Skip to content

Cyber Security

Finding it, classifying it, encrypting it, deleting it

Controls that follow the data rather than the box it happens to sit in - discovery and classification, cryptography and key custody, egress prevention, and defensible deletion across file shares, databases, object storage, warehouses and SaaS.

What we deliver

Services in this focus area

Every engagement is scoped to your environment - deploy a single capability or the full stack.

  1. 01

    Asset Inventory & Configuration Baseline

    On-PremCloudHybridAdviseBuild

    A single authoritative inventory of hosts, workloads, services and data stores, reconciled continuously rather than surveyed annually.

    • Agent and agentless discovery across estate, cloud accounts and SaaS tenants
    • Ownership, criticality, exposure and lifecycle attribution
    • Reconciliation pipeline into CMDB or ITSM with drift alerting
  2. 02

    Data Discovery, Classification & Labelling

    On-PremCloudHybridAdviseBuild

    Sensitive data located by content and context, then labelled at creation so downstream controls have something to act on.

    • Pattern, dictionary and machine-learning classification across structured and unstructured stores
    • Label taxonomy, auto-labelling rules and user-override governance
    • Sensitive-data map with lineage and regulatory tagging
  3. 03

    Data Loss Prevention Engineering

    On-PremCloudHybridBuildRun

    Egress paths closed at endpoint, network, mail and cloud, tuned to a false-positive rate the business will tolerate.

    • Channel-by-channel policy design with exact-data-match and fingerprinting
    • Staged rollout from monitor to warn to block with tuning cycles
    • Incident triage workflow, user coaching and exception governance
  4. 04

    Data Security Posture Management

    CloudHybridBuildRun

    A continuously current answer to where sensitive data lives in cloud and SaaS, and who can actually reach it.

    • Agentless discovery across object stores, managed databases, warehouses and lakes
    • Effective-access analysis combining identity, resource and network policy
    • Exposure, over-permission and shadow-copy alerting into the SOC
  5. 05

    Enterprise Encryption & Key Management

    On-PremCloudHybridAdviseBuild

    Cryptography you can evidence: approved algorithms, keys you control, rotation that actually happens.

    • Cryptographic standard, algorithm inventory and exception process
    • KMS and HSM architecture with BYOK, HYOK and envelope-encryption patterns
    • Rotation, escrow, dual control and separation-of-duties enforcement
  6. 06

    PKI & Certificate Lifecycle Automation

    On-PremCloudHybridBuildRun

    No outage caused by an expiry nobody owned, and no private CA whose trust chain nobody can explain.

    • Internal CA hierarchy design, remediation or migration
    • ACME-based automated issuance, renewal and revocation
    • Full certificate inventory with ownership and expiry alerting
  7. 07

    Information Rights Management

    On-PremCloudHybridBuild

    Protection that stays attached to the document after it leaves the tenant, the network and the company.

    • Sensitivity label taxonomy with encryption and usage-rights binding
    • Expiry, revocation and offline-access policy
    • Rollout with co-authoring, external-sharing and exception handling
  8. 08

    Database Security, Masking & Activity Monitoring

    On-PremCloudHybridBuildRun

    Systems of record hardened, monitored and de-risked for non-production use.

    • Configuration hardening and privilege review per engine
    • Activity monitoring with anomalous-query and mass-extract detection
    • Dynamic masking, tokenisation and synthetic test-data pipelines
  9. 09

    Data Retention & Defensible Deletion

    On-PremCloudHybridAdviseBuild

    Deletion that can be demonstrated end to end, including the copies nobody logged.

    • Retention schedule per data category with legal-hold interaction
    • Clearing, purging and cryptographic-erasure standards by media type
    • Deletion orchestration across primaries, replicas, backups and analytics copies

Technical deep dive

Deletion you can actually prove, across every copy

Applies wherever a subject-rights or contractual deletion obligation exists and the data has been replicated into analytics, backup and third-party systems - which is to say, everywhere.

