Skip to content

Services

Cloud & DevSecOps

Security that ships with the code, and evidence that collects itself.

Security that ships with the code, not after it.

A security report that arrives after the platform is built describes a problem. A guardrail in the pipeline prevents one. The difference in cost is roughly two orders of magnitude, and it is the reason this practice exists inside a security firm rather than next to one.

We design landing zones as code in your repository, wire security testing into the pipelines your teams already use, and tune it until the output is trusted — because a scanner nobody reads is worse than no scanner at all. Then we make the same controls produce their own audit evidence, timestamped and exportable, which is what makes an ISO 27001 or SOC 2 certificate affordable to keep.

And we watch the bill. FinOps usually returns fifteen to thirty per cent of cloud spend, which tends to fund the rest of the work.

Cloud & DevSecOps

Cloud strategy and architecture

Decide what moves, where it lands, and what it will cost before the first migration.

  • Cloud strategy and opportunity studyTypical duration: 8–20 days

    Application-by-application analysis of what to retire, retain, rehost, replatform or rebuild, with the business case and the regulatory constraints in the same table.

    You receive

    • Application portfolio assessment
    • Migration strategy per application
    • Business case with total cost of ownership
    • Roadmap with sequencing and dependencies
  • Hyperscaler and sovereign cloud selectionTypical duration: 5–12 days

    A structured comparison of AWS, Azure, GCP, OVHcloud, Scaleway, S3NS and Bleu against your technical, contractual, sovereignty and exit requirements.

    You receive

    • Weighted requirement matrix
    • Provider comparison with evidence
    • Sovereignty and exit analysis
    • Recommendation and decision record
  • Well-Architected reviewTypical duration: 3–8 days

    A review of an existing workload against the provider's framework, covering operational excellence, security, reliability, performance, cost and sustainability.

    You receive

    • Review findings by pillar
    • High-risk issue list
    • Prioritised improvement plan
    • Effort and saving estimates
  • Data platform and governanceTypical duration: 10–25 days

    A data platform with ownership, quality and lineage defined from the start, and access controls that let analytics happen without opening the whole warehouse.

    You receive

    • Target data architecture
    • Data ownership and stewardship model
    • Access control and classification design
    • Quality and lineage approach

Foundation and migration

A landing zone built as code, then workloads moved onto it without a rebuild.

  • Secure landing zone with infrastructure as codeTypical duration: 10–25 days

    Account structure, network, identity, logging, encryption and guardrails delivered as code in your repository, so every new environment inherits the same baseline.

    You receive

    • Account and subscription topology
    • Network, identity and logging baseline
    • Terraform or Bicep modules in your repository
    • Guardrail policies and exception process
  • Migration programme managementTypical duration: Scoped per engagement

    Wave planning, runbooks, cutover rehearsals and rollback criteria, with the security and compliance checks built into each wave rather than added at the end.

    You receive

    • Wave plan and dependency map
    • Migration runbooks per workload
    • Cutover and rollback criteria
    • Programme reporting and risk log
  • Application modernisation and containersTypical duration: 20–60 days

    Containerisation and refactoring of applications where it pays, with base images, build pipelines and platform targets defined once and reused.

    You receive

    • Modernisation assessment per application
    • Reference container build and base images
    • Deployment manifests and pipelines
    • Developer documentation
  • Hybrid and multi-cloud networkingTypical duration: 10–25 days

    Connectivity between data centres, clouds and sites designed for segmentation and observability, not just for reachability.

    You receive

    • Target network architecture
    • Segmentation and routing design
    • Connectivity implementation plan
    • Network observability baseline

Governance, operations and cost

Who owns what, how it is monitored, and why the bill stopped growing.

  • Cloud governance and operating modelTypical duration: 8–20 days

    Who can create what, who pays for it, who secures it and who is called at night — written down, agreed, and enforced by policy rather than by memory.

    You receive

    • Operating model and RACI
    • Account and environment standards
    • Policy and guardrail catalogue
    • Governance forum and cadence
  • FinOpsTypical duration: 10–25 days

    Cost allocation, commitment strategy, rightsizing and waste elimination, typically returning fifteen to thirty per cent of the bill within the first quarter.

    You receive

    • Cost allocation and tagging model
    • Rightsizing and commitment plan
    • Savings tracker with measured results
    • Monthly FinOps reporting
  • Continuous cloud security and complianceTypical duration: Recurring

    Posture management that runs every day and reports in the language of your control framework, so cloud evidence for ISO 27001 or SOC 2 is produced automatically.

