled the client's teams to respond to interviews, document requests and control-testing requirements during the independent CPA examination.
The Outcome
Caelius Consulting established a structured governance program with clear responsibilities, documented controls, risk management, evidence of control performance, and ongoing monitoring. In addition, they had an annual SOC 2 plan to look ahead.
For Coral, the real transformation was the ability to reduce risk, implement new controls, and design and document a governance structure that ensures an ongoing security governance framework, reducing the likelihood of a cybersecurity incident in future.
© 2026 www.coralesecure.com. All rights reserved | Privacy Policy