Skip to content
A long meeting table set with chairs in a bright, empty boardroom.

Services

Strategic Advisory

A security strategy the board can fund and the CISO can execute.

A security strategy the board can fund and the CISO can execute.

Most security programmes fail at the join between the board and the engineers. The board is asked to fund controls it cannot evaluate; the engineers are handed a budget with no sequence. Strategic advisory is the work of building that join.

We start with where you stand — a maturity assessment scored against NIST CSF 2.0 or ISO 27001 with the gaps ranked by exposure — and turn it into a three-year master plan with costs, owners and the order things have to happen in. The same method applies to the cloud: which providers, how sovereign, where the data may sit, and what an exit would cost.

Where you need the function and not just the plan, a virtual CISO carries it: a senior specialist at a fixed number of days a month who attends your committees, owns the roadmap and answers for it.

Strategic Advisory

Strategy and roadmap

Where you stand, where you need to be, and the sequence of decisions in between.

  • National and sectoral cybersecurity strategyTypical duration: 3–6 months

    For a ministry, regulator or sector body: the strategy document, the governance behind it, the capability roadmap and the indicators that show whether it is working.

    You receive

    • Strategy and governance model
    • Capability roadmap with sequencing
    • Indicator framework and review cycle
  • CERT implementationTypical duration: 4–9 months

    Standing up a computer emergency response team: mandate, constituency, services, tooling, staffing and the procedures, to the FIRST and ENISA models.

    You receive

    • Mandate and service catalogue
    • Procedures, tooling and staffing plan
    • Readiness review before go-live
  • SOC implementationTypical duration: 4–9 months

    Designing and standing up a security operations centre — or choosing not to and buying it — with the use cases, data sources, tooling, tiers and metrics that make it worth having.

    You receive

    • Operating model and sourcing decision
    • Use-case and data-source catalogue
    • Tooling architecture and runbooks
  • Critical infrastructure protectionTypical duration: 2–5 months

    For operators of essential services: the asset and dependency map, the protection baseline, the sector obligations, and a plan that survives a regulator's inspection.

    You receive

    • Critical asset and dependency map
    • Protection baseline against sector rules
    • Inspection-ready programme plan
  • Cyber crisis management frameworkTypical duration: 4–8 weeks

    Who decides, who speaks, who calls the regulator and when: the crisis organisation, escalation criteria, communication templates and decision logs, exercised once before you need them.

    You receive

    • Crisis organisation and escalation criteria
    • Communication templates for every audience
    • Tabletop exercise and improvement plan
  • Cyber maturity assessmentTypical duration: 3–8 days

    A structured read of where you stand against NIST CSF 2.0 or ISO 27001, scored by domain, with the gaps that matter ranked by exposure rather than by framework order.

    You receive

    • Maturity scoring by domain with evidence
    • Ranked gap register with owners
    • Costed 18-month improvement plan
    • Executive summary for the board
  • Cyber resilience frameworkTypical duration: 4–8 weeks

    One framework that joins security, continuity and recovery: the critical services, their tolerances, the controls that protect them and the tests that prove they hold — the shape DORA and NIS2 both expect.

    You receive

    • Critical services and impact tolerances
    • Integrated control and testing plan
    • Resilience dashboard for the board
  • Cyber strategy and master planTypical duration: 10–20 days

    A multi-year security plan tied to budget, headcount and regulatory deadlines, so the next three board meetings already have their agenda.

    You receive

    • Target operating model and roles
    • Three-year roadmap with budget envelopes
    • Investment cases per initiative
    • Board-level KPI set
  • Cloud strategy and opportunity studyTypical duration: 8–20 days

    Application-by-application analysis of what to retire, retain, rehost, replatform or rebuild, with the business case and the regulatory constraints in the same table.

    You receive

    • Application portfolio assessment
    • Migration strategy per application
    • Business case with total cost of ownership
    • Roadmap with sequencing and dependencies
  • Hyperscaler and sovereign cloud selectionTypical duration: 5–12 days

    A structured comparison of AWS, Azure, GCP, OVHcloud, Scaleway, S3NS and Bleu against your technical, contractual, sovereignty and exit requirements.

    You receive

    • Weighted requirement matrix
    • Provider comparison with evidence
    • Sovereignty and exit analysis
    • Recommendation and decision record
  • Sovereignty and data residency assessmentTypical duration: 5–12 days

    Where your data physically sits, who can legally compel access to it, and what it would take to change that — documented for the regulator and the board.

    You receive

    • Data residency map
    • Extraterritorial access analysis
    • Sovereignty risk assessment
    • Options and cost of change

vCISO

A senior security leader on your management team for a defined number of days each month: strategy, board reporting, supplier reviews, incident decisions and the compliance calendar.

What is included

  • Named senior consultant
  • Security roadmap and budget ownership
  • Board and executive reporting
  • Supplier and customer security reviews
  • Escalation availability during incidents

Available tiers

  • Essential · 2 days per month
  • Standard · 4 days per month
  • Extended · 8 days per month
AdvisoryGRC

Discuss this service — vCISO

Start with the assessment

A cyber maturity assessment takes four to six weeks and gives you the scored picture and the costed plan the board will ask for.