Security programme review
A clear view of your security programme and the risks that matter.
ISO 27001, NIST CSF and CIS Controls assessments, with gaps ranked by business impact.Independent security practice
Build a security programme that works: clear governance, practical policies, assurance and ownership.
Contact usWhat we do
A clear view of your security programme and the risks that matter.
ISO 27001, NIST CSF and CIS Controls assessments, with gaps ranked by business impact.Practical policies and standards people can use.
Policy, standards and control mapping for audits, customer reviews and day-to-day delivery.Clear ownership and habits that lower risk.
Operating model, RACI, awareness, supplier assurance and security built into delivery.Engagements
A fixed-scope review of your programme, policies or a specific capability, ending in findings and a practical roadmap.
A defined piece of work with a defined outcome: a policy framework, certification readiness programme or awareness programme build.
Fractional security leadership from a couple of days a month, with ongoing guidance and momentum.
How I work
No software resale, no referral fees and no commercial interest in your buying decisions.
A plan suited to your team, budget and business—not a maturity model set to its highest bar.
Reports and policies that leaders, engineers and auditors can all use.