Services
Ongoing and once-off cybersecurity services.
Most organisations don't call me because they've had a breach. They call because something isn't adding up — the reporting says one thing and the room knows another, or security has become a bottleneck nobody wants to own. Find the line below that sounds most like you.
We don't know what we need to do in cyber security.
→ Start with a Cybersecurity Risk & Maturity Assessment, which often leads into a vCISO engagement.
We need someone to translate between the board or executive and our technical staff.
Is there a risk or issue you already believe needs addressing?
No → Start with a Virtual CISO engagement.
Yes → Start with a Cybersecurity Risk & Maturity Assessment.
We don't know what our risk tolerance is.
→ A full Security Risk & Maturity Assessment.
→ An Incident Response Game run as a readiness test, with the stakeholders who actually make the decisions.
→ Board & Executive Risk Communication on your borderline risks, to make sure there's genuine alignment on them.
We know what we need, and we won't be surprised.
We need help setting up or practising for incidents.
We need help getting our technical teams to collaborate.
Not sure which line you're on? That's a normal place to start — the first conversation is usually about working out which problem you actually have.
Ongoing fractional security leadership, scaled to what you need: functional oversight — a second set of experienced eyes across strategy, risk and reporting; function leadership — running the security function outright while you grow or recruit; or staff coaching — developing the people you already have so they can do the job themselves.
Board and executive reporting, and risk oversight, come with all three.
An honest, evidence-based assessment of where you actually stand — covering reputational risk, compliance risk, and the impact security risk is having on your delivery and your strategy.
It can be scoped the way that's useful to you: to a customer, a system, a data set or a cohort, or run against a framework of your choice (ISO 27001, NIST CSF, Essential Eight, CPS 234). The assessment deliberately covers visibility and capability as well as controls — what you can't currently see, and what you couldn't act on even if you could.
Setting up incident response, or practising it. Game-based exercises that put your real decision-makers inside a realistic incident and make them make the calls, followed by a walkthrough of what the decisions revealed.
Run with the right stakeholders in the room, this is also the fastest way to find out what your risk tolerance genuinely is, rather than what your policy says it is.
Game-based threat modelling that gets engineering and security teams solving the same problem together. Engineers walk through their architecture, the room roleplays threat actors, and the group leaves with prioritised risks and actual decisions — not a report that sits unread.
Based on the open-source workshop I developed and have been running for years.
Translating cyber risk into terms your board and executive team can actually use to make decisions — board papers, briefings, and metrics that tell the truth. Particularly useful for borderline risks, where what you need is genuine alignment on whether to accept or act, not a number everyone quietly disagrees with.
Turning an assessment into a sequenced, fundable plan: what to do, in what order, with which people and what money — and what you're deliberately choosing not to do yet, stated out loud so nobody is surprised later.
Designing the security function itself — governance design, skills assessment, and operating model design. Structure, decision rights and ways of working, so the function can carry what you're asking of it. More on the organisational design and risk culture page.
Vendor risk reviews, and security due diligence for acquisitions — on either side of the table.
This goes beyond a questionnaire. A questionnaire tells you what a third party says about itself; the assessment covers the visibility risks you're taking on — what you will and won't be able to see once you depend on them.
Covering a security or technology leadership gap during a search, restructure, or transition.
This list is a starting point rather than a fixed menu — every engagement starts with a conversation about what you actually need.
Get in touch