Skip to content
A rack of accelerator nodes in a data centre, status lights running the height of every cabinet.

Services

AI & Cybersecurity

Deploy AI you can defend, and defend with AI.

Deploy AI you can defend, and defend with AI.

Two things are usually true at the same time. Your teams are already using generative AI, often through tools nobody approved. And the projects that have been formally proposed are stuck, because nobody can say whether they are safe or allowed.

This practice resolves both. We inventory what is actually in use, put governance in place that is light enough not to become the reason nothing ships, and build: a scoped pilot on your data, evaluated against a measured baseline, with access control and logging from the first day rather than added before go-live.

Then we attack it. Prompt injection, data exfiltration through an assistant connected to your document store, an agent holding credentials it should not — an AI red team finds these before a customer or a regulator does. And the same models go the other way: into detection, triage and the compliance evidence that used to take a person a week.

AI & Cybersecurity

Strategy and governance

Where AI is worth the effort, and the rules that keep it defensible.

  • AI and data maturity assessmentTypical duration: 3–6 days

    Where you actually stand on data, skills, governance and tooling, including an honest inventory of the shadow AI your teams are already using.

    You receive

    • Maturity scoring across five dimensions
    • Shadow AI inventory
    • Readiness gaps by capability
    • Priorities for the next two quarters
  • AI strategy and roadmapTypical duration: 8–15 days

    A portfolio of use cases ranked by value and feasibility, sequenced into a roadmap with the platform and governance work that has to happen alongside it.

    You receive

    • Use-case portfolio with value estimates
    • Prioritisation and sequencing
    • Target platform and skills plan
    • Investment case and roadmap
  • AI governance frameworkTypical duration: 5–10 days

    Roles, approval gates, an AI register and review criteria, aligned with ISO 42001 and the AI Act so that governance and compliance are one piece of work.

    You receive

    • AI policy and roles
    • AI system register
    • Approval gates and review criteria
    • Alignment map to ISO 42001 and the AI Act

AI solutions implementation

Pilots, agents, copilots and the platform underneath them, built on your data and measured against a baseline.

  • Use-case scoping with AI Act risk analysisTypical duration: 3–6 days

    A use case defined precisely enough to build — data, users, success measures — with its AI Act classification settled before any budget is committed.

    You receive

    • Use-case specification
    • Data availability and quality check
    • AI Act classification and obligations
    • Build or buy recommendation
  • Generative AI pilotTypical duration: 15–40 days

    A working pilot — retrieval-augmented search, an internal assistant or document automation — built on your data, evaluated against a measured baseline, with access control and logging from day one.

    You receive

    • Working pilot in your environment
    • Evaluation set and measured results
    • Access control, logging and guardrails
    • Production readiness assessment
  • AI agents and process automationTypical duration: 20–50 days

    Agents that act on systems, built with the permission model and the human checkpoints defined first, because an agent with broad credentials is an access risk before it is a productivity gain.

    You receive

    • Process analysis and automation design
    • Agent permission and tool model
    • Human-in-the-loop checkpoints
    • Deployment with monitoring
  • Secure roll-out of Copilot, ChatGPT Enterprise, Gemini or ClaudeTypical duration: 5–12 days

    The work that has to happen before a company-wide assistant is switched on: permission cleanup, data classification, tenant configuration, logging and user guidance.

    You receive

    • Permission and oversharing remediation
    • Tenant and data controls configuration
    • Usage policy and user guidance
    • Adoption and monitoring plan
  • MLOps and LLMOpsTypical duration: 15–40 days

    The engineering that turns a promising pilot into a system you can operate: versioning, evaluation in the pipeline, cost control, monitoring and a rollback that works.

    You receive

    • Model and prompt versioning
    • Automated evaluation in CI
    • Monitoring, cost and quality dashboards
    • Release and rollback process

AI security and threat defense

Models, prompts, agents and the data behind them, tested the way an attacker would.

  • AI and LLM securityTypical duration: 5–15 days

    Security review of AI systems against the OWASP Top 10 for LLM applications: prompt injection, data leakage through context, tool and agent permissions, and model supply chain.

    You receive

    • AI system architecture and data flow review
    • OWASP LLM Top 10 assessment
    • Guardrail and monitoring design
    • Secure usage guidance for builders
  • AI Red TeamTypical duration: 5–12 days

    Adversarial testing of an assistant, RAG system or agent: jailbreaks, indirect prompt injection through retrieved content, data exfiltration and abuse of connected tools.

