What we do.
Six service lines, one team. Each blends advisory with the platforms we build, so recommendations arrive with the means to carry them out.
CGRC
Cybersecurity governance, risk and compliance
A comprehensive GRC solution and service that streamlines and fortifies your cybersecurity strategy.
- Current-state assessment and target-state definition
- Rapid maturity analysis with regulatory compliance metrics
- Roadmaps aligned to NIST CSF, ISO 27001, PCI DSS, IEC 62443 and regional frameworks
- Board-level reporting that tracks progress, not just findings
PCIS
Physical, cloud and infrastructure security
Protection across digital and physical domains, from the data-centre floor to the cloud control plane.
- Enterprise and network security architecture
- Cloud security posture, CASB and SASE
- Segmentation, zero trust and defence in depth
- Perimeter, edge and SD-WAN security
IDAS
Identity, data and application security
Robust protection of critical assets and systems: who can reach what, and how data and applications are defended.
- Identity and access management, MFA and privileged access
- Data loss prevention and data classification
- Application security and secure development
- Cryptographic inventory and post-quantum readiness with CADP
CSNOC
Cognitive security and network operations centre
A proactive operations centre for threat detection and response, combining analysts with correlated, AI-assisted detection.
- SIEM and SOAR design and operation
- EDR and XDR, network and host intrusion detection
- MITRE ATT&CK-aligned detection engineering
- 24×7 monitoring and escalation
TTM
Tactical threat management
Incident response, penetration testing, vulnerability and threat management: an honest assessment of your defences and help when they are tested.
- Security incident response and readiness
- Penetration testing and red-team exercises
- Vulnerability assessment and management
- Threat intelligence and hunting
UMSS
Unified managed security services
Secure, unified and automated managed services across all of our competencies, for organisations that want outcomes rather than tooling.
- Managed detection and response
- Managed GRC and compliance monitoring
- Managed infrastructure and cloud security
- Managed cryptographic inventory
Not sure where to start?
A current-state assessment is usually the first engagement. It produces a maturity baseline and a prioritised roadmap in weeks, not months.
