Skip to content
Syntax-highlighted source code filling a screen, seen at an angle so the lines recede.

Services

Seven practices, one conversation

A regulation lands on a compliance officer, is implemented by an engineer, and is audited against evidence a platform has to produce. Split that across three firms and the gaps become your problem. We keep it in one place.

Seven practices, one measure

Seven practices, one measure: the cut is made once, in a unified control framework, and every practice works from it.

Below, the seven practices. Each page says what we do, what you receive and how long it usually takes. Durations are consultant days, drawn from engagements of comparable scope, and are confirmed in the proposal.

Most of this catalogue is also available at a fixed price inside a pack, or continuously through a recurring service.

A rack of accelerator nodes in a data centre, status lights running the height of every cabinet.

AI & Cybersecurity

Deploy AI you can defend, and defend with AI.

  • Strategy and governance
  • AI solutions implementation
  • AI security and threat defense
  • Trustworthy and secure AI
  • AI for cybersecurity operations
  • AI training and awareness

Learn more — AI & Cybersecurity

An operations room: staff at consoles facing a wall of screens, each watching a different feed.

Managed Services

Detection, response and operations, run for you around the clock.

  • SOC management
  • CERT and incident response
  • Managed operations

Learn more — Managed Services

The European Parliament chamber in Strasbourg, seats curving in tiers around the rostrum.

Governance, Risk & Compliance

Prove it once. Use the proof everywhere.

  • Cybersecurity and compliance assessment
  • European cybersecurity regulation
  • Regulatory compliance and certification
  • Personal data
  • Artificial intelligence
  • GRC advisory services
  • Governance and risk

Learn more — Governance, Risk & Compliance

Someone working on a laptop late at night, the screen the only bright thing in a dark room.

Offensive Security

Find the way in before someone else does.

  • Offensive assessment
  • Red team
  • Web and mobile application assessment

Learn more — Offensive Security

Switches and routers stacked in a rack, patch cables running between their ports.

Security Assessment & DevSecOps

Know the estate, harden it, and ship security with the code.

  • Technical assessment
  • Technical assistance
  • DevSecOps
  • Foundation and migration
  • Governance, operations and cost

Learn more — Security Assessment & DevSecOps

A long meeting table set with chairs in a bright, empty boardroom.

Strategic Advisory

A security strategy the board can fund and the CISO can execute.

  • Strategy and roadmap

Learn more — Strategic Advisory

A cybersecurity training class: people at workstations, one reading through a printed exercise.

Training & Awareness

Every employee a strong link, from the boardroom to the build pipeline.

  • Training
  • Awareness
  • Cyber exercises and competitions

Learn more — Training & Awareness

Where they meet

The engagements we are asked for most often sit across two practices at once.

Compliance meets engineering

A control framework is only cheap to maintain if the evidence collects itself. We map the controls, then implement them as automated checks in your pipeline.

Cloud meets regulation

DORA wants a tested exit plan. The AI Act wants logging. Sovereignty questions want a data residency map. All three are architecture decisions before they are documents.

AI meets security

An assistant connected to your file server inherits every permission mistake you ever made. The roll-out project and the security project are the same project.

Packs →Recurring services →How we work →

Not sure which practice you need?

That is a normal place to start. Describe the deadline or the question you are facing and we will tell you what it actually involves.