Exsol Solfield LTD was established in 2015 as a digital products innovator. In 2022 the company moved into cybersecurity, and everything we have built since answers the same question: how does an organisation know its defences actually work?
The first answer was ENLISEC, a security learning management and phishing simulation platform. It now supports threat awareness and workforce readiness across more than 25 corporate enterprises, more than 30 SMEs, and federal and state government ministries, departments and agencies.
Security assurance is usually assembled from disconnected products. Awareness training sits in one place, supplier questionnaires in another, control evidence in a third, and none of them agree. The gaps between them are where risk goes unnoticed.
So VASSURE and CONFICIENT were designed as parts of the same system rather than separate purchases. VASSURE covers third-party risk: vendor onboarding, risk assessment, evidence collection and remediation tracking. CONFICIENT covers control assurance: control libraries, adequacy and effectiveness testing, attestation workflows and audit readiness. Together with ENLISEC they span people, suppliers and controls, which is most of what an auditor will ask about.
Why we automate it
Most assurance work is done once a year, by hand, and is out of date by the time it is filed. Automating it changes what is possible: vulnerabilities are monitored continuously, emerging risks surface while they are still small, regulatory alignment is maintained rather than reconstructed, and leadership gets oversight across the whole digital estate instead of a snapshot.
That is the difference between a compliance exercise and genuine cyber resilience.
Standards, not our own scoring
Our platforms map to recognised global frameworks including ISO 27001, ISO 42001, NIST CSF, DORA, NDPA, GDPR, Cyber Essentials, OWASP MASVS and CSA CAIQ. We deliberately do not invent proprietary scoring, because a result that only makes sense inside our product is a result you cannot hand to an auditor, a regulator or a customer.
How we choose what to build
Our product direction is grounded in the everyday work behind security assurance: educating users, testing phishing readiness, assessing suppliers, validating controls, preparing evidence and reporting posture to stakeholders. Each product takes one of those tasks and makes it repeatable.