SERVICE DIRECTORY
Find the service.
Understand the scope.
Search by need or filter by family. Every service explains what it addresses, what is delivered and how the outcome is verified.

100 results
AUD-01 / Audits & assessments
Cybersecurity maturity assessment
A review of practices, tools and responsibilities to decide what to secure first, rather than starting with a product purchase.
AUD-02 / Audits & assessments
Infrastructure security audit
An examination of server, network, access and infrastructure-service architecture and configurations to identify weaknesses and protection gaps.
AUD-03 / Audits & assessments
Identity and privilege audit
A review of who has which access, how accounts are protected and how a compromised identity could affect sensitive resources.
AUD-04 / Audits & assessments
Cloud and collaboration security review
A review of a tenant’s security configuration and usage: identities, sharing, connected applications, logs and responsibilities.
AUD-05 / Audits & assessments
Network, segmentation and firewall audit
A review of communication paths and filtering rules to understand what can reach what and identify unjustified exposure.
AUD-06 / Audits & assessments
Backup and recovery readiness audit
A review of whether backups cover the right systems, resist malicious use and support recovery requirements.
AUD-07 / Audits & assessments
Cybersecurity awareness programme audit
An assessment of risk understanding and awareness-programme effectiveness, beyond simply counting training attendance.
PEN-01 / Penetration testing
External penetration testing
An authorised simulation of an internet-based attacker to assess whether exposed services allow unauthorised access or actions.
PEN-02 / Penetration testing
Internal and assumed-breach penetration testing
An assessment of what an attacker could reach after gaining an initial internal foothold, examining excessive privileges and weak separation.
PEN-03 / Penetration testing
Web application penetration testing
Testing browser-based applications for weaknesses, particularly in authentication, authorisation and business workflows.
PEN-04 / Penetration testing
API penetration testing
Testing the interfaces applications use to exchange data, with particular attention to object-level permissions and abusive usage.
PEN-05 / Penetration testing
Mobile application security testing
Assessment of an Android or iOS application and its communications to identify exposed data and inadequate security controls.
PEN-06 / Penetration testing
Wireless security testing
Assessment of wireless networks, authentication and separation to reduce unauthorised access near company premises.
PEN-07 / Penetration testing
Cloud and IAM penetration testing
Controlled testing of abuse scenarios in a cloud environment, beyond configuration review alone.
PEN-08 / Penetration testing
Objective-based red team exercise
A coordinated adversary simulation to exercise prevention, detection and response against a defined business objective.
PEN-09 / Penetration testing
Purple teaming and control validation
Joint work between testers and defenders to verify that simulated malicious behaviour produces the expected signals and responses.
GRC-01 / Risk & governance
EBIOS Risk Manager risk assessment
A structured method linking business objectives to cyber-risk scenarios and a treatment plan decided by the organisation.
GRC-02 / Risk & governance
EBIOS 2010 review and transition to EBIOS RM
Updating a legacy EBIOS 2010 assessment or supporting its transition to EBIOS Risk Manager without treating the versions as interchangeable.
GRC-03 / Risk & governance
ISO/IEC 27001 and ISMS implementation support
Establishing an information security management system: responsibilities, risks, controls, evidence and continual improvement, with optional certification preparation.
GRC-04 / Risk & governance
NIS 2 readiness and security improvement plan
Support to assess potential NIS 2 applicability and develop relevant technical, organisational and evidence-based security measures.
GRC-05 / Risk & governance
DORA and ICT risk-management support
Support for digital operational resilience at in-scope financial organisations and for evidence requested from their ICT providers.
GRC-06 / Risk & governance
Fractional CISO and cybersecurity governance
Recurring executive support to manage security risks, priorities, projects and decisions without immediately hiring a full-time CISO.
GRC-07 / Risk & governance
Security policies, procedures and project governance
Defining understandable, enforceable rules for access, usage, operations and security decisions within projects.
GRC-08 / Risk & governance
Third-party and supply-chain risk management
Assessing risks introduced by external providers, software and services according to their access and business importance.
HUM-01 / Awareness & culture
Cybersecurity awareness programme
An ongoing learning programme helping employees recognise risky situations and adopt practical safeguards in their work.
HUM-02 / Awareness & culture
Phishing simulations and coaching
Controlled simulated phishing exercises to observe responses, improve reporting and target training without collecting real credentials.
HUM-03 / Awareness & culture
Fraud prevention for executives and sensitive roles
Practical training for verifying sensitive requests: payments, bank-detail changes, data disclosure or instructions apparently from executives.
HUM-04 / Awareness & culture
Security training for technical teams
Practical training for developers, administrators and operations teams to implement required controls in everyday work.
HUM-05 / Awareness & culture
Security champions and security culture programme
Developing volunteer security champions in business or technical teams to share good practices and surface practical difficulties.
