Skip to content

Recurring

Services that do not end

A certificate has to be maintained. A register has to be current. An AI system has to be reviewed again when it changes. That work is cheaper continuous than rediscovered.

Recurring services give you a named senior contact, an agreed capacity each month, and a rhythm: a monthly review, a quarterly report, and someone to call when a customer sends a security questionnaire on a Friday afternoon.

They are priced monthly, committed by quarter, and can be stopped at the end of any quarter with thirty days' notice. No minimum term of one year, because a service you would leave if you could is not a service worth selling.

vCISO

A senior security leader on your management team for a defined number of days each month: strategy, board reporting, supplier reviews, incident decisions and the compliance calendar.

What is included

  • Named senior consultant
  • Security roadmap and budget ownership
  • Board and executive reporting
  • Supplier and customer security reviews
  • Escalation availability during incidents

Available tiers

  • Essential · 2 days per month
  • Standard · 4 days per month
  • Extended · 8 days per month
AdvisoryGRC

Discuss this service — vCISO

Compliance-as-a-Service

Your compliance obligations run continuously: evidence collected as it is produced, internal audits on schedule, regulatory changes watched, and the audit answered without a scramble.

What is included

  • Annual compliance calendar
  • Continuous evidence collection
  • Internal audit programme
  • Quarterly compliance report
  • Regulatory change watch

Available tiers

  • One framework
  • Two frameworks
  • Multi-framework
GRC

Discuss this service — Compliance-as-a-Service

Outsourced DPO

A designated data protection officer with the independence the GDPR requires, handling the register, impact assessments, data subject requests and the supervisory authority.

What is included

  • DPO designation and notification
  • Register and DPIA maintenance
  • Data subject request handling
  • Staff advice and training
  • Annual report to management
GRC

Discuss this service — Outsourced DPO

Outsourced AI officer (vCAIO)

The person who owns your AI register, reviews each new use case against the AI Act, and keeps governance moving at the speed your teams are actually adopting these tools.

What is included

  • AI register ownership
  • Use-case review and approval
  • AI Act and ISO 42001 tracking
  • Vendor and model assessments
  • Quarterly governance report
AI

Discuss this service — Outsourced AI officer (vCAIO)

Managed DevSecOps

Standing engineering capacity that keeps pipelines, guardrails and compliance evidence working as your platform changes, with a named engineer and a monthly review.

What is included

  • Named engineer and agreed capacity
  • Pipeline and guardrail maintenance
  • Finding triage and remediation support
  • Compliance evidence upkeep
  • Monthly review and roadmap
SOCAssessment

Discuss this service — Managed DevSecOps

White-label SOC and MDR

Delivered with a qualified partner

Detection and response around the clock, delivered with a PDIS-qualified partner, with detection use cases written for your environment and a single point of contact on our side.

What is included

  • 24/7 monitoring and triage
  • Detection use cases for your stack
  • Containment actions by agreement
  • Monthly detection performance review
  • Escalation to incident response
SOC

Discuss this service — White-label SOC and MDR

Vulnerability and attack-surface management

Continuous scanning of what you own and what is exposed in your name, with findings filtered, prioritised and tracked to closure rather than published as a raw list.

What is included

  • Internal and external scanning
  • External attack surface discovery
  • Risk-based prioritisation
  • Remediation tracking against SLAs
  • Monthly reporting
SOCOffensive

Discuss this service — Vulnerability and attack-surface management

Managed FinOps

Continuous cost management: allocation kept accurate, commitments managed, waste removed each month, and savings reported as measured figures.

What is included

  • Cost allocation upkeep
  • Commitment and discount management
  • Monthly rightsizing actions
  • Anomaly detection and alerts
  • Measured savings reporting
SOCAssessment

Discuss this service — Managed FinOps

Continuous awareness

A year-round programme rather than an annual module: short role-based content, phishing simulation with coaching, and reporting that holds up as NIS2 evidence.

What is included

  • Annual plan by population
  • Phishing simulation campaigns
  • Short role-based modules
  • Executive and board sessions
  • Participation evidence for audits
Training

Discuss this service — Continuous awareness

Multi-country regulatory support

One point of contact for regulatory questions across Europe, French-speaking Africa and South America, answered with local partners who practise in that jurisdiction.

What is included

  • Regulatory watch per country
  • Local filing and registration support
  • Cross-border transfer maintenance
  • Local partner coordination
  • Consolidated quarterly briefing
GRC

Discuss this service — Multi-country regulatory support

How an engagement usually evolves

We do not ask for a retainer on the first call. The sequence below is what actually happens, in that order, and each step is a decision you make with the previous step's output in hand.

  1. 1

    A pack

    A fixed-price engagement with a defined scope. It answers one question — where do we stand, or how do we meet this deadline — and ends with evidence.

  2. 2

    An action plan

    Every pack ends with a costed, prioritised plan. It is written so your team can execute it without us, and it is yours whatever you decide next.

  3. 3

    A recurring service

    Most clients hand us the part of the plan that never finishes: the calendar, the evidence, the reviews, the reporting. Known capacity, known monthly cost.

  4. 4

    Targeted missions

    The discrete items — a pentest, a landing zone, a certification push — are run as separate engagements from the catalogue, scoped and priced individually.

Start where it makes sense

If you already know which recurring service you need, we can scope it directly. If not, a pack first is usually cheaper and always clearer.