Cyber Security Consulting

Know where you stand, decide where to go, and get there.

Independent advisory that assesses your current security and IT position, designs the frameworks and strategy to improve it, and prepares your organisation to keep operating through disruption.

Why it matters

The problems we solve

01

No clear picture of the current state

Investment decisions are made without an objective view of where the real gaps are.

02

Security spending without a plan

Tools are bought one at a time instead of against a prioritised roadmap.

03

The SOC sees alerts, not attacks

Detection follows vendor defaults rather than the threats that matter to your organisation.

04

Recovery plans that were never tested

Continuity and disaster recovery plans exist on paper but have never been exercised.

Services

What we deliver

Each service can be engaged on its own or combined into a single programme.

01

Current State Assessment

An objective review of your people, processes and technology across security and IT.

  • Interviews, documentation and technical review
  • Capability gaps against good practice
  • Findings ranked by risk and effort
02

Maturity Assessment

Measurement of your security maturity against a recognised model, with a target state agreed with you.

  • Assessment against NIST CSF, CIS Controls or NCSA NIA
  • Current and target maturity by domain
  • A baseline for tracking progress
03

Security Strategy and Roadmap

A multi-year strategy and prioritised roadmap tied to your business and regulatory objectives.

  • Strategic objectives and guiding principles
  • Prioritised initiatives and dependencies
  • Budget and resourcing view for the board
04

SOC and Cyber Security Framework Design

Design of your security operating model, from SOC structure and processes to the wider cyber security framework.

  • SOC operating model, roles and shift patterns
  • Processes, playbooks and escalation paths
  • Metrics and management reporting
05

Detection Strategy Development

A threat-led detection strategy that defines what your SOC must detect, and how.

  • Threat profiling for your sector
  • Detection coverage mapped to MITRE ATT&CK
  • Use-case backlog and log source requirements
06

IT Governance Framework

IT governance and service management frameworks aligned with COBIT and ITIL.

  • IT governance structures and policies
  • Service management processes
  • IT risk and performance measures
07

Security Platform Migration

Planned migration of SIEM, EDR and other security platforms, and security for cloud migrations.

  • Migration planning and parallel running
  • Detection content and integrations moved across
  • Security controls for cloud migrations
08

Business Continuity Management

Continuity programmes aligned with ISO 22301, so critical services keep running through disruption.

  • Business impact analysis
  • Continuity strategies and plans
  • Programme governance and review
09

Disaster Recovery Planning

IT disaster recovery plans with recovery objectives that match what the business needs.

  • Recovery time and recovery point objectives
  • DR architecture and runbooks
  • DR testing and reporting
10

Tabletop Exercises

Scenario-based exercises that test how your leadership and technical teams respond to a crisis.

  • Cyber, ransomware and operational scenarios
  • Executive and technical sessions
  • After-action report with improvements
Outcomes

What you get

An objective baseline
A roadmap the board can approve
Plans tested before they are needed
How it works

Our approach

01

Assess

Establish the current state and maturity.

02

Define

Agree the target state with your leadership.

03

Plan

Build the roadmap, frameworks and plans to get there.

04

Enable

Support delivery, run exercises and measure progress.

Standards we work to

Standards we work to

NIST CSFCIS ControlsNCSA National Information AssuranceISO 22301COBITITILMITRE ATT&CK
Questions

Frequently asked

How is a current state assessment different from an audit?

An audit checks compliance with a specific standard. A current state assessment looks at capability across people, process and technology, to tell you where to invest.

Can you run tabletop exercises for our board?

Yes. We run executive sessions for boards and senior management, as well as technical exercises for response teams.

Can you help us move to a new SIEM?

Yes. We plan the migration, move detection content and integrations, and run both platforms in parallel until cut-over.

Get in touch

Tell us what your regulator, auditor or board is asking for.

We will come back to you with how we would approach it, who would work on it and what it would take.