REM-01 / Remediation
Technical remediation after audits or penetration tests
Implementing identified fixes with testing and rollback preparation to turn audit findings into operational controls.
REM-02 / Remediation
Guided remediation for in-house teams
Support for teams that can implement changes but need prioritisation, specialist advice and validation.
REM-03 / Remediation
Remediation programme and cross-team delivery management
Organising security workstreams across teams or providers, with priorities, dependencies and executive decisions.
REM-04 / Remediation
Urgent remediation of critical vulnerabilities
Controlled remediation of priority vulnerabilities, considering exposure, exploitability and production constraints.
REM-05 / Remediation
Compensating controls and legacy-system protection
Reducing exposure of systems that cannot be fixed immediately, with explicit risk tracking and a replacement roadmap.
REM-06 / Remediation
Remediation retesting and closure validation
Targeted verification that identified vulnerabilities or gaps have been fixed, maintaining a clear link to the original finding.
IAM-01 / Identity & access
Identity lifecycle and role management
Organising account creation, changes and removal so each person receives the right access at the right time for the right duration.
IAM-02 / Identity & access
Single sign-on and identity federation
Centralised application sign-in using a governed identity, with access policies, monitoring and emergency access.
IAM-03 / Identity & access
MFA, passkeys and stronger authentication
Strengthening sign-in with additional factors or phishing-resistant methods while governing account recovery.
IAM-04 / Identity & access
PAM and privileged-access security
Stronger control over administrative access: named identities, limited privileges, approvals and traceability of sensitive actions.
IAM-05 / Identity & access
Directory hardening and secure administration
Hardening the services that manage identities and authorisation to reduce excessive privileges and unsafe administrative access.
IAM-06 / Identity & access
Secrets and workload identity management
Protecting application keys, tokens and accounts to reduce shared, forgotten or code-embedded secrets.
IAM-07 / Identity & access
Access certification and access governance
Organising campaigns in which accountable owners verify that user and third-party permissions remain justified.
MSG-01 / Email & fraud protection
Email and anti-phishing protection — Proofpoint
Deploying and tuning protection against malicious email, dangerous attachments and impersonation, with alert handling.
MSG-02 / Email & fraud protection
SPF, DKIM and DMARC domain authentication
Configuring mechanisms that help recipients verify email origin and handle unauthorised use of a domain.
MSG-03 / Email & fraud protection
Business email compromise risk reduction
Combining email, identity and business-process controls to reduce fraud that may contain no malicious attachment, including payment requests.
MSG-04 / Email & fraud protection
Microsoft 365 or Google Workspace email hardening
Tuning existing email services to reduce abuse of accounts, delegation, forwarding and connected applications.
MSG-05 / Email & fraud protection
Email DLP and protected message exchange
Controlling sensitive-data email and protecting exchanges where recipients, content or context require additional safeguards.
NET-01 / Network security
Next-generation firewall deployment and migration — Palo Alto Networks
Install or replace a firewall that controls network traffic and enforces security policies suited to applications and users. The project covers architecture, rule migration and operational readiness.
NET-02 / Network security
Network segmentation and microsegmentation
Separate environments and restrict communication to what is necessary so that a compromised device or service does not gain broad access to information systems. Separation must be tested, not merely diagrammed.
NET-03 / Network security
Network intrusion detection and prevention — IDS/IPS
An IDS observes and alerts on suspicious activity; an IPS can also block traffic when deployed in an enforcement position. The service deploys, tunes and connects these controls to a handling process.
NET-04 / Network security
Secure remote access and Zero Trust Network Access
Give each user or supplier access only to required resources after verifying identity and access conditions. The project reduces broad network access without presenting Zero Trust as a magic product.
NET-05 / Network security
Secure internet access and SASE/SWG architecture
Control users’ web and cloud access in the office and remotely through consistent policies. SASE combines networking and security capabilities; the actual purchased scope must be defined.
NET-06 / Network security
Published application protection — WAF and API gateway
Add controls in front of exposed applications and APIs: request filtering, access restrictions and usage limits. This complements secure code without automatically fixing business-logic flaws.
NET-07 / Network security
DNS security and protective resolution filtering
Protect the service that resolves domain names and control destinations resolved by devices. The service addresses internal DNS availability and detection or blocking of domains considered dangerous.
END-01 / Endpoints & vulnerabilities
EDR/XDR deployment and integration
Deploy and configure detection and response tools on workstations and servers. EDR focuses on endpoints; XDR correlates multiple security sources according to the platform and licensing.
END-02 / Endpoints & vulnerabilities
Workstation, server and baseline-image hardening
Remove unnecessary functionality and apply reproducible security settings to systems. Hardening must remain compatible with business use and be maintained through changes and updates.
