
Security work should reduce risk,
not produce paperwork.
We put controls into your pipeline and your identity layer, write detections for the estate you actually run, and rehearse the recovery — then hand you the evidence as a by-product.
Six ways organisations get hurt, and what actually stops each one
None of these require a novel attack. They are the same six every year, which is why the controls on the right are unglamorous and effective.
01A valid password in the wrong hands
Phishing-resistant multi-factor authentication and conditional access, so a stolen credential alone opens nothing.
02One compromised laptop reaching everything
Segmented networks, device compliance and least-privilege access, so a foothold stays a foothold.
03A dependency nobody chose
Every build produces a software bill of materials, and known-vulnerable packages fail the pipeline rather than the audit.
04A misconfiguration shipped at 5pm
Policy as code checks infrastructure before it exists. The unsafe resource never gets created.
05Nobody noticing for three months
Centralised logging with detections written for your estate, tested against real techniques rather than bought as a feed.
06A recovery plan nobody has run
Restores are rehearsed on a schedule, from immutable backups, with the time-to-recover written down and measured.

Most breaches we are called about were not clever. They were a known gap that nobody owned.
Evidence as a by-product, not a project
If proving a control takes a person a week, the control is not really operating. We automate the evidence so audits stop being events.
| Framework | Engagement | What we do |
|---|---|---|
| SOC 2 Type II | Readiness | Control mapping, evidence automation and a gap plan before the auditor arrives. |
| ISO 27001 | Readiness | ISMS scoping, risk register and the documentation set, built to be maintained rather than to pass once. |
| Customer security reviews | Ongoing | The questionnaire answers, architecture diagrams and pen-test summaries your buyers ask for. |
| Sector obligations | Advisory | PCI DSS, HIPAA or local privacy law translated into specific engineering work. |


Four weeks to know where you actually stand
Map what you actually have
Identity, endpoints, cloud estate, internet-facing surface and data stores — discovered, not surveyed.
Test the assumptions
Configuration review, privilege analysis and a controlled test of the paths an attacker would prefer.
Rank by real risk
Findings ordered by exploitability and business impact, with the cost of each fix beside it.
Agree the plan
A sequenced programme your board can fund, and a short list of things worth doing this month.
If you are being asked questions you cannot answer
That is usually the moment to start. The four-week assessment gives you the honest position and a plan — and it is yours whoever does the work.




