Certification readiness
SOC 2 Type 2 and ISO 27001, run as a programme rather than a paperwork exercise. Controls that engineering will actually keep using after the report is signed.
- Gap analysis against the target framework and your customers' questionnaires
- Policy set, control design and implementation with named owners
- Evidence collection that runs on its own, not the week before the audit
- Auditor selection, coordination and remediation through to opinion
Fractional CISO
Senior security leadership at the fraction of a full-time hire you need. Accountable for posture, present in the rooms where it is decided.
- Security strategy and roadmap tied to product and revenue, not to a tool list
- Enterprise risk register, risk assessments and treatment plans you can defend
- Executive and board reporting: posture, incidents, compliance status
- Vendor risk, due-diligence responses and regulated-customer assurance
Cloud & platform security
Architecture and configuration review across AWS, GCP and Kubernetes, done by someone who has run the infrastructure as well as reviewed it.
- Cloud security posture, secure baselines and infrastructure-as-code review
- Identity and access design, secrets management, least privilege that survives contact with engineers
- Kubernetes hardening, network policy and workload isolation
- Central logging, detection and alerting with owners for every alert
DevSecOps & secure SDLC
Security inside the pipeline, where it costs the least. Gates that block real risk and stay quiet the rest of the time.
- Threat modelling, architecture review and code review on the paths that matter
- SAST, SCA and DAST selected, tuned and triaged so findings get fixed
- Build integrity, artefact provenance and dependency control
- Software-supply-chain controls to SLSA levels 1 and 2, with in-toto attestation
Incident response & BC/DR
The plan that gets used at three in the morning, and the rehearsal that proves it works before you need it.
- Incident response plan, severity model and SIRT roles with real escalation paths
- Business continuity and disaster recovery planning, RTO and RPO you can meet
- Ransomware resilience: immutable backups, isolation and tested restore
- Tabletop exercises, root-cause analysis and corrective-action tracking
AI security & governance
Your teams are already using AI. Governance turns that from an unmanaged exposure into something you can describe to a customer or a regulator. We work to the EU AI Act and the NIST AI Risk Management Framework.
- AI-system inventory and risk classification aligned to the EU AI Act
- Governance mapped to the NIST AI Risk Management Framework — govern, map, measure, manage
- Acceptable-use, accountability and human-oversight model
- Security and privacy controls for model access, prompts and data flows
- Vendor assessment for AI providers and AI features inside existing tools
Secure SaaS, AI-assisted
We build products, not only the controls around them. AI-assisted development compresses the delivery timeline; twenty years of security work keeps the shortcuts out of the architecture.
- Product and platform architecture with the threat model written first
- AI-assisted implementation with human review on every security-relevant path
- Authentication, tenancy isolation, secrets and audit logging designed in from the start
- Delivered on a cloud footprint that is already compliance-ready
Not sure which one you need?
Describe the deadline you are working towards. We will name the shortest path to it.