Services
Each service below can run as a standalone engagement or as part of a broader programme. All of them are staffed by the same senior consultants — so a finding from an audit, an architecture review or a compliance gap assessment doesn't get lost between teams.
We help essential and important entities under NIS2, and financial entities and their critical ICT third parties under DORA, move from legal text to operating reality.
We work alongside your legal counsel rather than replacing it. Our focus is translating each obligation into technical controls, evidence and processes your team can actually run day to day — not a compliance binder that sits on a shelf.
Whether you're pursuing certification for the first time or maintaining an existing ISMS, we support the full lifecycle from scoping through to the certification audit.
We work with the certification body of your choice and prepare your team to answer auditor questions with real, working evidence — not paperwork assembled the week before the audit.
We conduct independent audits of IT general controls, access management, change management, backup and recovery, and vendor oversight — sized to what your organisation actually needs.
That might be a pre-certification readiness check, a due-diligence audit ahead of an investment or acquisition, or a recurring internal audit function you don't have the headcount to run yourselves.
We assess your network, identity, endpoint and cloud architecture against the CIS Critical Security Controls, mapped to the Implementation Group that fits your organisation's size and risk exposure.
The output is a concrete architecture roadmap — what to change, in what order, and why — connecting technical decisions back to the control objectives your compliance obligations require.
Tell us what's prompting the engagement and we'll recommend a starting point — no obligation.
Talk to us