What this is

A deletion control plane. Classification labels are attached at creation, a catalogue tracks every downstream copy through lineage, and a deletion orchestrator fans a single request out to every store that holds a copy - including replicas, warehouses, object storage, backups and processors - returning a signed attestation per target.

The problem being solved

A deletion request arrives. The system of record is trivial: one row, one transaction. The problem is the other eleven places that row was copied to - a read replica, a nightly extract into the analytics warehouse, a feature store, an object-storage export a data scientist made in a notebook, four years of backup images, a CSV emailed to a processor, and a non-production environment refreshed from production every night. Deleting the row and declaring the obligation met is factually incorrect, and the organisation cannot demonstrate otherwise because nothing tracked the copies.

Why it is hard

  • Backups are immutable by design. A per-record deletion cannot be executed inside a retention-locked image, so the control has to be crypto-shredding or documented expiry, not a delete statement.
  • Lineage breaks the moment a human exports data. Notebook exports, ad-hoc extracts and email attachments leave no lineage record unless egress is instrumented.
  • Non-production refreshes re-import deleted records the next night unless the pipeline itself is changed, so deletion without pipeline change is temporary.

Reference architecture - step through it

all
INTAKECONTROL PLANETARGET ESTATEDeletion requestsubject, contract or retentionruleIdentity verificationprove the requesterLegal-hold checksuspend if under holdClassification at creationlabels applied on writeData catalogueentities, owners, systemsLineage graphevery downstream copyDeletion orchestratorfan-out, retry, verifyAttestation ledgersigned per-target receiptsTransactional storehard delete + tombstoneRead replicaspropagated, then verifiedWarehouse & lakerow and partition rewriteObject storageversioned object purgeBackup imagescrypto-shred key, log expirySaaS & processorsAPI delete + attestationNon-productionmasked refresh, not copyEgress instrumentationcaptures ad-hoc exportsclearedlabelsback-fills lineage
One request, per-target semantics, signed receiptsjson
{
  "request_id": "del-7f3a91",
  "subject_ref": "sha256:9c1e…",            // pseudonymous, never the raw identifier
  "basis": "subject_erasure_request",
  "legal_hold": { "checked": true, "active": false },
  "targets": [
    { "system": "orders-oltp",     "op": "hard_delete + tombstone",
      "rows": 14,  "receipt": "sig:3af1…", "at": "2026-03-04T09:12:07Z" },
    { "system": "warehouse.fact_order", "op": "partition_rewrite",
      "rows": 14,  "partitions": 3, "receipt": "sig:71bc…" },
    { "system": "object-store/exports", "op": "purge_all_versions",
      "objects": 2, "delete_markers_removed": 2, "receipt": "sig:9d02…" },
    { "system": "backup-vault",    "op": "crypto_shred",
      "key_id": "sub-key-7f3a91", "key_destroyed": true,
      "ciphertext_expires": "2027-03-04", "receipt": "sig:c55e…" },
    { "system": "processor:analytics-vendor", "op": "api_delete",
      "attestation_received": true, "receipt": "sig:ea77…" }
  ],
  "non_production": { "refresh_mode": "synthetic", "reimport_risk": "eliminated" },
  "status": "complete", "closed_at": "2026-03-04T09:41:55Z"
}

Measured change

MeasureBeforeAfter
Known copies of a regulated entity3 (assumed)11 (measured)
Time to close a deletion request9–14 days, manualunder 45 minutes, orchestrated
Evidence of completionan email saying donesigned receipt per target
Storage footprint after clean-upbaseline31% reduction - expired data had never left

The obligation stopped being an investigation and became a query. The side effect the platform team cared about more: a third of the estate turned out to be data with no remaining reason to exist.

Talk to a data security & privacy engineering specialist.

Schedule a free consultation and our team will connect within 12 hours to understand your environment and map out the right approach.

We respond within 12 hours