Diagnostics & Reviews

Start with a defined first step.

Not sure it is worth a full programme yet? Each of the seven is a bounded engagement you can commission on its own: fixed scope, defined outputs, senior delivery, and a result you can take to a decision.

Cybersecurity Governance and Board Advisory

Explore the line
Fixed scope

Board Cyber Governance Review

An assessment of how your board oversees cyber risk today, and what would need to change for that oversight to satisfy directors, auditors, and regulators.

What you receive
  • Governance assessment against regulatory expectations
  • Review of board reporting and the decisions it actually supports
  • Accountability map showing who owns which cyber risks
  • Prioritised, practical recommendations
  • A facilitated board workshop on the findings
Request a governance review
Facilitated exercise

Cyber Resilience Executive Exercise

A scenario built around your critical services, run with the executives who would own the real decisions. It tests how they decide, escalate, and communicate under pressure.

What you receive
  • A tailored scenario grounded in your organisation and sector
  • A facilitated exercise with the executive team
  • Observations on decision-making, escalation, and communication
  • An improvement plan the management body can act on
Discuss an exercise

Regulatory Cyber Resilience

Explore the line
5-day engagement

NIS2 Readiness Diagnostic

Establishes your scope, governance readiness, control maturity, incident notification capability, and supply chain exposure before any programme investment is made.

What you receive
  • Provisional scope statement by entity, sector, and jurisdiction
  • Governance readiness assessment against the management body's obligations
  • Maturity map across all ten security obligation areas
  • Incident notification capability assessment against the regulatory timelines
  • Supply chain exposure map for material supplier relationships
  • Programme readiness brief written for the management body
Request a diagnostic
Fixed scope

Critical Supplier Cyber Risk Review

Establishes which of your supplier relationships carry material cyber risk, where the concentration sits, and what the contracts and due diligence need to change.

What you receive
  • Supplier criticality and dependency view
  • Concentration risk assessment
  • Due diligence findings for priority suppliers
  • Control and contract recommendations
Request a supplier review

Cyber Risk and Security Assurance

Explore the line
Fixed scope

Cyber Risk Decision Review

An independent risk opinion on one system, cloud service, or architecture. For decisions that need evidence behind them: approvals, exceptions, go-lives, and material changes.

What you receive
  • Findings against business criticality, threats, and existing controls
  • The residual risk position, stated plainly
  • Conditions for approval where the decision can proceed
  • Risk acceptance considerations for the decision owner
Request a decision review

Zero Trust Strategy and Transformation

Explore the line
Fixed scope

Zero Trust Discovery and Roadmap

Establishes where you stand, which use cases justify investment, and what a realistic transformation sequence looks like, before any programme commitment is made.

What you receive
  • Maturity assessment across identity, devices, networks, applications, workloads, data, monitoring, automation, and governance
  • Priority use cases grounded in business risk
  • Target capability model and operating model implications
  • A phased roadmap with investment priorities
Request a discovery

Cloud and Digital Security Governance

Explore the line
Fixed scope

Cloud Security Governance Review

Establishes whether your cloud security governance actually operates: who owns what, which policies are followed, where exceptions accumulate, and what needs fixing first.

What you receive
  • Governance maturity assessment
  • Review of policies, ownership, and exception handling
  • Workload onboarding and assurance gate findings
  • Prioritised remediation plan
Request a governance review

We use analytics cookies to understand how this site is used. See our Privacy Notice for details. You can change your choice at any time.