Advisory

Where we’re brought in.

A focused practice, for organisations where the stakes are real: a matter of judgement, not process.

What we do

The way in

The Risk Profile Assessment

A senior, independent read on where your security, data and regulatory risk concentrates, what order to take it in, and how your posture compares to the stakes you carry. Fixed scope, a fixed fee stated before we begin. The considered beginning of a relationship.

For those who own the risk

Independent assurance

For those who own the risk (a board, an audit committee, a chief executive, or the person who carries it directly): an independent view of what risk is genuinely understood and controlled. A position the accountable owner can defend, designed to back the in-house team rather than sit over it.

ISO 27001 · ISO 42001 · SOC 2 · Cyber Essentials · NIST

Programme & ISMS oversight

Where a programme has to be built or turned around, to ISO 27001, ISO 42001, SOC 2, Cyber Essentials, NIST or whichever standard applies, we own its direction and lead the people delivering it, and where there is no team to lead, we are the people delivering it, alongside your management. Senior ownership of the outcome, not a rented function.

Incident · finding · transaction

Situations

The high-stakes moment (an incident, a regulatory finding, a transaction under diligence) where a credible answer is needed quickly, from someone who has been in the chair. With it comes the preparation that makes that moment survivable: response plans that have been exercised, tabletop simulations with your leadership, reporting obligations mapped before the clock starts, and an honest post-incident review afterwards.

How we work

One

It begins with a conversation, not a pitch

The first conversation carries no charge and no assumption of commitment on either side, and it is not a sales meeting: you should leave it seeing your own position more clearly than when it began. The full diagnosis is the Risk Profile Assessment, fixed scope, a fixed fee stated before we begin, and any wider scope follows from what it finds, shaped to the situation rather than drawn from a menu.

Two

Senior ownership, not staff

We work as a senior extension of your leadership, owning the direction of the work rather than renting you a function. Where a programme must be built or turned around, we lead it, and the people delivering it; we do not simply add a pair of hands. Senior ownership of the outcome, named and continuous.

Three

Close over time

The most valuable position we can hold is the one you call early, before a question becomes a crisis. We are built for long relationships and low drama: retained year to year, brought in ahead of the problem, kept close by being useful, not by selling.

Four

Built to run without us

A management system is documented by design. What we build is yours, written down, and operable without us. We would rather be retained because the work keeps being useful than because you cannot run it if we leave.

Five

Where we draw the line

Knowing what we do not do is part of the service. We advise, assess, design and steer, and where needed we run the management system itself; we do not operate your security tooling or monitoring, conduct technical testing, or act as your lawyers. On questions of law we will say plainly when you need qualified legal advice, and help you frame the question for those who give it. The boundary is not a disclaimer; it is how you know our counsel is independent.

The right scope is a conversation, not a line item, and that conversation is the place to begin. There is no charge for it, and nothing follows from it unless you decide it should.

Contact us