Home/Services
Services
Scoped, fixed-price engagements led by practitioners who have sat on both sides of an audit. Start small; extend only if it is working.
Every engagement starts with a scoping call and a written proposal that states deliverables, timeline and price. We do not sell open-ended day rates unless you ask for them.
Gap assessment
A structured review of where you stand against ISO 27001, NIST CSF, SOC 2, PCI DSS, NIS2 or DORA, with an itemised, prioritised findings report and a realistic plan to close the gaps. Fixed price, two to three weeks.
What's included
- Clause-by-clause and control-by-control review
- Evidence sampling, not just interviews
- Roadmap with effort and sequencing
- No obligation to continue with us
Implementation
We build the management system with your team: scope, risk assessment, control selection, documentation and the evidence trail an auditor expects. You end up with something your people can run without us.
What's included
- Risk methodology and register
- Policy, standard and procedure set
- Control ownership and evidence schedule
- Readiness check before the audit
Virtual CISO
Senior security leadership on a retained basis for organisations that need the judgement but not the headcount. Board reporting, programme ownership, supplier and customer assurance, and someone to call when it goes wrong.
What's included
- Monthly or fortnightly cadence
- Board and audit-committee reporting
- Customer questionnaire and due-diligence response
- Incident leadership when needed
Internal audit & readiness review
Independent internal audit to ISO 19011, or a mock Stage 2 / Type II / C3PAO assessment, so the findings surface while you can still fix them. Reported the way the certification body will report them.
What's included
- Risk-based audit programme
- Mock certification audit
- Non-conformity and corrective-action tracking
- Management review facilitation
NIST 800-171 & CMMC readiness
For defence suppliers: CUI scoping, objective-by-objective assessment against 800-171A, System Security Plan and POA&M, and preparation for a C3PAO or self-assessment.
What's included
- CUI boundary and data-flow definition
- SPRS-style scoring
- SSP and POA&M authorship
- Assessor liaison
Penetration testing
Adversarial testing of your web applications, APIs, networks and infrastructure, reported against the risk to your business rather than as a raw scanner output. Findings are mapped to the controls your framework expects, so remediation feeds straight into your audit evidence.
What's included
- Web application, API, network and infrastructure testing
- Social engineering and phishing simulation
- Prioritised findings with remediation guidance
- Findings mapped to ISO 27001, SOC 2 and PCI DSS controls
Managed security monitoring
SOC monitoring, threat detection and response for organisations without an in-house security operations team, with the business continuity planning that keeps you operating when something gets through.
What's included
- SOC monitoring, threat detection and response
- Log and alert evidence your auditors can sample
- Business continuity and resilience planning
- Regular reporting to management
Incident response
Rapid containment, investigation and recovery when something goes wrong, then a post-incident review that strengthens the controls. Plans and tabletop exercises beforehand, so the first time you run the playbook is not the real thing.
What's included
- Incident containment, forensic investigation and recovery
- Post-incident review and improvement report
- Incident response plans, playbooks and tabletop exercises
- Regulator and customer notification support (GDPR, NIS2, DORA)
Training
Security training for every level of the organisation, from all-staff awareness to board briefings, delivered by the practitioners who run our engagements.
What's included
- Cyber awareness essentials for all staff
- AI security and governance
- ISO 27001 implementation training
- Executive and board cyber briefings
Documentation sets
The same policy, standard and procedure sets we use on engagements, sold as editable files with your organisation's name in place. For teams that have the expertise and just need the writing done.
- 15 sets across ISO 27001, NIST, SOC 2, PCI DSS, GDPR, NIS2, DORA and ISO 42001
- One structure and vocabulary across every set
- 12 months of updates included
- Multi-client licence available for consultancies and MSPs
How an engagement runs
Scoping call
30 minutes. What you are being asked for, by whom, by when, and what already exists.
Proposal
Deliverables, timeline, price and the assumptions behind them. Fixed unless the scope changes.
Delivery
Weekly check-ins, a shared tracker, and findings raised as we go rather than in a final report.
Handover
Your team owns the system. We stay available for the audit and for surveillance if you want us.
Not sure which service fits?
Describe the situation and we will tell you which one, or whether you need any of them.