The practice
A core team, plus specialists engaged per job.
The compliance work is done by the practice. The technical work is delivered by vetted specialists brought in for the engagement that needs them — scoped, briefed and quality-controlled by the same people who wrote the assessment. You get depth without paying to keep a penetration tester on a bench.
Lead auditor and practice lead
ISO/IEC 27001:2022 Lead Auditor. Owns scope, methodology and quality on every engagement, and is the person who signs the report.
Penetration testers
Brought in per engagement against a defined scope and rules of engagement. Findings are reviewed by the practice before they reach you.
SOC analysts
Detection and response capability delivered through partner operations, with use cases and escalation designed by the practice.
DevSecOps engineers
Pipeline and secure-development work, engaged where an assessment has identified something that needs building rather than documenting.
Regulatory and privacy counsel
Engaged where a determination needs a legal opinion rather than a practitioner's reading.
How an engagement runs
Four stages, and you can stop after any of them.
Scoping call
Thirty minutes, no charge. We establish what applies to you and whether we are the right people. Sometimes the answer is that you do not need us yet, and we say so.
Written scope and fixed price
What is included, what is not, what we need from you, and what you will hold at the end. Priced before you commit.
Delivery
Evidence review, interviews, testing as scoped. Findings shared as they emerge rather than saved for a reveal at the end.
Report and walkthrough
The deliverable, plus a session with the people who have to act on it. Remediation support is a separate decision, not an assumed upsell.