Skip to content

Portfolio

Where the depth actually sits.

149 named services, organised into a structure built for scoping real engagements: how the catalogue is modelled, where departments meet, and the order work actually happens in.

How to read this

Three tiers, and each one answers a different question.

The structure is not decoration; it is how the work is actually organised and staffed. A pillar is a practice. A department is a team with a standing capability. A service is something you can buy on its own or as part of a programme.

Tier 1
Pillar

Which practice owns this problem?

Three practices: Cyber Security, Digital Solutions, Enterprise Applications. Each has its own delivery model, its own partner platforms, and its own idea of what "done" means. Most substantial programmes touch more than one.

Tier 2
Department

Which standing capability does the work?

Nineteen departments. This is the level worth knowing, because it is where expertise is grouped and where a scope is drawn. Depth varies deliberately: a department with thirteen services is not better resourced than one with four, it is answering a broader question.

Tier 3
Service

What are you actually buying?

One hundred and forty-nine named services. Engagements are scoped at this level: deploy a single capability, or the full stack of a department, or a path that crosses several.

Cyber Security10 domains · 104 servicesDigital Solutions6 departments · 28 servicesEnterprise Applications3 departments · 17 services104services28services17servicesPILLARDEPARTMENTSERVICEgroupsdelivers
The fan-out is uneven on purpose. Cyber Security carries seventy per cent of the catalogue because defence is a layered problem: controls are rarely deployed alone, and the domains span governance, data, architecture, network, identity, offensive testing, operations, application, cloud and emerging technology. Enterprise Applications carries the fewest services and the largest programmes.

Portfolio

Where the depth actually sits.

Two views of the same 149 services. The split tells you how the firm is weighted; the department ranking tells you which capabilities are broad and which are deliberately narrow.

Where the practices meet

The departments that arrive together.

Every filled cell is a relationship one department's own service descriptions name explicitly, not an inference. Hover a cell to see the sentence it comes from.

