Consultancy

Advice that turns into tracked work

Security leadership, testing and cloud expertise from people who run security operations. Every engagement is vendor-neutral and separate from our managed services, so our advice is never shaped by what we sell.

Scope an engagement
01 · Virtual CISO

Security leadership without the full-time hire

A senior security leader who owns your strategy, reports to your board and works alongside your IT team, a few days a month.

Best for: organisations without a CISO, or preparing for growth, funding or certification. Explore vCISO →
✓ Security strategy and roadmapA 12-month plan tied to your risks, budget and business goals.
✓ Board and investor reportingQuarterly updates in plain language, backed by evidence.
✓ Policy and governancePolicies written, approved and actually used.
✓ Customer and supplier assuranceSecurity questionnaires and due-diligence calls handled for you.
02 · Penetration testing

Manual testing by experienced testers

Real attackers don’t run a scanner and stop. Our testers chain weaknesses the way they would, scoped to where you are actually exposed.

Best for: annual assurance, new releases, customer requirements and certification. Explore Penetration testing →
✓ Web applications and APIsAuthentication, access control, business logic and injection.
✓ External and internal infrastructurePerimeter, Active Directory and lateral movement.
✓ Cloud configurationAWS, Azure and Google Cloud identity and exposure paths.
✓ Findings portalEvery finding is risk-ranked and retested free once fixed.
03 · Cloud security

Secure the cloud you already run

Posture reviews and expert remediation guidance for AWS, Azure and Google Cloud, with a logging plan so issues don’t go unseen.

Best for: fast-growing cloud estates, M365 tenants and pre-audit clean-ups. Explore Cloud security →
✓ Posture reviewBenchmarked against CIS and provider best practice.
✓ Identity and accessConditional access, privileged roles and service accounts.
✓ Logging and detectionThe right logs switched on and sent where they’re watched.
✓ Remediation guidanceClear, prioritised recommendations your team can act on.
04 · Tabletop exercises

Rehearse the worst day before it happens

Facilitated scenarios for your leadership and technical teams, from ransomware to supplier breach, so everyone knows their role when it counts.

Best for: leadership teams, insurers’ requirements and incident-plan testing. Explore Tabletop exercises →
✓ Realistic scenariosBuilt from current threats and your own environment.
✓ Executive and technical tracksDecisions for leaders, actions for responders.
✓ Incident plan reviewGaps in your plan identified, with recommended changes.
✓ Written after-action reportFindings and actions, each with an owner.

Explore →
05 · Engineering & implementation

We find it. We can fix it too.

Certified, vendor-neutral engineers who design, deploy and harden your security stack, then hand it back to your team fully documented.

Best for: closing pentest and audit findings, new security tooling and Zero Trust rollouts. Explore Engineering →
✓ Network securityFirewalls, segmentation and secure remote access.
✓ IdentityEntra ID, MFA, conditional access and PAM.
✓ Cloud hardeningAzure, M365, AWS, GCP and IONOS to CIS benchmark.
✓ SIEM & XDRDeployed and tuned before go-live.
06 · Incident response retainer

Responders on call before you need them

Pre-agreed terms and hours, with investigation, containment and recovery from one team.

Best for: insurer requirements, regulated organisations and anyone without an IR provider. Explore IR retainer →
✓ 24/7 responseGuaranteed response times.
✓ ForensicsTimeline, root cause and evidence.
✓ RecoveryClean rebuild of servers, AD and cloud tenants.
✓ ReadinessIR plan review and tabletop included.
08 · Third-party risk

Know which suppliers could hurt you

Suppliers tiered, assessed and tracked in a live register, ready for DORA and NIS2.

Best for: financial entities, essential services and customer audits. Explore Third-party risk →
✓ Supplier tieringEffort where the risk is.
✓ AssessmentsEvidence chased and reviewed for you.
✓ Exposure checksOn your critical suppliers.
✓ DORA registerRegulator-ready.
09 · AI governance

Use AI safely, and prove it

Shadow AI discovery, policy and a governance programme aligned to the EU AI Act and ISO 42001.

Best for: organisations adopting AI or selling into the EU. Explore AI governance →
✓ Shadow AI discoveryWhat’s in use and with what data.
✓ PolicyAcceptable use, trained and signed.
✓ Risk classificationAgainst EU AI Act tiers.
✓ ISO 42001 readinessGap assessment and build.
10 · M&A cyber due diligence

Know the cyber risk before you sign

Independent outside-in and data-room diligence, with cost-to-fix estimates and a 100-day plan.

Best for: private equity, acquirers and portfolio operating partners. Explore M&A due diligence →
✓ Outside-in scanNo target access needed.
✓ Red-flag reportTo deal timelines.
✓ Cost to fixFor the deal model.
✓ 100-day planDelivered by our engineers if you want.

Not sure which you need?

Tell us what's worrying you and we'll recommend the smallest engagement that answers it. Fixed-price scopes, agreed before we start.

Get in touch