Skip to content

Cyber Security

Deciding what gets built, funded and proved

The control plane above the technology: what the organisation has decided to protect, how much risk it will carry, and how it evidences that to auditors, insurers, regulators and customers in every market it operates in. Framework-led rather than jurisdiction-led - one control set, mapped outward to whichever regime asks.

What we deliver

Services in this focus area

Every engagement is scoped to your environment - deploy a single capability or the full stack.

  1. 01

    Security Strategy & Target Operating Model

    On-PremCloudHybridAdvise

    A costed multi-year security plan anchored to business risk, with an operating model that says who runs each control.

    • Current-state baseline across people, process and technology
    • Target operating model with RACI down to control-owner level
    • Sequenced, costed initiative roadmap and board investment case
  2. 02

    Control Framework Mapping & Maturity Assessment

    On-PremCloudHybridAdvise

    One internal control library, scored for maturity and cross-mapped so a single piece of evidence satisfies several frameworks at once.

    • Maturity scoring against ISO/IEC 27001:2022, NIST CSF 2.0 and CIS Controls v8.1
    • Crosswalk matrix collapsing overlapping controls into a unified library
    • Gap register with effort, dependency and remediation sequencing
  3. 03

    Enterprise Cyber Risk Assessment

    On-PremCloudHybridAdvise

    A risk register the business will argue with - scenarios, named owners, and treatment decisions that are actually made.

    • Threat modelling from crown-jewel assets outward
    • Likelihood and impact scoring with documented rationale
    • Treatment plan with accept, mitigate, transfer and avoid decisions recorded
  4. 04

    Cyber Risk Quantification

    On-PremCloudHybridAdvise

    Security risk expressed as a loss distribution in currency, so it competes on the same terms as every other capital request.

    • FAIR-based loss exposure modelling with Monte Carlo ranges
    • Scenario decomposition for the top exposure drivers
    • Control ROI comparison and insurance limit adequacy analysis
  5. 05

    Policy, Standard & Control Library Engineering

    On-PremCloudHybridAdviseBuild

    A document hierarchy engineers can follow and an assessor will accept, versioned like code rather than kept in a shared drive.

    • Policy, standard, procedure and baseline hierarchy
    • Technical baselines per platform family with measurable statements
    • Exception register, review cadence and change-control workflow
  6. 06

    ISMS Design & Certification Support

    On-PremCloudHybridAdviseBuild

    A management system that survives surveillance audits without a fire drill each cycle.

    • Scope definition, risk methodology and Statement of Applicability
    • Annex A control build-out with evidence pipelines per control
    • Internal audit programme, management review and certification-body liaison
  7. 07

    Audit Readiness & Continuous Control Monitoring

    On-PremCloudHybridAdviseBuild

    Evidence produced as a by-product of running the controls, not assembled in the fortnight before fieldwork.

    • Readiness gap assessment against the target attestation or standard
    • Automated evidence collection wired to the systems of record
    • Control-failure alerting and auditor liaison through fieldwork
  8. 08

    Multi-Jurisdiction Compliance Engineering

    On-PremCloudHybridAdviseBuild

    One control set that answers every regime the business trades under, with the deltas isolated rather than duplicated.

    • Applicability analysis across the markets and sectors in scope
    • Obligation-to-control mapping with jurisdictional delta register
    • Data residency, breach notification and reporting workflow design
  9. 09

    Privacy Engineering & Data Protection Programme

    On-PremCloudHybridAdviseBuildRun

    Privacy obligations designed into systems and pipelines rather than retrofitted at assessment time.

    • Data inventory, processing records and transfer mapping
    • Privacy impact assessment method and design-review gates
    • Consent, rights-request, minimisation and retention automation
  10. 10

    Third-Party & Supply Chain Risk Management

    On-PremCloudHybridAdviseRun

    A vendor assurance programme that scales past a questionnaire spreadsheet and tracks obligations after signature.

    • Criticality tiering model and proportionate due-diligence packs
    • Contractual security schedules, processing terms and right-to-audit clauses
    • Continuous external monitoring with re-assessment and offboarding triggers
  11. 11

    Cyber Resilience, Continuity & Recovery Programme

    On-PremCloudHybridAdviseBuild

    Recovery objectives that have been measured under adversarial conditions rather than asserted in a plan.

