Practice 02

Security that survives the audit and the attacker.

Plenty of security work passes an audit but wouldn't slow down an intruder. Plenty more is technically sound but generates no evidence an auditor can accept. We've spent thirty years on both sides of that gap — as the CISO being audited, and as the architect designing what the auditors were checking. Our consulting work closes it.

Service areas

Six areas of deep practice.

Assess

Risk & maturity assessment

A structured, evidence-based view of where you actually stand — against NIST CSF 2.0, ISO 27001, CIS Benchmarks or your regulator's expectations — with a remediation plan ranked by risk, not by vendor.

  • NIST CSF 2.0, NIST 800-53 & ISO 27001 assessment
  • Cloud security posture & CIS Benchmark review
  • Threat modelling (STRIDE) — complex models in days, not months
  • Legacy platform security forensics & migration risk

Comply

Compliance & certification

We run certification programmes end to end: scoping, control design, evidence pipelines, auditor management and the surveillance cycle after the certificate arrives. We build evidence collection into how your teams already work — including automating it — so compliance stops being an annual fire drill.

  • Programme leadership through to certification
  • Policy & control documentation that engineers can follow
  • Automated evidence pipelines
  • Auditor & assessor relationship management

Identity

Identity & access management

IAM is where security programmes go to stall. We've led IAM transformations at some of the UK's largest insurers, pharmaceutical manufacturers and retailers — from strategy and standards through IGA architecture, PAM, and phishing-resistant authentication for both office and operational technology.

  • IAM strategy, standards & maturity assessment
  • IGA & PAM architecture (SailPoint, CyberArk)
  • Passwordless & phishing-resistant MFA (FIDO2, CBA)
  • ABAC policy design & access modelling

Detect

SOC, SIEM & detection

Security operations designed around the threats you actually face, not the dashboards a vendor wants to sell. We design SOCs, select and negotiate tooling, and build the use cases and incident response that make the investment pay.

  • SOC design, operating model & product selection
  • SIEM architecture (Sentinel, CrowdStrike, XSIAM)
  • Detection use cases & incident response playbooks
  • Cyber threat intelligence — strategic to tactical

Govern & secure

AI governance & AI security

Your teams are already using AI; the question is whether it's governed and secured. We build ISO 42001-anchored AI governance frameworks — including for agentic AI — and the security controls that treat models and agents as new identities, new attack surface and new things to monitor. Pragmatic enough that people follow them, rigorous enough that customers and regulators accept them.

  • AI governance framework, including agentic AI (ISO 42001-aligned)
  • Governance processes: intake, risk tiering, approval and review
  • Model cards and AI system inventory
  • AI Architecture Review Board (AI ARB) design and operation
  • Identity & access management for AI agents and services
  • SIEM for AI: logging, telemetry and detection for models and agents
  • AI detection & response (AIDR)
  • Security review of AI tools, pipelines and agentic workflows

Protect

Data protection & DLP

Data protection strategy that starts from what data you hold and who needs it — then applies classification, DLP tooling and controls proportionately, so protection doesn't become obstruction.

  • Data classification frameworks & cloud data policy
  • DLP strategy & implementation (Microsoft Purview)
  • Key management & encryption standards
  • GDPR and data privacy compliance across 33 countries

Frameworks we run

Certifications delivered, not just advised on.

The difference between advising on a framework and owning it through certification is the difference between a report and a result.

FrameworkTypical driverWhat we do
ISO 27001 Enterprise customers, international markets ISMS design and implementation, certification and surveillance audit ownership
SOC 2 US enterprise & SaaS buyers Control design, evidence automation, Type I → Type II programme leadership
GovRAMP / StateRAMP US state & local public-sector sales Full programme leadership: control register, policies, 3PAO assessment, authorisation
Cyber Essentials+ UK government & supply-chain requirements Gap assessment, remediation and certification
DORA EU financial services & their ICT suppliers Gap analysis, ICT risk framework, resilience testing and register of information
ISO 42001 Demonstrable AI governance AI management system design anchored to how your teams actually build and buy AI
NIST CSF 2.0 Board-level risk framing, US customers, maturity benchmarking Maturity assessment against the six functions, target profile, prioritised roadmap
NIST SP 800-53 Federal, state and regulated US environments; underpins FedRAMP and GovRAMP Control selection and tailoring, System Security Plan authoring, control implementation evidence
HIPAA Handling protected health information for US healthcare clients Security Rule risk analysis, safeguards assessment, BAA readiness and remediation
HITRUST CSF US healthcare buyers demanding a certified assurance Scoping, readiness assessment, control mapping and route to validated assessment
NCSC CAF UK critical national infrastructure, NIS Regulations, public-sector operators Self-assessment against the four objectives and contributing outcomes, gap analysis and improvement plan for regulator review
Enhanced CAF (eCAF) Operators of essential services in higher-risk sectors requiring deeper assurance Assessment against the enhanced profile, evidence pack and remediation roadmap aligned to your competent authority's expectations
GDPR / UK GDPR / DPA 2018 Baseline UK/EU obligation for any organisation processing personal data Compliance assessment, DPIAs, records of processing, privacy-by-design integration and remediation
Global data privacy Multinational operations across 33 jurisdictions — CCPA/CPRA, PIPEDA, LGPD, PDPA, POPIA, PIPL and others Multi-jurisdiction gap analysis, harmonised control framework, cross-border transfer mechanisms and local-law overlays

Shape of an engagement

Fixed scope, honest findings, usable output.

Consulting engagements are scoped as discrete pieces of work with a defined deliverable — an assessment, a strategy, an architecture, a certification. Three commitments apply to all of them:

No landgrabThe deliverable is designed to be handed over, not to create dependency. If a finding means "hire someone permanent", the report says so.
No vendor biasWe hold no reseller agreements and take no commissions. Tooling recommendations are ours alone — and we'll negotiate the pricing on your side of the table: recent examples include $2M taken off a CrowdStrike renewal, 50% off Vanta and 45% off Checkmarx.
No shelfwareEvery document is written for the person who has to use it: policies engineers can follow, board packs executives will read, evidence auditors will accept.

“A security assessment that ranks findings by severity alone is half-finished. The useful question is always: which three things, done this quarter, remove the most risk?”

— On prioritisation

Facing an audit, a framework, or a finding?

Send us the requirement — even if it's just the customer questionnaire that started it. We'll come back with a straight view of scope, effort and sequence.

Start a conversation