Services
Sixteen engagements across six categories.
Most are fixed-scope and fixed-price — you can read what is included, see a sample of the output, and decide without a sales cycle. The rest are relationships rather than projects, and are priced that way.
The rules and the paperwork
GRC & Compliance
Making sure a company has the right policies, follows the right regulations, and can prove it. This is the flagship category — it is where the Annex A Explorer and the scope wizard live.
ISO 27001 Gap Assessment
Find out exactly what is missing before you attempt certification.
Read more GRC & ComplianceNIS2 Applicability & Gap Assessment
First establish whether NIS2 binds you at all. Then close the gap.
Read more GRC & ComplianceRegulation Translation
Dense legal text turned into a technical to-do list your engineers can act on.
Read more GRC & ComplianceNIST CSF Maturity Benchmark
A scored maturity snapshot, not a certificate.
Read more GRC & ComplianceCompliance Framework Design
Building the internal rulebook — and the reason each rule exists.
Read more GRC & ComplianceSecurity Policy Development
Writing — or fixing — the specific documents inside the rulebook.
Read moreTraining humans, not just firewalls
Security Culture
Most breaches start with a person clicking something they should not have. This category is about changing what people do, measured — not an annual video nobody watches.
What could go wrong, and what are we doing about it
Risk Management
Risk work that leadership actually reviews. Scored, owned, and revisited — not a spreadsheet built once for an auditor and never opened again.
Cyber Risk Assessment & Risk Register
A scored list of business risks leadership actually reviews.
Read more Risk ManagementThird-Party & Vendor Risk Management
Checking whether your suppliers are secure, because their breach becomes your breach.
Read more Risk ManagementBusiness Continuity & Incident Response
The plan for when it happens — tested before you need it.
Read moreThe hands-on defence side
Technical Security
The half of the market that usually sits in a different company from the compliance half. Delivered by vetted specialists brought in per engagement, scoped and quality-controlled by the practice.
Penetration Testing (VAPT)
A specialist tries to break in, on purpose, so you find the holes first.
Read more Technical SecurityManaged SOC
An outsourced team watching your systems for signs of attack.
Read more Technical SecurityDevSecOps
Security checks built into the pipeline, so problems are caught before code ships.
Read more Technical SecurityWeb & Mobile App Security Review
The same rigour, aimed specifically at your own applications.
Read moreSenior expertise without a full-time hire
Leadership Advisory
A senior security leader on a monthly relationship instead of a payroll line. For organisations that need direction and accountability more than they need another tool.
The urgent, sales-blocking stuff
Fast-Turnaround
Work with a deadline attached to a contract. Scoped in a call, delivered in days.