Strategic advisory
Short engagements that end with a clear decision and the reasoning behind it.
- Security design and architecture review
- High-level target architecture
- An independent view on vendor choice
- A second opinion before a major commitment
Four practices, delivered as short advisory work, assessments, long-term programmes or a virtual CISO. Every engagement is independent of any vendor and led by the founder.
AI you can put in front of the board: models, retrieval and agents, governed before they reach production.
Most organisations are already running AI in more places than their security team can name. The questions are the same everywhere: what can this system reach, what can it be talked into doing, and who answers for it when it does.
We answer them from the architecture up. We map the system, find where its trust boundaries really are, and design controls that can be measured rather than trusted.
An architecture you build over time, not a product you buy once.
Zero trust has been sold as a product category for long enough that the term now means whatever the last vendor said. We start from your estate as it is: your identity provider, your network, your applications and the paths an attacker would take through them.
The result is a target architecture and a roadmap in phases, each of which reduces risk on its own, so the programme is worth funding before it is finished.
Strategy, architecture and assessment across infrastructure, cloud and applications.
A security programme is only as good as its link to the risks the business carries. We work with CISOs, CIOs and CTOs to set that direction, then hold the architecture and the controls to it.
What you hold, where it moves, who may see it, and the controls that survive an audit as well as an attacker.
Data protection fails in the gap between the policy and the systems. We close it from both ends: the obligations that follow the data, and the technical controls that enforce them.
Every assessment ends with findings ranked by risk to the business, the evidence behind each, and what to do about it, in that order.
Models, retrieval, agents and the platform they run on, against how they can be attacked and how they are governed.
The security programme as a whole: strategy, governance, controls and how they hold up in practice.
Networks, identity and the core systems the business depends on, and the paths between them.
Configuration, identity and segmentation across your cloud accounts, against a known baseline.
The design and the code of the applications that carry your data, and the services around them.
Where personal and sensitive data lives, who can reach it, and whether the controls meet your obligations.
Engagements are sized to the question. A short one ends with a decision; a long one ends with the change made.
Short engagements that end with a clear decision and the reasoning behind it.
Long-term engagements that stay until the change is delivered.
Security leadership for as long as you need it, answering to your board.
A first conversation is with the founder, not a sales team. We reply within one working day.