    • Business impact analysis with RTO and RPO per business service
    • Continuity, crisis-management and recovery playbooks
    • Tabletop, walkthrough, simulation and full-cutover exercise programme
  12. 12

    Human Risk Management

    On-PremCloudHybridRun

    Behaviour measured in report rates and dwell time, not in training-completion percentages.

    • Role and risk-based curriculum with adaptive targeting
    • Simulation programme spanning phishing, voice, callback and AI-generated lures
    • Per-team human risk scoring and intervention workflow
  13. 13

    Virtual CISO & Security Leadership

    On-PremCloudHybridRun

    Senior security ownership on a fraction of a head, accountable inside your governance forums.

    • Programme ownership, board and committee reporting
    • Budget, architecture-authority and vendor management
    • Incident escalation cover and regulator or customer engagement

Technical deep dive

Turning an annual audit scramble into continuous control assurance

Applies to any multi-entity group carrying several attestations at once - a management-system certification, a service-organisation report, a payment-card assessment and one or more privacy regimes.

What this is

A control assurance pipeline. Every control in a single internal library is bound to a machine-readable test and a system of record that can prove it. Tests run on a schedule, results are stored immutably, and the framework-specific views are generated from that one store rather than assembled by hand for each auditor.

The problem being solved

The group holds four attestations across three regions. Each has its own control list, its own evidence request, its own sampling window and its own auditor. Roughly seventy per cent of the underlying controls are the same control described in four different vocabularies - and each one is evidenced four times, manually, by the same three engineers. Fieldwork consumes six weeks per cycle, the evidence is a point-in-time screenshot with no assurance about the days either side, and a control that silently fails in month four is only discovered in month eleven.

Why it is hard

  • Evidence is pulled by humans from consoles, so it proves the state at the moment of capture and nothing about the period under review.
  • Framework vocabularies do not line up one-to-one: one framework's single control maps to five in another, and a partial mapping is worse than none if it is not tracked.
  • Controls fail silently. Nothing alerts when an S3-style bucket policy drifts, an access review is skipped, or a leaver stays enabled - the control simply stops working.

Reference architecture - step through it

all
SYSTEMS OF RECORDCOLLECTIONCONTROL PLANECONSUMERSHRIS + Identity providerjoiners, movers, leaversCloud control planesconfig, IAM, logging stateSIEM, EDR, scannerscoverage and finding stateITSM + CMDB + VCSchange, approval, code reviewEvidence collectorsscheduled API pulls, signedControl test harnessassert → pass / fail / no-dataUnified control libraryone control, many mappingsImmutable evidence storehash-chained, time-stampedCrosswalk enginecontrol → framework clausesException registerowner, expiry, compensatingcontrolFramework viewsgenerated per attestationAuditor workspaceread-only, period-scopedBoard & risk reportingtrend, not snapshotControl-failure alertingrouted to owning teamdefineson failremediation ticket
A control expressed once, asserted continuously, mapped outwardyaml
control:
  id: GG-AC-014
  statement: >
    Privileged access to production is time-bound; no standing
    administrative role assignment persists beyond 8 hours.
  owner: platform-security
  systems_of_record: [identity_provider, cloud_org_a, cloud_org_b]

  test:
    schedule: "*/30 * * * *"          # every 30 minutes
    assert: |
      count(
        role_assignments
        where scope startswith "/prod"
          and type == "permanent"
          and role in PRIVILEGED_ROLES
      ) == 0
    on_fail:
      severity: high
      route: platform-security@queue
      evidence: [assignment_id, principal, role, created_at]

  mappings:                            # one control, four vocabularies
    - {framework: iso_27001_2022, clause: "A.5.18", coverage: full}
    - {framework: soc2, criteria: "CC6.1",  coverage: partial,
       note: "paired with GG-AC-015 for periodic review"}
    - {framework: pci_dss_4,     req: "7.2.2",    coverage: full}
    - {framework: nist_csf_2,    subcat: "PR.AA-05", coverage: full}

Measured change

MeasureBeforeAfter
Evidence cycle per attestation6 weeks of engineer time2 days of review
Control verdicts per year1 point-in-time sample17,520 continuous assertions
Mean time to detect control failureup to 11 monthsunder 1 hour
Controls evidenced more than once70% duplicated 4×0% - single library, four views

The control set barely changed. What changed is that it now proves itself continuously, in a vocabulary each auditor recognises, without four teams doing the same work four times.

Talk to a security governance, risk & compliance specialist.

Schedule a free consultation and our team will connect within 12 hours to understand your environment and map out the right approach.

We respond within 12 hours