Cyber risk, governance and resilience for critical digital services.
We help regulated and security-critical organisations make defensible risk decisions, strengthen cyber governance, and turn security strategy into practical change.
What are you trying to change?
Most of this work comes down to one of three needs, and each engagement is built to deliver the one that is yours.
Govern cyber risk
Decision rights, accountability, and board oversight that make cyber risk a governed business risk. Reporting that tells your board what it needs to decide.
Protect critical services
Independent assessment of the systems, cloud services, and suppliers your critical services depend on, and the architecture and segmentation work that reduces what an attacker can reach.
Demonstrate resilience
The governance, controls, and evidence that NIS2, DORA, the Cyber Resilience Act, and the UK's Cyber Security and Resilience Bill demand, built to hold up under supervisory scrutiny.
Six areas we work in.
Each starts from a decision or obligation you are facing and ends in something you can act on.
Cyber Risk and Security Assurance
Independent risk assessments, security opinions, and architecture assurance that end in a decision, either to proceed, to proceed with conditions, or not to proceed.
ExploreCybersecurity Governance and Board Advisory
Governance frameworks, board reviews, executive exercises, and reporting for management bodies now personally accountable for cyber risk.
ExploreZero Trust Strategy and Transformation
Maturity assessment, strategy and roadmap, architecture, and programme governance that turn Zero Trust principles into changed access behaviour.
ExploreRegulatory Cyber Resilience
NIS2, DORA, the Cyber Resilience Act, and the UK's Cyber Security and Resilience Bill translated into one control framework, one body of evidence, and one operating model.
ExploreCloud and Digital Security Governance
Cloud security governance, secure adoption, and DevSecOps governance that keep pace with delivery.
ExploreAI Governance and Transformation
A secure foundation, delivery process, operations, and governance for scaling AI use safely, independent of model or cloud provider.
ExploreThe sectors we work in.
Each sector brings its own regulation, dependencies, and consequences when something goes wrong.
Financial services
Keep critical services running, and prove it to supervisors.
Central banking
Protect the systems the financial system relies on.
Energy and utilities
Protect the systems that keep power and water flowing.
Healthcare
Keep patient services running and patient data protected.
Public sector
Protect the services citizens cannot get anywhere else.
Supply chain and logistics
Keep goods moving through a cyber incident.
Aerospace and manufacturing
Protect production and the intellectual property behind it.
Media and publishing
Keep every title, station, and platform running.
Technology and SaaS
Give customers evidence that your platform is resilient.
UK public sector buyers can commission us through the G-Cloud 15 and Digital Outcomes and Specialists 7 frameworks. How to buy
Start with a defined engagement.
Each of the fourteen is a bounded engagement you can commission on its own, with defined scope, defined outputs, and senior delivery.
Establish your position
Reviews and diagnostics that give you an evidenced position before any programme commitment.
Cyber Risk Decision Review
An independent risk opinion on one system, cloud service, or architecture, with conditions for approval and the residual risk stated plainly.
View engagementBoard Cyber Governance Review
How your board oversees cyber risk today, and what would need to change to satisfy directors and regulators, closing with a facilitated board workshop.
View engagementCyber Resilience Executive Exercise
Executives rehearse the decisions a real incident would force, against a scenario built on your critical services, ending in an improvement plan.
View engagementNIS2 Readiness Diagnostic
Five days, six defined outputs. Scope, gap, and governance readiness before any programme investment, with a readiness brief for the management body.
View engagementCritical Supplier Cyber Risk Review
Which supplier relationships carry material cyber risk, where concentration sits, and what the contracts and due diligence need to change.
View engagementCloud Security Governance Review
Whether cloud security governance operates in practice, covering ownership, policies, and exceptions, and what needs fixing first.
View engagementZero Trust Discovery and Roadmap
Maturity, priority use cases grounded in business risk, and a phased roadmap with investment priorities, before any technology commitment.
View engagementAI Readiness and Governance Review
Where AI use already exists across your organisation, including use nobody formally approved, what it is missing, and what to build first.
View engagementDesign and deliver the change
Engagements that design the capability you need, with phased engagements leading its delivery alongside your teams.
Cyber Risk Framework Design
A cyber risk management framework aligned with your enterprise risk framework, so cyber risk is assessed and reported on the same basis as other material risks.
View engagementCyber Governance Framework Design
A cyber governance framework that sets decision rights, accountability, and board oversight, aligned with management body obligations.
View engagementNIS2 Programme Design and Delivery
A funded NIS2 programme designed from your diagnostic findings and delivered in agreed phases, with evidence for supervisory review.
View engagementCloud Landing Zone Design
A governed cloud foundation designed around your organisation, with a staged plan to bring your estate onto it without disrupting live services.
View engagementZero Trust Transformation
A phased transformation led by independent architects and programme governors, starting with a pilot on a high-priority service, each phase agreed in advance.
View engagementAI Factory Design
An AI factory designed around your priorities, with a phased transformation plan, named owners, and investment decision points.
View engagementWhy clients keep us in the room.
One team across three jurisdictions
Offices in London, Warsaw, and Berlin, and one engagement team that covers the UK's Cyber Security and Resilience Bill and NIS2 as it is transposed across the EU Member States where you operate. You do not coordinate separate national advisers.
The people who scope it deliver it
The people who design the engagement deliver it. Where we bring in associates, they are senior practitioners we have worked with over many years. Senior involvement runs from the first review through to programme close.
A method you can hold us to
Our regulatory and risk work follows a documented methodology, establishing position first, delivering against evidence, and handing over to a named owner who sustains the outcome.
