Advice from people who still do the work.
Security programme design, AI adoption strategy, and compliance readiness — delivered by the same people who run the operations and build the systems. No pyramid of junior consultants, no deck that dies in a drawer.
A practitioner with fifteen-plus years running security programmes or shipping production systems. They attend the working sessions, write the recommendations, and present to your board.
Drawn from our offensive and engineering teams as the work requires — the people who will tell you whether a control holds or a plan is buildable, because they do that work every week.
A rotating bench of graduates learning your business on your budget. We staff small and senior, and we say no to work we can't cover properly.
Four things we hold to.
Consulting has a reputation problem, most of it earned. These are the commitments we make at the start of every engagement, and you can hold us to them.
We tell you what not to buy
A recommendation is only credible if it can come back negative. We routinely advise clients against tooling they'd already budgeted for, against certifications their customers don't actually require, and against automating processes that should be retired instead.
Recommendations come with a build path
Anything we recommend, we can cost and sequence. Where it needs building, we'll tell you what it takes in engineer-weeks — whether or not we're the ones doing it. Advice that can't be executed isn't advice.
Evidence over frameworks
Maturity models are a way of describing findings, not of producing them. Our assessments are grounded in what we observe in your environment — configurations, logs, ticket histories, and conversations with the people doing the work.
No manufactured dependency
The objective is a client who needs us less each year. Deliverables are written so your team can run them without us, and we'll say plainly when a retainer has stopped earning its fee.
Three practices.
Most clients engage one. Organisations adopting AI under regulatory pressure usually end up needing all three, and they work better bought together than separately.
Senior security judgement, without the full-time hire.
For organisations that have outgrown ad-hoc security but can't yet justify a permanent CISO — or that have one and need independent challenge.
001Fractional CISO
Named senior cover on a defined day-rate: risk ownership, vendor and insurer conversations, incident escalation, and the board reporting that comes with the role.
002Security programme design
A costed, sequenced roadmap built from where you actually are — what to fix this quarter, what to defer, and what to stop paying for.
003Architecture & control review
Identity, network segmentation, cloud posture and data flows reviewed against a real threat model for your sector, with findings validated by offensive testing where it matters.
004Incident readiness
Response plans, tabletop exercises with your executive team, and the uncomfortable questions — who declares an incident, who calls the regulator, who talks to the press.
005Board & investor reporting
Security posture translated into the language of risk, cost and obligation, for directors who need to make decisions rather than admire heat maps.
Where AI pays, where it doesn't, and what has to be true first.
An honest opportunity map for organisations under pressure to "do something with AI" and wary of spending a year proving the obvious.
006Opportunity mapping
Your processes ranked by automation return — volume, handling time, error cost and feasibility — so investment goes where the arithmetic already works.
007Readiness assessment
An unsentimental look at data quality, system access, and organisational appetite. Usually the finding is that the data work must come first.
008Build, buy or wait
Per use case: what the vendor market actually delivers today, what building costs in engineer-weeks, and where waiting two quarters is the better trade.
009AI governance
Acceptable-use policy, model and vendor approval, human-oversight requirements, incident handling, and an inventory that survives an auditor asking what you're running.
010Cost & run modelling
Inference, integration, monitoring and the maintenance nobody budgets for — modelled at your projected volume, not at demo scale. See AI automation for delivery.
Controls that work, then the certificate.
Readiness work built around controls that genuinely function, rather than evidence assembled the week before the audit — because the second approach fails the moment something real happens.
011SOC 2 & ISO 27001 readiness
Gap analysis, control design, policy authoring and evidence automation, through to auditor selection and support during fieldwork.
012DORA & NIS2
Operational resilience, third-party risk registers, and incident reporting obligations for financial services and critical infrastructure in scope.
013EU AI Act readiness
System classification, risk-tier obligations, technical documentation and transparency requirements — mapped against what you're actually deploying.
014Third-party & supply chain
Vendor due-diligence programmes, security questionnaire handling, and contractual security terms that mean something when tested.
015Evidence & audit support
Continuous control monitoring so evidence accumulates as a by-product of operating, not as an annual fire drill.
Three ways to engage.
Scope and cost are set in a scoping conversation, and we quote fixed fees wherever the scope allows it.
- Current-state review against a real threat model
- Interviews with the teams doing the work
- Prioritised findings with costed remediation
- Board-ready summary and working session
- Fee credited against a subsequent retainer
- Named senior lead, 4–6 days per month
- Risk ownership and programme governance
- Board and audit-committee reporting
- Vendor, insurer and customer security reviews
- Incident escalation path with defined response times
- Discounted rates on offensive engagements
- Certification readiness through to audit
- AI governance framework and rollout
- Hands-on control implementation, not just design
- Hands-on delivery support, not just design
- Knowledge transfer so your team can run it
Before you get in touch.
Isn't it a conflict for you to advise on security and also sell testing?
It would be if we hid it, so we don't. Advisory engagements state plainly where we could later be a supplier, and we're comfortable recommending competitors — we do it regularly for specialist work outside our strengths. If you'd prefer hard separation, we'll contract the advisory work with an explicit exclusion from bidding on what it recommends.
We already have a CISO. What would you add?
Independent challenge, usually. A good CISO is often the person who most wants an outside read on their own programme — something to take to the board that isn't self-assessed. We're also frequently brought in for surge capacity around certification, funding rounds or acquisitions.
How fast can you get us to SOC 2 or ISO 27001?
Realistically six to nine months to a first certificate if you're starting from close to nothing, three to four if your controls are largely in place and the gap is documentation. Anyone promising a compliant certificate in six weeks is selling you evidence rather than controls, and it tends to unravel at the first customer security review.
Do you actually implement, or just recommend?
Both, and we prefer both. We can implement what the advisory work identifies — control tooling, integrations, automation — which is a large part of why our recommendations tend to be buildable. You're never obliged to use us for delivery.
Does the EU AI Act apply to us?
Possibly, even if you're outside the EU — placement on the EU market and effects on EU persons both matter, and obligations vary sharply by risk tier. Classification is usually the first thing we do, because a surprising number of internal tools land in a lower tier than clients fear and a few land higher than they hoped.
What size of organisation do you work with?
Typically 50 to 5,000 people: past the point where security is somebody's side project, short of a mature in-house function. Below that we'll usually point you at a lighter-touch option rather than take the fee.
Bring us the awkward question.
The decision you can't get a straight answer on, the certification you're not sure you need, the AI project you suspect isn't worth it. That's the conversation we're useful in.