Departments that commonly engage together. A filled cell marks a documented relationship.
Security Governance, Risk & ComplianceData Security & Privacy EngineeringSecurity Architecture & Zero Trust EngineeringNetwork & Edge SecurityIdentity & Access ManagementOffensive Security & Exposure ManagementSecurity Operations, Detection & ResponseApplication & Product SecurityCloud & Container SecurityAI, OT & Emerging Technology SecurityWebsite Design & DevelopmentMobile App DevelopmentCustom Software DevelopmentEnterprise Application DevelopmentAPI & Third-Party System IntegrationCloud-Based Application DevelopmentERP - Enterprise Resource PlanningCRM - Customer Relationship ManagementHRMS / HCM - Human Resource Management
1Security Governance, Risk & ComplianceSecurity Governance, Risk & Compliance works with Data Security & Privacy EngineeringSecurity Governance, Risk & Compliance works with Offensive Security & Exposure ManagementSecurity Governance, Risk & Compliance works with Cloud & Container Security
2Data Security & Privacy EngineeringData Security & Privacy Engineering works with Security Governance, Risk & ComplianceData Security & Privacy Engineering works with Cloud & Container Security
3Security Architecture & Zero Trust EngineeringSecurity Architecture & Zero Trust Engineering works with Network & Edge SecuritySecurity Architecture & Zero Trust Engineering works with Identity & Access ManagementSecurity Architecture & Zero Trust Engineering works with Security Operations, Detection & ResponseSecurity Architecture & Zero Trust Engineering works with AI, OT & Emerging Technology Security
4Network & Edge SecurityNetwork & Edge Security works with Security Architecture & Zero Trust EngineeringNetwork & Edge Security works with Identity & Access ManagementNetwork & Edge Security works with Cloud & Container Security
5Identity & Access ManagementIdentity & Access Management works with Security Architecture & Zero Trust EngineeringIdentity & Access Management works with Network & Edge SecurityIdentity & Access Management works with Security Operations, Detection & ResponseIdentity & Access Management works with Application & Product SecurityIdentity & Access Management works with AI, OT & Emerging Technology Security
6Offensive Security & Exposure ManagementOffensive Security & Exposure Management works with Security Governance, Risk & ComplianceOffensive Security & Exposure Management works with Security Operations, Detection & Response
7Security Operations, Detection & ResponseSecurity Operations, Detection & Response works with Security Architecture & Zero Trust EngineeringSecurity Operations, Detection & Response works with Identity & Access ManagementSecurity Operations, Detection & Response works with Offensive Security & Exposure ManagementSecurity Operations, Detection & Response works with AI, OT & Emerging Technology Security
8Application & Product SecurityApplication & Product Security works with Identity & Access ManagementApplication & Product Security works with Website Design & DevelopmentApplication & Product Security works with Custom Software DevelopmentApplication & Product Security works with Enterprise Application DevelopmentApplication & Product Security works with API & Third-Party System IntegrationApplication & Product Security works with Cloud-Based Application Development
9Cloud & Container SecurityCloud & Container Security works with Security Governance, Risk & ComplianceCloud & Container Security works with Data Security & Privacy EngineeringCloud & Container Security works with Network & Edge SecurityCloud & Container Security works with Cloud-Based Application DevelopmentCloud & Container Security works with ERP - Enterprise Resource Planning
10AI, OT & Emerging Technology SecurityAI, OT & Emerging Technology Security works with Security Architecture & Zero Trust EngineeringAI, OT & Emerging Technology Security works with Identity & Access ManagementAI, OT & Emerging Technology Security works with Security Operations, Detection & Response
11Website Design & DevelopmentWebsite Design & Development works with Application & Product SecurityWebsite Design & Development works with API & Third-Party System Integration
12Mobile App DevelopmentMobile App Development works with API & Third-Party System Integration
13Custom Software DevelopmentCustom Software Development works with Application & Product SecurityCustom Software Development works with API & Third-Party System Integration
14Enterprise Application DevelopmentEnterprise Application Development works with Application & Product SecurityEnterprise Application Development works with ERP - Enterprise Resource PlanningEnterprise Application Development works with CRM - Customer Relationship ManagementEnterprise Application Development works with HRMS / HCM - Human Resource Management
15API & Third-Party System IntegrationAPI & Third-Party System Integration works with Application & Product SecurityAPI & Third-Party System Integration works with Website Design & DevelopmentAPI & Third-Party System Integration works with Mobile App DevelopmentAPI & Third-Party System Integration works with Custom Software DevelopmentAPI & Third-Party System Integration works with Cloud-Based Application DevelopmentAPI & Third-Party System Integration works with ERP - Enterprise Resource PlanningAPI & Third-Party System Integration works with CRM - Customer Relationship ManagementAPI & Third-Party System Integration works with HRMS / HCM - Human Resource Management
16Cloud-Based Application DevelopmentCloud-Based Application Development works with Application & Product SecurityCloud-Based Application Development works with Cloud & Container SecurityCloud-Based Application Development works with API & Third-Party System Integration
17ERP - Enterprise Resource PlanningERP - Enterprise Resource Planning works with Cloud & Container SecurityERP - Enterprise Resource Planning works with Enterprise Application DevelopmentERP - Enterprise Resource Planning works with API & Third-Party System Integration
18CRM - Customer Relationship ManagementCRM - Customer Relationship Management works with Enterprise Application DevelopmentCRM - Customer Relationship Management works with API & Third-Party System Integration
19HRMS / HCM - Human Resource ManagementHRMS / HCM - Human Resource Management works with Enterprise Application DevelopmentHRMS / HCM - Human Resource Management works with API & Third-Party System Integration

Read symmetrically: if Integration names ERP, the pair is marked in both directions. A blank cell means no documented relationship, not that the two never combine.

The integration department is the hub

API & Third-Party System Integration touches more departments than any other, because its own remit names them: CRM, ERP, HRMS, accounting, payments. If a programme spans two pillars, this is usually where the seam is.

Security is not a phase at the end

Application & Product Security links back into every build department, and the architecture, identity and cloud domains link across to them too. That is why security appears in the build phase of the engagement sequence rather than after it, and why the cyber practice carries more departments than the other two combined.

Cloud appears on both sides

Cloud Security and Cloud-Based Application Development share the same primitives: containers, Kubernetes, infrastructure as code. One builds on them, the other secures them, and they are scoped together far more often than separately.

Engagement

What actually happens, in order.

These six phases are numbered because the order is real: each one depends on the decisions made in the last. The dots show which practices run that phase.

  1. 01

    Strategy & advisory

    Establish what the programme is for before choosing anything. Business objectives, current-state assessment, and the constraints that will actually shape the design.

  2. 02

    Architecture & platform selection

    Design the target architecture, and where a platform is involved, run the evaluation against your requirements rather than a vendor's feature grid.

  3. 03

    Implementation & build

    Deploy the technology or build the software. Security-by-design and change management belong here, not as a later phase.

  4. 04

    Integration & migration

    Connect the new to the existing and move the data. Usually the phase that decides whether the programme is judged a success.

  5. 05

    Optimisation

    Tune what is now running (performance, cost, process fit) using evidence from production rather than assumptions from design.

  6. 06

    Ongoing support

    Continuous monitoring and protection, or tiered application support. The phase with no end date, and the one worth scoping properly at the start.

Phase 04 is the one most often under-scoped. Integration and migration is where a programme meets the data and the systems that were already there, and it is usually the phase that decides whether the result is judged a success.