END-03 / Endpoints & vulnerabilities
Mobile device and application security — MDM/MAM
Govern phones, tablets and business applications: configuration, access, data separation and lost-device response. MDM manages devices; MAM manages compatible applications and their data.
END-04 / Endpoints & vulnerabilities
Application, device and local-privilege control
Restrict executable software, usable peripherals and privilege elevation on sensitive devices. The service also governs exceptions so protection does not prevent legitimate work.
END-05 / Endpoints & vulnerabilities
Continuous vulnerability and patch management
Establish a recurring cycle to find vulnerabilities, prioritise them by exposure and impact, schedule remediation and verify closure. Scanning produces observations; management adds ownership and follow-through.
DAT-01 / Data protection
Sensitive-data discovery and classification
Identify information requiring protection, where it resides, who owns it and how sensitive it is. Classification provides a practical basis for access, sharing, retention and protection decisions.
DAT-02 / Data protection
Multichannel data loss prevention — DLP
Detect and govern sensitive-data transfers through selected channels: email, cloud services, endpoints or removable media. DLP combines classification, policies, exceptions and human review of events.
DAT-03 / Data protection
Secure sharing and external collaboration
Enable exchanges with customers and partners without permanently exposing data to an overly broad audience. The project addresses links, guests, permissions, shared workspaces and removal procedures.
DAT-04 / Data protection
Encryption, key and certificate management
Protect data and communications through cryptography while organising key and certificate storage, rotation and recovery. Encryption that prevents recovery can itself become a risk.
DAT-05 / Data protection
Personal-data security and technical DPIA support
Assess and strengthen technical and organisational measures protecting personal data, supporting the DPO and controllers. The project supplies security evidence; it does not replace their legal assessment.
DAT-06 / Data protection
Insider data-risk management and proportionate investigation
Organise prevention and analysis of internal activity that may expose sensitive information without treating an alert as proof of misconduct. The programme combines data rules, investigation procedures and privacy safeguards.
CLD-01 / Cloud & SaaS
Secure cloud foundations — landing zone
Build consistent cloud foundations before projects multiply: environment separation, identity, networking, logs, security and spending control. A landing zone establishes guardrails without automatically securing every application.
CLD-02 / Cloud & SaaS
Cloud security posture management — CSPM
Detect exposed cloud configurations or deviations from selected policies and organise remediation. CSPM tracks technical posture; it does not replace full event monitoring or application assessment.
CLD-03 / Cloud & SaaS
Microsoft 365 security implementation
Strengthen identity, data, collaboration and security visibility coherently in a Microsoft 365 environment. The project starts from actual licensing and usage rather than assuming features are available.
CLD-04 / Cloud & SaaS
Google Workspace security implementation
Configure Google Workspace identity, sharing and security controls according to organisational needs. The aim is understandable, tested and manageable policies.
CLD-05 / Cloud & SaaS
Kubernetes, container and registry security
Secure container environments from images to clusters and operations. The project addresses permissions, isolation, secrets, image provenance and workload visibility.
CLD-06 / Cloud & SaaS
SaaS posture and ungoverned application management
Inventory cloud applications and govern their configuration, integrations and lifecycle. The service also addresses tools adopted without approval by providing a secure usage path rather than an abstract ban.
APP-01 / Application security
Threat modelling and secure design
Examine an application before or during design to identify sensitive assets, trust boundaries and abuse scenarios. The aim is to select appropriate controls before architectural mistakes become expensive to fix.
APP-02 / Application security
Source-code review and application security verification
Analyse application code and configuration to identify security defects and understand their causes. Automated tools help target review, but findings must be validated and linked to usage.
APP-03 / Application security
CI/CD security and DevSecOps integration
Integrate security controls into development and deployment with understandable blocking and exception rules. The project also protects the software delivery chain itself: accounts, runners, secrets and permissions.
APP-04 / Application security
Dependency and software supply-chain security — SCA/SBOM
Know a software product’s components and govern provenance, vulnerabilities and updates. An SBOM describes components; it must be used and maintained to support security.
APP-05 / Application security
API architecture and security implementation
Design or fix API controls so each client accesses only authorised data and actions. The project covers identity, business authorisation, validation, quotas and traceability.
SOC-01 / Security operations
Managed SOC — monitoring, triage and escalation
Entrust a specialist team with monitoring agreed sources, analysing alerts and escalating incidents. A SOC combines people, processes and tools; its service level depends on scope and contract.
SOC-02 / Security operations
Co-managed SOC and internal-team support
Complement an existing security team with expertise, triage capacity or shared monitoring scope. The service specifies who monitors, decides and acts, and how cases transfer between teams.
SOC-03 / Security operations
Log collection and SIEM deployment
Centralise useful security events and make them usable for searching, alerting and investigations. The project addresses quality, timestamps, retention and cost as much as platform installation.