    You receive

    • Adversarial test plan and corpus
    • Findings with reproducible prompts
    • Guardrail effectiveness measurement
    • Remediation and retest

Trustworthy and secure AI

The assurance layer: risk assessment, data protection, and audit of what is already running.

  • AI risk assessment and fundamental rights impact assessmentTypical duration: 5–12 days

    Risk assessment of an AI system across safety, bias, robustness and rights, including the fundamental rights impact assessment the AI Act requires from certain deployers.

    You receive

    • AI risk assessment report
    • Bias and robustness testing results
    • Fundamental rights impact assessment
    • Mitigation plan and residual risk
  • Data security in AI projectsTypical duration: 5–15 days

    Controls for the data an AI system touches: minimisation, pseudonymisation, retention in vector stores, tenant isolation and the contractual position with your model provider.

    You receive

    • Data flow and retention map
    • Minimisation and pseudonymisation design
    • Vector store and isolation controls
    • Provider contract and DPA review
  • Audit of an existing AI systemTypical duration: 8–20 days

    An independent review of a system already in production: how it performs, how it fails, what it logs, and whether its documentation would survive a regulator's question.

    You receive

    • Performance and failure mode analysis
    • Documentation and logging review
    • Compliance gap assessment
    • Remediation plan

AI for cybersecurity operations

The same models pointed the other way: at your alert queue, your runbooks and the compliance evidence that used to take a week.

  • AI for cybersecurity and complianceTypical duration: 8–20 days

    Applying AI where it genuinely helps our own field: alert triage, evidence gathering, policy drafting and supplier questionnaire handling, with a human decision at the end.

    You receive

    • Opportunity assessment in security and compliance
    • Pilot implementation
    • Human oversight design
    • Measured effect on workload
  • AI-assisted detection and triageTypical duration: 3–6 weeks

    Language models put to work on your alert queue: enrichment, deduplication and a first triage, with the analyst keeping the decision.

    You receive

    • Triage assistant integrated with your SIEM or SOAR
    • Measured reduction in time to first triage
    • Guardrails and audit trail for every model action
  • Security copilot deploymentTypical duration: 2–5 weeks

    A secured roll-out of Microsoft Security Copilot or an equivalent, scoped to the analysts who will use it and the data it may see.

    You receive

    • Access model and data scope for the copilot
    • Prompt library for your runbooks
    • Adoption review after thirty days
  • Compliance evidence automation with AITypical duration: 3–6 weeks

    Models that read your tickets, configurations and logs and draft the control evidence an auditor asks for, reviewed by a person before it leaves.

    You receive

    • Evidence pipelines for the controls you choose
    • Reviewer workflow with sign-off
    • Time saved per audit cycle, measured

AI training and awareness

Executives, teams and everyone who pastes into an assistant, taught what applies to them.

  • Executive and business enablementTypical duration: 4–16 hours

    Working sessions that leave leaders able to judge an AI proposal: what these systems do well, where they fail, and what the regulation asks of them.

    You receive

    • Executive briefing session
    • Business team workshops
    • Use-case identification output
    • Internal communication material
  • AI literacy programmeTypical duration: 2–4 days

    What generative AI does, what it gets wrong and what the AI Act asks of the people who use it — for every employee, in their own terms.

    You receive

    • Two-hour session per audience
    • Company acceptable-use rules explained
    • Completion and comprehension figures
  • Safe use of generative AITypical duration: 3–6 hours

    Hands-on training on the assistants your teams actually use: what to paste, what never to, and how to check an answer before acting on it.

    You receive

    • Half-day workshop on your own tools
    • One-page rules card per team
    • Follow-up quiz after a month

AI Act Check

Every AI system inventoried, classified and dated, with the obligations that follow.

Duration
3–4 weeks
Price
€6,000 to €12,000
excl. VAT, indicative

Discuss this pack — AI Act Check

GenAI Secure Launch

An assistant rolled out to the whole company without opening the whole file server with it.

Duration
4–6 weeks
Price
€12,000 to €25,000
excl. VAT, indicative

Discuss this pack — GenAI Secure Launch

Outsourced AI officer (vCAIO)

The person who owns your AI register, reviews each new use case against the AI Act, and keeps governance moving at the speed your teams are actually adopting these tools.

What is included

  • AI register ownership
  • Use-case review and approval
  • AI Act and ISO 42001 tracking
  • Vendor and model assessments
  • Quarterly governance report
AI

Discuss this service — Outsourced AI officer (vCAIO)

Start with the inventory

AI Act Check takes three to four weeks and tells you what you are running, what it is classified as, and what is owed from when.