Secure Cloud Start
A landing zone delivered as code in your repository, with guardrails and cost control from the first account.
- Duration
- 6–10 weeks
- Price
- €20,000 to €40,000
- excl. VAT, indicative
AI & Cybersecurity
Deploy AI you can defend, and defend with AI.
Legal

Services
Know the estate, harden it, and ship security with the code.
A security report that arrives after the platform is built describes a problem. A guardrail in the pipeline prevents one. The difference in cost is roughly two orders of magnitude, and it is the reason this practice exists inside a security firm rather than next to one.
We design landing zones as code in your repository, wire security testing into the pipelines your teams already use, and tune it until the output is trusted — because a scanner nobody reads is worse than no scanner at all. Then we make the same controls produce their own audit evidence, timestamped and exportable, which is what makes an ISO 27001 or SOC 2 certificate affordable to keep.
And we watch the bill. FinOps usually returns fifteen to thirty per cent of cloud spend, which tends to fund the rest of the work.
A structured read of an estate — organisational, cloud, industrial or Kubernetes — against what good looks like.
Network, servers, endpoints and directory reviewed for configuration weaknesses, missing patches and exposure, from the inside, with a prioritised fix list.
A documented security baseline for your cloud accounts, enforced by policy as code and monitored continuously, so a new project starts compliant instead of being corrected later.
Assessment of industrial systems against IEC 62443 with a specialist partner, using passive techniques on production networks and a zone-and-conduit model as the output.
The banking platform and its customer channels reviewed end to end: transaction integrity, authentication, session handling, fraud controls and the interfaces between them.
A review of an existing workload against the provider's framework, covering operational excellence, security, reliability, performance, cost and sustainability.
The paths from a standard user to domain admin, found with the same tooling attackers use, and the tiering model that closes them.
An audit that looks at both sides: how security is organised and decided, and how it is actually configured in the systems that matter.
Cluster review against the CIS Kubernetes benchmark: RBAC, admission control, network policy, workload identity, secrets handling and node hardening.
Measured against DORA metrics, OWASP SAMM, NIST SSDF and SLSA, with the difference between what the documentation claims and what the pipelines actually do.
Hardening, architecture, identity, encryption and backups — the engineering that closes what the assessments found.
Conditional access, privileged identity management, tenant restrictions and mail security configured to a documented baseline, with the drift checks that keep it in place.
Configuration standards for your operating systems, databases, network gear and cloud services, derived from CIS and vendor baselines and cut to what you actually run.
A target architecture where access decisions are made per request against identity, device and context, and a migration path that does not require replacing everything at once.
Joiner-mover-leaver that works, least privilege that survives contact with reality, and privileged accounts held in a vault with session recording rather than in a password manager.
Classification that people apply, encryption and key management that hold up to audit, and data loss prevention tuned to your real flows rather than to the vendor's demo.
Backups an attacker cannot reach and a restore you have actually tested, built to the 3-2-1-1-0 rule with immutability and an offline copy.
A security engineer on call for your development teams: design reviews, threat models, findings triage and the awkward questions before release.
Controls inside the pipeline, producing their own audit evidence as they run.
Security requirements, review gates and acceptance criteria defined per stage, light enough that teams keep them and firm enough to satisfy an auditor.
Structured threat modelling of your critical services, run as a workshop with the engineers who build them, producing backlog items rather than a document nobody reopens.
Hardening of GitHub Actions, GitLab CI or Azure DevOps: least-privilege runners, pinned actions, protected branches, signed artefacts and no long-lived credentials.
Security testing wired into the pipeline with thresholds that block what matters and stay quiet otherwise, because a scanner nobody trusts is a scanner nobody reads.
Secrets out of repositories and pipelines, into a vault with short-lived credentials and workload identity, plus detection for the ones already leaked.
SBOM generation, dependency policy, artefact signing and provenance to SLSA levels, aligned with what the Cyber Resilience Act will require you to produce.
Policies expressed as code and enforced before deployment, so a non-compliant resource fails the pull request instead of appearing in an audit six months later.
Minimal base images, reproducible builds, registry scanning and signing, with a patch path that does not require rebuilding every service by hand.
Paved paths that make the secure option the fastest option: golden templates, self-service environments and GitOps delivery with the guardrails already inside.
Detection of what happens after deployment: anomalous process behaviour, container escapes, unexpected network flows, with response actions defined in advance.
Service level objectives, error budgets, incident review without blame, and toil measured so that automation is funded by evidence rather than by conviction.
One telemetry pipeline serving both engineering and security, with retention set by regulatory requirement rather than by default configuration.
Controls for ISO 27001, SOC 2, NIS2 and DORA implemented as automated checks that produce their own timestamped evidence, which is what makes a certificate affordable to keep.
Change management that satisfies auditors without a weekly committee: approvals in the pull request, deployment records generated automatically, emergency path documented.
Recovery expressed as code and tested on a schedule, so the recovery time objective is a measured number rather than an aspiration in a document.
A landing zone built as code, then workloads moved onto it without a rebuild.
Account structure, network, identity, logging, encryption and guardrails delivered as code in your repository, so every new environment inherits the same baseline.
Wave planning, runbooks, cutover rehearsals and rollback criteria, with the security and compliance checks built into each wave rather than added at the end.
Containerisation and refactoring of applications where it pays, with base images, build pipelines and platform targets defined once and reused.
Connectivity between data centres, clouds and sites designed for segmentation and observability, not just for reachability.
Who owns what, how it is monitored, and why the bill stopped growing.
Who can create what, who pays for it, who secures it and who is called at night — written down, agreed, and enforced by policy rather than by memory.
A documented, tested exit strategy for critical cloud services, which DORA requires financial entities to hold and most contracts quietly assume will never be used.
Metrics, logs and traces that answer real questions, with service level objectives defined with the business and alerting that does not wake people for nothing.
A data platform with ownership, quality and lineage defined from the start, and access controls that let analytics happen without opening the whole warehouse.
A landing zone delivered as code in your repository, with guardrails and cost control from the first account.
Security controls inside your pipeline, tuned so the team keeps them after we leave.
A cluster audit against the CIS benchmark, with the hardening applied and verified.
SBOM, signing and provenance in place, mapped to what the Cyber Resilience Act will ask for.
Three weeks to a clear picture: maturity, exposure and the ten things to fix first.
Standing engineering capacity that keeps pipelines, guardrails and compliance evidence working as your platform changes, with a named engineer and a monthly review.
Continuous cost management: allocation kept accurate, commitments managed, waste removed each month, and savings reported as measured figures.
Secure Cloud Start if the foundation needs building. DevSecOps Kickstart if the code ships weekly and security is still outside the pipeline.