SOC-04 / Security operations
Detection engineering and rule improvement
Design and maintain detection rules tied to customer risks, with testing and investigation procedures. The aim is useful, explainable alerts rather than an uncontrolled catalogue of enabled rules.
SOC-05 / Security operations
Security orchestration and response automation — SOAR
Automate repetitive alert enrichment and handling tasks, retaining human approval for sensitive actions. SOAR connects tools and procedures; it does not replace judgement in complex incidents.
SOC-06 / Security operations
Proactive compromise investigation — threat hunting
Search for suspicious behaviour using explicit hypotheses beyond existing alerts. Hunting covers a defined scope and period; it may find no evidence, but cannot prove the absolute absence of compromise.
SOC-07 / Security operations
Threat intelligence and external exposure monitoring
Identify threats and exposed assets relevant to the organisation and turn information into action. The service distinguishes contextual intelligence, external attack-surface inventory and technical vulnerability validation.
RES-01 / Response & resilience
Incident response and digital investigation — DFIR
Help understand an incident, limit its effects, preserve useful evidence and prepare controlled recovery. Investigation separates established facts, hypotheses and missing data; it does not cover all legal or communication decisions on its own.
RES-02 / Response & resilience
Incident-response readiness and assistance retainer
Prepare contacts, permissions, access and procedures before an incident to avoid delays at activation. A retainer specifies assistance conditions; it must not be sold as guaranteed intervention without a formal commitment.
RES-03 / Response & resilience
Business impact analysis, continuity and disaster recovery planning
Determine which activities must recover first and prepare continuity or restoration. Business continuity planning covers business operations; disaster recovery planning describes restoration of the supporting information systems.
RES-04 / Response & resilience
Ransomware-resilient backup implementation
Build backup arrangements whose data and administration better withstand compromise of the primary environment. The project combines access separation, protected copies, monitoring and restore testing.
RES-05 / Response & resilience
Restore exercises and secure rebuild validation
Verify that data and services can actually be restored in a controlled environment. The exercise measures timing, reveals dependencies and tests procedures before a real incident creates urgency.
RES-06 / Response & resilience
Cyber crisis and tabletop exercises
Bring leadership, business teams, IT and support functions together around a crisis scenario without actually attacking production. The exercise tests decisions, coordination, messaging and use of procedures.
AI-01 / Secure AI
Secure enterprise AI deployment
Provide useful AI to teams within a controlled framework: approved uses, identities, data, integrations, costs and operations. Security covers the whole service, not merely the selected model.
AI-02 / Secure AI
AI governance and risk assessment
Identify AI uses, owners and risks to decide what may be deployed and under which conditions. The programme links quality, security, personal data, human oversight and change monitoring.
AI-03 / Secure AI
Permission-aware RAG document assistant
Connect an assistant to enterprise documents without granting more access than the user has. RAG retrieves material before generating an answer; permissions must be enforced before prohibited data enters the model’s context.
AI-04 / Secure AI
AI cost controls, quotas and access gateway
Make AI consumption attributable and controllable by user, team or application. The project combines measurement, model selection, quotas, alerts and tested enforcement without confusing budget notifications with blocking.
AI-05 / Secure AI
AI system security testing and validation
Assess a complete AI application: model, data, connectors, policies, tools and users. Tests examine information leakage, malicious instructions received by the system and limits on possible actions.
AI-06 / Secure AI
AI agent and enterprise-action security
Govern AI that can use tools or act: least privilege, task boundaries, approval of sensitive operations and a stop mechanism. An agent must not automatically inherit every permission of its operator.
AI-07 / Secure AI
Private AI hosting and data-lifecycle control
Deploy or scope AI in an environment with controlled hosting, access and processing. The service examines model, inference, indexes, logs, backups and subprocessors; private hosting is not automatically secure.
SPC-01 / Specialist security
Industrial environment security — OT/ICS
Assess and strengthen systems controlling physical processes while respecting availability and safety. Standard IT methods must be adapted with operators and control-system engineers.
SPC-02 / Specialist security
IoT and building-system security
Identify and secure connected equipment often managed outside IT: cameras, access control, sensors or building-management systems. The service connects ownership, networking, updates and data protection.
SPC-03 / Specialist security
Cyber due diligence and post-acquisition integration
Assess cyber risks in an acquisition or merger and plan integration without propagating weaknesses between environments. The project provides decision evidence, not a guarantee against every hidden risk.
SPC-04 / Specialist security
Security assurance case and accreditation support
Assemble evidence and decisions enabling a competent authority to accept a system’s risks within a defined framework. The provider prepares the case; it does not replace the decision-maker or grant accreditation merely by delivering a service.
No matching results. Try a broader term or another family.
START A CONVERSATION
Let’s put the next step in focus.
Tell us what you need to protect, change or understand. We will start with the scope, not a product list.
