Cybersecurity
Hold the walls, and know where they are thin.
- Governance, risk and strategy
- Audit and offensive security
- Architecture and protection
- Detection, response and continuity
- Cloud and AI security
Learn more — Cybersecurity
Four practices, held by one team.

Services
A regulation lands on a compliance officer, is implemented by an engineer, and is audited against evidence a platform has to produce. Split that across three firms and the gaps become your problem. We keep it in one place.
Below are the four practices. Each page lists what we do, what you receive, and how long it typically takes. Durations are working days for the consultant, based on engagements of comparable scope, and are confirmed in the proposal.
Most of this catalogue is also available at a fixed price inside a pack, or continuously through a recurring service.
Hold the walls, and know where they are thin.
Learn more — Cybersecurity
Prove it once. Use the proof everywhere.
Learn more — Compliance & Regulatory
Security that ships with the code, not after it.
Learn more — Cloud & DevSecOps
Deploy it because it works, and because you can defend it.
Learn more — AI Transformation
The engagements we are asked for most often sit across two practices at once.
A control framework is only cheap to maintain if the evidence collects itself. We map the controls, then implement them as automated checks in your pipeline.
DORA wants a tested exit plan. The AI Act wants logging. Sovereignty questions want a data residency map. All three are architecture decisions before they are documents.
An assistant connected to your file server inherits every permission mistake you ever made. The roll-out project and the security project are the same project.
That is a normal place to start. Describe the deadline or the question you are facing and we will tell you what it actually involves.