← Consultancy
Engineering & implementation

We find it. We can fix it too.

Certified engineers who design, deploy and harden your security stack, from firewalls and identity to SIEM and cloud, then hand it back to your team fully documented.

Fixed-scope projectsVendor-neutralDocumented handoverFull knowledge transfer
Project · Zero Trust rolloutENG-2026-044
Week 1 Design signed offIdentity, device and network policy Done
Week 3 Conditional access liveMFA on 100% of accounts Done
Week 5 Segmentation deployedPalo Alto, 14 zones In progress
Week 6 Handover to your teamRunbooks, detections, docs Scheduled
Why it's different

Implementation that stays secure after the engineers leave

The usual way With Touchpoint
A reseller installs what they sold you Vendor-neutral engineers deploy what your risk actually needs
Projects end with a config nobody documented Every change documented, with runbooks and an as-built design
Hardening drifts within months Baseline documented, with drift checks at handover
New tools generate alerts nobody watches Logging configured and sent to your SIEM or SOC from day one
Pentest findings wait in a backlog Our engineers close them and re-test each fix
What we build

Six areas we engineer and implement

Network security Firewalls (Palo Alto, Cisco, Fortinet), segmentation, IDS/IPS and secure remote access.
Identity & access Entra ID, MFA, conditional access, privileged access management and SSO.
Cloud hardening Azure, Microsoft 365, AWS, GCP and IONOS to CIS benchmark, as code where you want it.
SIEM & XDR deployment Microsoft Sentinel, Defender XDR and log pipelines, tuned before they go live.
Zero Trust & SASE Device trust, least-privilege access and SASE/SSE rollouts.
Email & endpoint security Mail filtering, DMARC, EDR deployment and device hardening.
How it works

From design to monitored handover

  1. 01 Scope A fixed scope, price and timeline, agreed before work starts.
  2. 02 Design An architecture signed off by your team, mapped to your risks and frameworks.
  3. 03 Build Staged changes with rollback plans and agreed change windows.
  4. 04 Verify Tested against CIS benchmarks and, where agreed, a targeted pentest.
  5. 05 Hand over Documentation, runbooks and training for your team.
What you get

A working control, not a half-finished project

Every project closes with the evidence your auditors, insurers and team will need.

✓ As-built designArchitecture, decisions and configuration, documented.
✓ RunbooksHow to operate, change and recover each component.
✓ Benchmark reportBefore and after, against CIS and vendor best practice.
✓ Knowledge transferHands-on sessions for your IT team.
✓ Monitoring rulesMonitoring and alert rules for what we built.
✓ Audit evidenceMapped to the controls it satisfies.
Engagement options

Three ways to engage

Fixed scope Project A defined build with a fixed price and timeline.
  • ✓Design, build and handover
  • ✓Change windows agreed with you
  • ✓Documentation and runbooks
  • ✓30 days of post-go-live support
Get a fixed quote →
Most flexible Remediation sprint Close a backlog of pentest or audit findings.
  • ✓Findings prioritised by risk
  • ✓Fixed number of engineer days
  • ✓Each fix re-tested
  • ✓Weekly progress report
Get a fixed quote →
Ongoing Engineering retainer A set number of engineer days each month.
  • ✓Named engineers
  • ✓Roadmap delivery
  • ✓Change requests handled
  • ✓Monthly summary
Get a fixed quote →
Questions

Before you ask

Can you fix what you audit?+

Not for the same client in the same audit period. Where we sign an independent audit (ISO 27001, CCPA, DORA), our audit and engineering teams are kept separate, and we tell you up front.

Are you tied to any vendor?+

No. We recommend what fits your risk and budget, and work with the tools you already own where they do the job.

Do we need other Touchpoint services?+

No. Engineering is a standalone service and works with your existing tools and providers.

Who owns the result?+

You do. Configurations, documentation and credentials are handed over in full.

Turn findings into fixed

Tell us what needs building or fixing. We’ll come back with a fixed scope, usually within two business days.

Scope a project
Other consultancy services Penetration testing→ Cloud security→ Tabletop exercises→ vCISO→