Our services
Expertise whereit matters most.
Six connected service areas covering the full arc from understanding your risk to sustaining resilience over time.
Engaged individually or as a coordinated programme, with ongoing audits, compliance reviews and improvement — always sized to your organisation.
Information Security
Senior security leadership through vCISO support, and an ISO 27001 management system built around your business.
We design and implement information security management systems (ISMS) aligned to ISO/IEC 27001 and adapted to how your organisation actually works. That means practical policies people follow, controls sized to real risk, and evidence that stands up in a certification audit or a customer security review.
Typical outcome
A certifiable, maintainable security management system with clear ownership and a control set proportionate to your risk.
What this includes
- vCISO leadership: governance, strategy and roadmaps without a full-time CISO
- ISMS design, implementation and certification readiness (ISO/IEC 27001:2022)
- Security gap assessments against ISO 27001, NIST CSF and CIS Controls
- Policy, standard and procedure frameworks that people actually use
- Security architecture and control design review
- Internal audits and management review support
- Interim or fractional security leadership (BISO / vCISO)
Risk Management
Turn a long list of possible problems into a short list of decisions your leadership can act on.
Risk management only creates value when it changes decisions. We establish risk frameworks that produce comparable, quantified results — so investment goes where exposure is greatest, and so the board sees a coherent picture rather than a heat map nobody trusts.
Typical outcome
A prioritised, costed risk picture your leadership team can use to allocate budget with confidence.
What this includes
- Enterprise and information risk framework design (ISO 31000 aligned)
- Risk assessments, scenario analysis and business impact quantification
- Risk appetite definition and tolerance thresholds
- Third-party and vendor risk management programmes
- Risk register design, treatment planning and remediation tracking
- Board-level and executive risk reporting
Resilience & Business Continuity
Plan for the disruption you will actually face — and rehearse it before it happens.
Continuity plans fail in the moment when nobody has practised them. We build business continuity and crisis management capability aligned to ISO 22301, grounded in a rigorous business impact analysis, and then we test it with your people under realistic pressure.
Typical outcome
Tested plans, trained people and recovery objectives you can evidence to customers, insurers and regulators.
What this includes
- Business impact analysis (BIA) and dependency mapping
- Business continuity management programmes (ISO 22301 aligned)
- IT disaster recovery strategy, RTO/RPO definition and validation
- Crisis management structures, escalation paths and decision authority
- Incident response planning and playbook development
- Tabletop exercises, simulations and post-exercise improvement plans
Compliance & Governance
Navigate NIS2, ENS, DORA, GDPR security and the Cyber Resilience Act through one coordinated programme.
European regulation has multiplied faster than most organisations can absorb. We map overlapping obligations onto a single control framework, so one piece of evidence satisfies several requirements — and so governance becomes a management tool rather than an annual scramble.
Typical outcome
A defensible compliance position with a single evidence base and a clear, dated roadmap to close remaining gaps.
What this includes
- NIS2 applicability analysis, gap assessment and implementation roadmap
- ENS (Esquema Nacional de Seguridad) readiness for organisations working with Spain’s public sector, where applicable
- DORA readiness for financial entities and ICT providers, where applicable
- GDPR technical and organisational security measures, alongside your DPO or legal advisers
- CRA readiness for in-scope products with digital elements: reporting obligations from 11 September 2026; main obligations from 11 December 2027
- Unified control frameworks that map obligations to shared evidence
- Governance structures, committee design and audit preparation
OT, Product & Supply Chain Security
Extend security to the plant floor, the products you ship and the suppliers you depend on.
For manufacturers, energy and logistics operators, the greatest exposure often sits outside the corporate network — in production systems that cannot be patched on demand, in shipped products with decade-long lifecycles, and in suppliers with access you have never assessed.
Explore our ReadinessNavigator partnershipTypical outcome
Visibility and control across production, product and supplier estates — with risk owners named for each.
What this includes
- OT and ICS security assessments aligned to IEC 62443
- IT/OT segmentation, secure remote access and asset inventory
- Product security and secure development lifecycle (SDLC) design
- SBOM practices and vulnerability handling for shipped products
- Supplier due diligence, security requirements and contract clauses
- Supply chain dependency mapping and concentration risk analysis
Training & Awareness
Give every level of the organisation the judgement to make good security decisions.
Awareness campaigns fail when they are generic. We build role-based programmes that speak to what people actually do — from executives weighing regulatory exposure to engineers making architecture choices to plant staff facing a suspicious request.
Typical outcome
Measurable behaviour change and a workforce that escalates the right things early.
What this includes
- Executive and board briefings on risk, regulation and accountability
- Role-based security training for engineering, operations and administration
- Security awareness programme design, delivery and measurement
- Phishing simulation programmes with coaching rather than blame
- ISO/IEC 27001 internal auditor and implementer training
- Crisis communication and decision-making workshops
Not sure where to start?Bring us your question.
You don’t need to identify the right regulation or framework first. Tell us what concerns you, and we’ll help you understand your obligations and agree practical next steps.


