Home/Services

Services

Scoped, fixed-price engagements led by practitioners who have sat on both sides of an audit. Start small; extend only if it is working.

Every engagement starts with a scoping call and a written proposal that states deliverables, timeline and price. We do not sell open-ended day rates unless you ask for them.

Gap assessment

A structured review of where you stand against ISO 27001, NIST CSF, SOC 2, PCI DSS, NIS2 or DORA, with an itemised, prioritised findings report and a realistic plan to close the gaps. Fixed price, two to three weeks.

What's included

  • Clause-by-clause and control-by-control review
  • Evidence sampling, not just interviews
  • Roadmap with effort and sequencing
  • No obligation to continue with us

Discuss this service

Implementation

We build the management system with your team: scope, risk assessment, control selection, documentation and the evidence trail an auditor expects. You end up with something your people can run without us.

What's included

  • Risk methodology and register
  • Policy, standard and procedure set
  • Control ownership and evidence schedule
  • Readiness check before the audit

Discuss this service

Virtual CISO

Senior security leadership on a retained basis for organisations that need the judgement but not the headcount. Board reporting, programme ownership, supplier and customer assurance, and someone to call when it goes wrong.

What's included

  • Monthly or fortnightly cadence
  • Board and audit-committee reporting
  • Customer questionnaire and due-diligence response
  • Incident leadership when needed

Discuss this service

Internal audit & readiness review

Independent internal audit to ISO 19011, or a mock Stage 2 / Type II / C3PAO assessment, so the findings surface while you can still fix them. Reported the way the certification body will report them.

What's included

  • Risk-based audit programme
  • Mock certification audit
  • Non-conformity and corrective-action tracking
  • Management review facilitation

Discuss this service

NIST 800-171 & CMMC readiness

For defence suppliers: CUI scoping, objective-by-objective assessment against 800-171A, System Security Plan and POA&M, and preparation for a C3PAO or self-assessment.

What's included

  • CUI boundary and data-flow definition
  • SPRS-style scoring
  • SSP and POA&M authorship
  • Assessor liaison

Discuss this service

Penetration testing

Adversarial testing of your web applications, APIs, networks and infrastructure, reported against the risk to your business rather than as a raw scanner output. Findings are mapped to the controls your framework expects, so remediation feeds straight into your audit evidence.

What's included

  • Web application, API, network and infrastructure testing
  • Social engineering and phishing simulation
  • Prioritised findings with remediation guidance
  • Findings mapped to ISO 27001, SOC 2 and PCI DSS controls

Discuss this service

Managed security monitoring

SOC monitoring, threat detection and response for organisations without an in-house security operations team, with the business continuity planning that keeps you operating when something gets through.

What's included

  • SOC monitoring, threat detection and response
  • Log and alert evidence your auditors can sample
  • Business continuity and resilience planning
  • Regular reporting to management

Discuss this service

Incident response

Rapid containment, investigation and recovery when something goes wrong, then a post-incident review that strengthens the controls. Plans and tabletop exercises beforehand, so the first time you run the playbook is not the real thing.

What's included

  • Incident containment, forensic investigation and recovery
  • Post-incident review and improvement report
  • Incident response plans, playbooks and tabletop exercises
  • Regulator and customer notification support (GDPR, NIS2, DORA)

Discuss this service

Training

Security training for every level of the organisation, from all-staff awareness to board briefings, delivered by the practitioners who run our engagements.

What's included

  • Cyber awareness essentials for all staff
  • AI security and governance
  • ISO 27001 implementation training
  • Executive and board cyber briefings

Discuss this service

Documentation sets

The same policy, standard and procedure sets we use on engagements, sold as editable files with your organisation's name in place. For teams that have the expertise and just need the writing done.

  • 15 sets across ISO 27001, NIST, SOC 2, PCI DSS, GDPR, NIS2, DORA and ISO 42001
  • One structure and vocabulary across every set
  • 12 months of updates included
  • Multi-client licence available for consultancies and MSPs

Browse the catalogue

How an engagement runs

  1. Scoping call

    30 minutes. What you are being asked for, by whom, by when, and what already exists.

  2. Proposal

    Deliverables, timeline, price and the assumptions behind them. Fixed unless the scope changes.

  3. Delivery

    Weekly check-ins, a shared tracker, and findings raised as we go rather than in a final report.

  4. Handover

    Your team owns the system. We stay available for the audit and for surveillance if you want us.

Not sure which service fits?

Describe the situation and we will tell you which one, or whether you need any of them.