Portfolio split
Share of named services by pillar.
- Cyber Security 104 · 70%
- Digital Solutions 28 · 19%
- Enterprise Applications 17 · 11%
Portfolio
149 named services, organised into a structure built for scoping real engagements: how the catalogue is modelled, where departments meet, and the order work actually happens in.
How to read this
The structure is not decoration; it is how the work is actually organised and staffed. A pillar is a practice. A department is a team with a standing capability. A service is something you can buy on its own or as part of a programme.
Three practices: Cyber Security, Digital Solutions, Enterprise Applications. Each has its own delivery model, its own partner platforms, and its own idea of what "done" means. Most substantial programmes touch more than one.
Nineteen departments. This is the level worth knowing, because it is where expertise is grouped and where a scope is drawn. Depth varies deliberately: a department with thirteen services is not better resourced than one with four, it is answering a broader question.
One hundred and forty-nine named services. Engagements are scoped at this level: deploy a single capability, or the full stack of a department, or a path that crosses several.
Portfolio
Two views of the same 149 services. The split tells you how the firm is weighted; the department ranking tells you which capabilities are broad and which are deliberately narrow.
Share of named services by pillar.
All 19 departments, deepest first. Select any bar to open that department in the catalogue.
Where the practices meet
Every filled cell is a relationship one department's own service descriptions name explicitly, not an inference. Hover a cell to see the sentence it comes from.
| Security Governance, Risk & Compliance | Data Security & Privacy Engineering | Security Architecture & Zero Trust Engineering | Network & Edge Security | Identity & Access Management | Offensive Security & Exposure Management | Security Operations, Detection & Response | Application & Product Security | Cloud & Container Security | AI, OT & Emerging Technology Security | Website Design & Development | Mobile App Development | Custom Software Development | Enterprise Application Development | API & Third-Party System Integration | Cloud-Based Application Development | ERP - Enterprise Resource Planning | CRM - Customer Relationship Management | HRMS / HCM - Human Resource Management | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1Security Governance, Risk & Compliance | Security Governance, Risk & Compliance works with Data Security & Privacy Engineering | Security Governance, Risk & Compliance works with Offensive Security & Exposure Management | Security Governance, Risk & Compliance works with Cloud & Container Security | ||||||||||||||||
| 2Data Security & Privacy Engineering | Data Security & Privacy Engineering works with Security Governance, Risk & Compliance | Data Security & Privacy Engineering works with Cloud & Container Security | |||||||||||||||||
| 3Security Architecture & Zero Trust Engineering | Security Architecture & Zero Trust Engineering works with Network & Edge Security | Security Architecture & Zero Trust Engineering works with Identity & Access Management | Security Architecture & Zero Trust Engineering works with Security Operations, Detection & Response | Security Architecture & Zero Trust Engineering works with AI, OT & Emerging Technology Security | |||||||||||||||
| 4Network & Edge Security | Network & Edge Security works with Security Architecture & Zero Trust Engineering | Network & Edge Security works with Identity & Access Management | Network & Edge Security works with Cloud & Container Security | ||||||||||||||||
| 5Identity & Access Management | Identity & Access Management works with Security Architecture & Zero Trust Engineering | Identity & Access Management works with Network & Edge Security | Identity & Access Management works with Security Operations, Detection & Response | Identity & Access Management works with Application & Product Security | Identity & Access Management works with AI, OT & Emerging Technology Security | ||||||||||||||
| 6Offensive Security & Exposure Management | Offensive Security & Exposure Management works with Security Governance, Risk & Compliance | Offensive Security & Exposure Management works with Security Operations, Detection & Response | |||||||||||||||||
| 7Security Operations, Detection & Response | Security Operations, Detection & Response works with Security Architecture & Zero Trust Engineering | Security Operations, Detection & Response works with Identity & Access Management | Security Operations, Detection & Response works with Offensive Security & Exposure Management | Security Operations, Detection & Response works with AI, OT & Emerging Technology Security | |||||||||||||||
| 8Application & Product Security | Application & Product Security works with Identity & Access Management | Application & Product Security works with Website Design & Development | Application & Product Security works with Custom Software Development | Application & Product Security works with Enterprise Application Development | Application & Product Security works with API & Third-Party System Integration | Application & Product Security works with Cloud-Based Application Development | |||||||||||||
