Offensive Security
Red Team Operations AI Red Teaming OT & IoT Red Teaming Adversary Emulation
AI Automation
AI Automation for Business
Consulting
Advisory & Consulting
Company
Intel About Request a briefing
Line 03 — Consulting

Advice from people who still do the work.

Security programme design, AI adoption strategy, and compliance readiness — delivered by the same people who run the operations and build the systems. No pyramid of junior consultants, no deck that dies in a drawer.

who you actually get
Engagement lead

A practitioner with fifteen-plus years running security programmes or shipping production systems. They attend the working sessions, write the recommendations, and present to your board.


Supporting specialists

Drawn from our offensive and engineering teams as the work requires — the people who will tell you whether a control holds or a plan is buildable, because they do that work every week.


Who you don't get

A rotating bench of graduates learning your business on your budget. We staff small and senior, and we say no to work we can't cover properly.

01
How we advise

Four things we hold to.

Consulting has a reputation problem, most of it earned. These are the commitments we make at the start of every engagement, and you can hold us to them.

i

We tell you what not to buy

A recommendation is only credible if it can come back negative. We routinely advise clients against tooling they'd already budgeted for, against certifications their customers don't actually require, and against automating processes that should be retired instead.

ii

Recommendations come with a build path

Anything we recommend, we can cost and sequence. Where it needs building, we'll tell you what it takes in engineer-weeks — whether or not we're the ones doing it. Advice that can't be executed isn't advice.

iii

Evidence over frameworks

Maturity models are a way of describing findings, not of producing them. Our assessments are grounded in what we observe in your environment — configurations, logs, ticket histories, and conversations with the people doing the work.

iv

No manufactured dependency

The objective is a client who needs us less each year. Deliverables are written so your team can run them without us, and we'll say plainly when a retainer has stopped earning its fee.

02
Practice areas

Three practices.

Most clients engage one. Organisations adopting AI under regulatory pressure usually end up needing all three, and they work better bought together than separately.

01 — Security Advisory

Senior security judgement, without the full-time hire.

For organisations that have outgrown ad-hoc security but can't yet justify a permanent CISO — or that have one and need independent challenge.

001Fractional CISO

Named senior cover on a defined day-rate: risk ownership, vendor and insurer conversations, incident escalation, and the board reporting that comes with the role.

002Security programme design

A costed, sequenced roadmap built from where you actually are — what to fix this quarter, what to defer, and what to stop paying for.

003Architecture & control review

Identity, network segmentation, cloud posture and data flows reviewed against a real threat model for your sector, with findings validated by offensive testing where it matters.

004Incident readiness

Response plans, tabletop exercises with your executive team, and the uncomfortable questions — who declares an incident, who calls the regulator, who talks to the press.

005Board & investor reporting

Security posture translated into the language of risk, cost and obligation, for directors who need to make decisions rather than admire heat maps.

02 — AI Strategy & Readiness

Where AI pays, where it doesn't, and what has to be true first.

An honest opportunity map for organisations under pressure to "do something with AI" and wary of spending a year proving the obvious.

006Opportunity mapping

Your processes ranked by automation return — volume, handling time, error cost and feasibility — so investment goes where the arithmetic already works.

007Readiness assessment

An unsentimental look at data quality, system access, and organisational appetite. Usually the finding is that the data work must come first.

008Build, buy or wait

Per use case: what the vendor market actually delivers today, what building costs in engineer-weeks, and where waiting two quarters is the better trade.

009AI governance

Acceptable-use policy, model and vendor approval, human-oversight requirements, incident handling, and an inventory that survives an auditor asking what you're running.

010Cost & run modelling

Inference, integration, monitoring and the maintenance nobody budgets for — modelled at your projected volume, not at demo scale. See AI automation for delivery.

03 — Compliance & Assurance

Controls that work, then the certificate.

Readiness work built around controls that genuinely function, rather than evidence assembled the week before the audit — because the second approach fails the moment something real happens.

011SOC 2 & ISO 27001 readiness

Gap analysis, control design, policy authoring and evidence automation, through to auditor selection and support during fieldwork.

012DORA & NIS2

Operational resilience, third-party risk registers, and incident reporting obligations for financial services and critical infrastructure in scope.

013EU AI Act readiness

System classification, risk-tier obligations, technical documentation and transparency requirements — mapped against what you're actually deploying.

014Third-party & supply chain

Vendor due-diligence programmes, security questionnaire handling, and contractual security terms that mean something when tested.

015Evidence & audit support

Continuous control monitoring so evidence accumulates as a by-product of operating, not as an annual fire drill.

03
Engagement models

Three ways to engage.

Scope and cost are set in a scoping conversation, and we quote fixed fees wherever the scope allows it.

Assessment
Custom quote
Fixed fee · 2–4 weeks
  • Current-state review against a real threat model
  • Interviews with the teams doing the work
  • Prioritised findings with costed remediation
  • Board-ready summary and working session
  • Fee credited against a subsequent retainer
Start here
Fractional CISO
Custom quote
Retainer · 6 months minimum
  • Named senior lead, 4–6 days per month
  • Risk ownership and programme governance
  • Board and audit-committee reporting
  • Vendor, insurer and customer security reviews
  • Incident escalation path with defined response times
  • Discounted rates on offensive engagements
Most common
Programme
Custom quote
Scoped programme · 3–9 months
  • Certification readiness through to audit
  • AI governance framework and rollout
  • Hands-on control implementation, not just design
  • Hands-on delivery support, not just design
  • Knowledge transfer so your team can run it
Discuss a programme
04
Common questions

Before you get in touch.

Isn't it a conflict for you to advise on security and also sell testing?

It would be if we hid it, so we don't. Advisory engagements state plainly where we could later be a supplier, and we're comfortable recommending competitors — we do it regularly for specialist work outside our strengths. If you'd prefer hard separation, we'll contract the advisory work with an explicit exclusion from bidding on what it recommends.

We already have a CISO. What would you add?

Independent challenge, usually. A good CISO is often the person who most wants an outside read on their own programme — something to take to the board that isn't self-assessed. We're also frequently brought in for surge capacity around certification, funding rounds or acquisitions.

How fast can you get us to SOC 2 or ISO 27001?

Realistically six to nine months to a first certificate if you're starting from close to nothing, three to four if your controls are largely in place and the gap is documentation. Anyone promising a compliant certificate in six weeks is selling you evidence rather than controls, and it tends to unravel at the first customer security review.

Do you actually implement, or just recommend?

Both, and we prefer both. We can implement what the advisory work identifies — control tooling, integrations, automation — which is a large part of why our recommendations tend to be buildable. You're never obliged to use us for delivery.

Does the EU AI Act apply to us?

Possibly, even if you're outside the EU — placement on the EU market and effects on EU persons both matter, and obligations vary sharply by risk tier. Classification is usually the first thing we do, because a surprising number of internal tools land in a lower tier than clients fear and a few land higher than they hoped.

What size of organisation do you work with?

Typically 50 to 5,000 people: past the point where security is somebody's side project, short of a mature in-house function. Below that we'll usually point you at a lighter-touch option rather than take the fee.

Bring us the awkward question.

The decision you can't get a straight answer on, the certification you're not sure you need, the AI project you suspect isn't worth it. That's the conversation we're useful in.