Advisory
Engagements, not engagements-of-record.
An engagement is scoped work with a named outcome: stand up the governance, run the risk assessment, get the evidence audit-ready. The program is then handed to the team that has to run it.
Fixed-scope engagements · Advisory retainers · Workshops
01 — The framework
One model, three fields of work.
Every engagement traces back to one model. Assets need protection; protection is ensured through governance and demonstrated through compliance, and both exist to manage risk. Select a field to read the work it holds.
02 — Governance
Ensure protection through governance.
Governance is what makes security decisions on purpose rather than by accident: policy, roles, and the authority to enforce them. It sets what good means for an organisation and who answers for it when the answer slips.
Capabilities
- ISMS design and build-out to ISO/IEC 27001
- Policy and standards architecture — a coherent set, not a binder nobody reads
- Roles, responsibilities and decision rights, with named control owners
- Security strategy and control objectives tied to the business
- Management review, metrics and a reporting cadence that holds
- Accountability that survives the next reorganisation
Typical deliverables
- ISMS charter and policy set
- Decision-rights and ownership map
- Security strategy on a page
- Management-review pack
Good fit when controls exist but nobody can say who owns them, or why.
03 — Risk
Know the risk before you treat it.
Risk work is where governance and compliance earn their keep: identify what can go wrong, decide what to do about it, and record the reasoning. That means a register a team maintains, and for connected products it also means threat analysis and risk assessment.
Capabilities
- Risk assessment and treatment to ISO/IEC 27005
- Third-party and supplier risk, from due diligence to monitoring
- Asset and impact analysis that ties risk back to the business
- Risk acceptance, treatment plans and residual-risk tracking
- A register the organisation's own team can maintain afterwards
- Threat analysis and risk assessment for connected products
Typical deliverables
- Risk register and treatment plan
- Supplier risk assessment framework
- Residual-risk report for sign-off
- Threat-modelling workshop series
Good fit when a defensible risk picture is owed to a regulator, a customer, or a board.
04 — Compliance
Demonstrate protection through compliance.
Compliance is how an organisation proves to an auditor, a customer or an authority that the controls it claims actually run. The work builds toward the certificate or the audit and leaves the evidence trail behind it.
Capabilities
- ISO/IEC 27001 certification readiness, end to end
- SOC 2 readiness for both report types, against the Trust Services Criteria
- NIS2 and IEC 62443 mapped to what authorities expect
- Statement of Applicability, control mapping and evidence design
- Audit dry-runs and remediation before the real assessment
- TISAX, R155 and ISO/SAE 21434 when in scope
Typical deliverables
- Statement of Applicability and evidence map
- Control-to-requirement mapping
- Audit dry-run report
- Readiness assessment and remediation plan
Good fit when an audit or certification date is on the calendar and the organisation intends to walk in ready.
05 — AI security governance
Govern AI systems on purpose.
AI moved from pilot to production faster than most governance did. This track puts a use case through triage, decides what the obligations are, and wires the controls into the delivery process instead of a policy nobody reads.
Capabilities
- EU AI Act readiness: role, risk tier and the obligations that follow
- AI use-case triage, with a register and a decision record per system
- AI-SSDLC governance — model, data and prompt changes under change control
- NIST AI RMF and ISO/IEC 42001 alignment for an existing management system
- Model and supplier evaluation, including hosted and third-party models
- Monitoring, incident handling and human oversight that is written down
Typical deliverables
- AI use-case register and triage criteria
- Role and risk-tier determination per system
- AI management-system gap analysis and roadmap
- Oversight, evaluation and incident procedures
Good fit when AI systems are already in production and the governance is still a slide.
06 — Product & OT security
When the product itself is in scope.
Connected products, vehicles and plant carry their own regimes. The work is the same discipline applied to engineering: a management system the type-approval or conformity route can be assessed against, and evidence produced by the development process rather than after it.
Capabilities
- R155 and R156 management systems for vehicle type approval, when in scope
- ISO/SAE 21434 engineering process, work products and assessment readiness
- IEC 62443 for industrial automation and control environments
- Cyber Resilience Act readiness for products with digital elements
- Machinery Regulation and CE conformity where cybersecurity is in the route
- Supplier interface agreements and the evidence they have to produce
Typical deliverables
- Management-system description and process map
- Threat analysis and risk assessment work products
- Conformity or type-approval evidence pack
- Supplier requirement and interface set
Good fit when a product regime is in scope and engineering, not only IT, has to carry the evidence.
07 — How we work
Assess, design, implement, operate.
Assess
Understand the business, the obligations, and what already exists. No two programs start from the same baseline.
Design
Shape controls and governance around how the organisation actually works — proportionate to the risk, not maximal.
Implement
Do the work alongside the team: policies written, risks assessed, evidence built as it goes.
Operate
Run it long enough to prove it holds, then hand it over — owned by the organisation's own people.