Cybersecurity
Known exposure closed, remaining risk documented and accepted by name, and a tested plan for the incident that still happens.
Security assessment, hardening, monitoring and incident response, delivered against the ISO/IEC 27001 control set we run ourselves.
What this service is usually brought in to fix
A test report with no remediation plan
Findings are delivered as a list of severities with no owner, no sequence and no retest, so the same findings reappear next year.
Detection without response
Alerts fire into a mailbox nobody monitors out of hours, and the first real indicator of compromise is a user complaint.
Policy that does not match operation
A written information security policy exists for the auditor, while actual practice on access, patching and offboarding differs.
What the service covers
- Vulnerability assessment and penetration testing
- Security architecture review and hardening
- ISO/IEC 27001 gap assessment and readiness support
- Identity, access and privileged account management
- Log aggregation, monitoring and alerting
- Incident response planning, tabletop exercises and awareness training
What you receive
- Assessment report with findings ranked by exploitability and impact
- Prioritised remediation plan with owners and target dates
- Retest report confirming closure
- Hardening baselines and configuration standards
- Incident response plan with contact and escalation matrix
How the work runs
Each stage produces something reviewable, so scope, risk and progress stay visible to your team throughout.
Assess
Test the estate against its real exposure — external, internal, application and configuration — with the scope agreed in writing.
Prioritise
Rank findings by exploitability and business impact, not scanner severity alone, and assign an owner to each.
Remediate
Fix, harden and verify. Risks that will not be remediated are documented and formally accepted by a named person.
Sustain
Establish monitoring, patch cadence, access review and an incident plan that has been rehearsed rather than only written.
Where we apply it
- Government and public sector systems
- Financial institutions
- Healthcare and patient data environments
- Critical infrastructure operators
The controls that apply
- Testing is performed only under written authorisation and an agreed scope and window.
- Findings are handled as confidential and delivered through an agreed secure channel.
- Our own operations run under an ISO/IEC 27001:2022 aligned control set.
Frequently asked
If your question is not here, ask it directly — we would rather answer it before a proposal than after a contract.
Ask a questionAn agreed scope of external, internal, application or wireless testing; a report ranking each finding by exploitability and impact with reproduction steps; a prioritised remediation plan; and a retest to confirm closure.
What this is usually combined with
Discuss your Cybersecurity requirement
Tell us the outcome you need and the constraints you are working within. We will respond with a scoped approach and the documentation your evaluation process requires.