| 9Cloud & Container Security | Cloud & Container Security works with Security Governance, Risk & Compliance | Cloud & Container Security works with Data Security & Privacy Engineering | Cloud & Container Security works with Network & Edge Security | Cloud & Container Security works with Cloud-Based Application Development | Cloud & Container Security works with ERP - Enterprise Resource Planning | ||||||||||||||
| 10AI, OT & Emerging Technology Security | AI, OT & Emerging Technology Security works with Security Architecture & Zero Trust Engineering | AI, OT & Emerging Technology Security works with Identity & Access Management | AI, OT & Emerging Technology Security works with Security Operations, Detection & Response | ||||||||||||||||
| 11Website Design & Development | Website Design & Development works with Application & Product Security | Website Design & Development works with API & Third-Party System Integration | |||||||||||||||||
| 12Mobile App Development | Mobile App Development works with API & Third-Party System Integration | ||||||||||||||||||
| 13Custom Software Development | Custom Software Development works with Application & Product Security | Custom Software Development works with API & Third-Party System Integration | |||||||||||||||||
| 14Enterprise Application Development | Enterprise Application Development works with Application & Product Security | Enterprise Application Development works with ERP - Enterprise Resource Planning | Enterprise Application Development works with CRM - Customer Relationship Management | Enterprise Application Development works with HRMS / HCM - Human Resource Management | |||||||||||||||
| 15API & Third-Party System Integration | API & Third-Party System Integration works with Application & Product Security | API & Third-Party System Integration works with Website Design & Development | API & Third-Party System Integration works with Mobile App Development | API & Third-Party System Integration works with Custom Software Development | API & Third-Party System Integration works with Cloud-Based Application Development | API & Third-Party System Integration works with ERP - Enterprise Resource Planning | API & Third-Party System Integration works with CRM - Customer Relationship Management | API & Third-Party System Integration works with HRMS / HCM - Human Resource Management | |||||||||||
| 16Cloud-Based Application Development | Cloud-Based Application Development works with Application & Product Security | Cloud-Based Application Development works with Cloud & Container Security | Cloud-Based Application Development works with API & Third-Party System Integration | ||||||||||||||||
| 17ERP - Enterprise Resource Planning | ERP - Enterprise Resource Planning works with Cloud & Container Security | ERP - Enterprise Resource Planning works with Enterprise Application Development | ERP - Enterprise Resource Planning works with API & Third-Party System Integration | ||||||||||||||||
| 18CRM - Customer Relationship Management | CRM - Customer Relationship Management works with Enterprise Application Development | CRM - Customer Relationship Management works with API & Third-Party System Integration | |||||||||||||||||
| 19HRMS / HCM - Human Resource Management | HRMS / HCM - Human Resource Management works with Enterprise Application Development | HRMS / HCM - Human Resource Management works with API & Third-Party System Integration |
Read symmetrically: if Integration names ERP, the pair is marked in both directions. A blank cell means no documented relationship, not that the two never combine.
API & Third-Party System Integration touches more departments than any other, because its own remit names them: CRM, ERP, HRMS, accounting, payments. If a programme spans two pillars, this is usually where the seam is.
Application & Product Security links back into every build department, and the architecture, identity and cloud domains link across to them too. That is why security appears in the build phase of the engagement sequence rather than after it, and why the cyber practice carries more departments than the other two combined.
Cloud Security and Cloud-Based Application Development share the same primitives: containers, Kubernetes, infrastructure as code. One builds on them, the other secures them, and they are scoped together far more often than separately.
Engagement
These six phases are numbered because the order is real: each one depends on the decisions made in the last. The dots show which practices run that phase.
Establish what the programme is for before choosing anything. Business objectives, current-state assessment, and the constraints that will actually shape the design.
Design the target architecture, and where a platform is involved, run the evaluation against your requirements rather than a vendor's feature grid.
Deploy the technology or build the software. Security-by-design and change management belong here, not as a later phase.
Connect the new to the existing and move the data. Usually the phase that decides whether the programme is judged a success.
Tune what is now running (performance, cost, process fit) using evidence from production rather than assumptions from design.
Continuous monitoring and protection, or tiered application support. The phase with no end date, and the one worth scoping properly at the start.