Cybersecurity practice
Security that holds up on the worst day
Detection, response and evidence for organisations that cannot justify a round-the-clock team of their own, and for those whose team needs relief.
What we run
Engagements start at one of these and widen. Nothing here is sold as a platform licence; we work with the tooling you already own wherever it is fit for purpose.
01Monitoring and detection
Log sources mapped to the threats that actually apply to you, detections tuned against your environment rather than a vendor default, and alerts that a human triages before they reach you. Coverage follows the working day across three offices.02Incident response
A retained response capability with named contacts, agreed authority to act, and rehearsed playbooks. Post-incident, a written root cause with a corrective action, an owner and a date — the value of a bad night is entirely what changes afterwards.03Identity and access
Joiner, mover and leaver processes that survive a busy quarter. Privileged access brought under control, multi-factor coverage measured rather than assumed, and service accounts inventoried before an auditor finds them.04Vulnerability and exposure management
External attack surface discovery, patch programmes with realistic service windows, and a risk-ranked backlog your engineering leads will actually work through instead of a scanner export nobody opens.05Operational technology and physical systems
Building management, power and cooling controls, access control and CCTV treated as attack surface. Segmentation, remote-access hygiene and vendor connections audited — the systems that keep a facility alive are rarely in the security scope, and they should be.06Cloud and platform security
Configuration baselines, tenancy and network separation, secrets handling, and a review cadence tied to your release process rather than to an annual date.07Governance, risk and compliance
Control frameworks mapped once and reported to several audiences. Third-party and supply chain assessment, board-level risk reporting, and evidence gathered as the work happens rather than assembled in a panic before an audit.08Security for capital projects
Security requirements written into design, procurement and commissioning for new facilities, so that resilience and access control are specified once instead of retrofitted at handover.
Frameworks we work to
We do not sell certification, and we do not pretend a framework is a security programme. We use these as a common language with your auditors, insurers and customers, and we tell you where a control genuinely reduces risk and where it only produces paperwork.
What we will not tell you
That a certificate makes you secure. That a tool replaces a process. That a control we recommended is working when we have not tested it.
If an assessment comes back saying your exposure is smaller than you feared, we say so and reduce the scope. We would rather lose the work than manufacture it.
How an engagement usually runs
Small first step, deliberately falsifiable. If we are not useful you will know inside a month.
Assessment
Two to four weeks. Current state against the threats that apply to you, a ranked set of gaps, and an honest view of which ones are worth money this year.
Build and transition
Detections, playbooks, access controls and reporting stood up with your team alongside, so operating knowledge stays in-house rather than with us.
Run and assure
Monitoring and response on a standing basis, or a quarterly assurance review if you run it yourselves. Either way, one named principal and an agreed escalation route.
Ask us something specific
A worry about one system, a customer questionnaire you cannot answer, an incident you are still cleaning up. Concrete beats general.