Services

Strategic advisory for the boardroom and the audit table.

I.

Virtual CISO & Virtual DPO

Interim or fractional senior leadership for security and privacy. Board-level reporting, programme oversight, incident command, and supervisory authority liaison on an annual or quarterly retainer.

  • Board and audit-committee briefings
  • Strategic roadmap and KPI ownership
  • Incident command and post-incident review
II.

Information Security Governance

Design, revision and operationalisation of security governance for medium-to-large enterprises. Policy architecture that is lived, not shelved—aligned to business risk appetite and auditor expectations.

  • Policy revision, updates and greenfield creation
  • Governance framework aligned to ISO 27001 / NIST CSF
  • Board-ready policy dashboards and attestation packs
III.

Risk & Incident Management

Pragmatic risk and incident management that balances rigour with operational reality. Frameworks your teams will actually use, and training that changes behaviour rather than checking a box.

  • Risk framework development and appetite calibration
  • Incident response process design and playbooks
  • Tabletop exercises and role-specific training
IV.

Secure Software Development Lifecycle Governance

Governance overlay for engineering organisations building or procuring software at scale. From policy to pipeline, ensuring security is an enabler of velocity, not a blocker.

  • SDLC security framework and stage-gate design
  • Secure coding standards and supplier security requirements
  • Developer and engineering-lead training programmes
V.

Compliance Programme Build-out

End-to-end design and stand-up of governance programmes against NIST 800-171, CMMC, ISO 27001 and GDPR. Includes policy architecture, control mapping, RoPA, DPIA templates and internal audit enablement.

  • Gap analysis against target framework
  • Control mapping and policy library
  • Internal audit coaching and evidence packs
VI.

Regulatory Readiness Assessments

Focused diagnostics ahead of certification, customer assurance reviews or regulatory inspection. Practical, prioritised remediation plans, not pages of generic findings.

  • CMMC Level 2 pre-assessment
  • EU AI Act conformity readiness
  • EU CRA product-security gap analysis
VII.

M&A & Investment Due Diligence

Buy-side and sell-side security, privacy and compliance diligence. Materiality-focused findings that hold up under counsel review and integration planning.

  • Pre-LOI risk triage
  • Confirmatory diligence and red-flag reports
  • Day-one integration playbooks

Engagements typically begin with a confidential conversation.

Open a Discussion →