    You receive

    • Continuous control monitoring
    • Compliance dashboards per framework
    • Drift and exception workflow
    • Automated evidence export
  • Resilience, multi-cloud and DORA exit planTypical duration: 10–25 days

    A documented, tested exit strategy for critical cloud services, which DORA requires financial entities to hold and most contracts quietly assume will never be used.

    You receive

    • Criticality and concentration analysis
    • Exit strategy per critical service
    • Portability and data extraction design
    • Exit test plan and results
  • ObservabilityTypical duration: 8–20 days

    Metrics, logs and traces that answer real questions, with service level objectives defined with the business and alerting that does not wake people for nothing.

    You receive

    • Observability architecture
    • Service level objectives and error budgets
    • Dashboard and alert design
    • Runbook integration
  • Sovereignty and data residency assessmentTypical duration: 5–12 days

    Where your data physically sits, who can legally compel access to it, and what it would take to change that — documented for the regulator and the board.

    You receive

    • Data residency map
    • Extraterritorial access analysis
    • Sovereignty risk assessment
    • Options and cost of change

DevSecOps

Controls inside the pipeline, producing their own audit evidence as they run.

  • DevOps and DevSecOps maturity assessmentTypical duration: 5–12 days

    Measured against DORA metrics, OWASP SAMM, NIST SSDF and SLSA, with the difference between what the documentation claims and what the pipelines actually do.

    You receive

    • DORA metrics baseline
    • OWASP SAMM and NIST SSDF scoring
    • SLSA level assessment
    • Prioritised improvement backlog
  • Secure SDLC designTypical duration: 8–20 days

    Security requirements, review gates and acceptance criteria defined per stage, light enough that teams keep them and firm enough to satisfy an auditor.

    You receive

    • Secure SDLC definition per stage
    • Security requirements catalogue
    • Gate and exception process
    • Team onboarding material
  • Threat modellingTypical duration: 3–10 days

    Structured threat modelling of your critical services, run as a workshop with the engineers who build them, producing backlog items rather than a document nobody reopens.

    You receive

    • Data flow diagrams
    • Threat model per critical service
    • Mitigation backlog items
    • Repeatable method for your teams
  • CI/CD pipeline hardeningTypical duration: 8–20 days

    Hardening of GitHub Actions, GitLab CI or Azure DevOps: least-privilege runners, pinned actions, protected branches, signed artefacts and no long-lived credentials.

    You receive

    • Pipeline threat model and findings
    • Hardened reference workflows
    • Runner and credential architecture
    • Branch and release protection rules
  • SAST, DAST, SCA and IaC scanningTypical duration: 8–20 days

    Security testing wired into the pipeline with thresholds that block what matters and stay quiet otherwise, because a scanner nobody trusts is a scanner nobody reads.

    You receive

    • Tool selection and integration
    • Rule tuning and baseline suppression
    • Break-build policy by severity
    • Triage workflow and ownership
  • Secrets managementTypical duration: 5–15 days

    Secrets out of repositories and pipelines, into a vault with short-lived credentials and workload identity, plus detection for the ones already leaked.

    You receive

    • Secret inventory and leak scan
    • Vault and workload identity design
    • Rotation and revocation process
    • Pipeline integration
  • Software supply-chain securityTypical duration: 10–25 days

    SBOM generation, dependency policy, artefact signing and provenance to SLSA levels, aligned with what the Cyber Resilience Act will require you to produce.

    You receive

    • SBOM generation and storage
    • Dependency and licence policy
    • Artefact signing and provenance
    • CRA alignment mapping
  • Infrastructure-as-code security and policy as codeTypical duration: 8–20 days

    Policies expressed as code and enforced before deployment, so a non-compliant resource fails the pull request instead of appearing in an audit six months later.

    You receive

    • Policy catalogue as code
    • Pre-deployment enforcement in CI
    • Exception and waiver workflow
    • Coverage reporting
  • Developer security enablementTypical duration: Recurring

    Training built on your own codebase and findings, plus a security champion network that gives teams someone to ask before the review rather than after it.

    You receive

    • Role-based training sessions
    • Security champion programme
    • Secure coding guidelines for your stack
    • Progress measurement
  • Kubernetes security auditTypical duration: 5–12 days

    Cluster review against the CIS Kubernetes benchmark: RBAC, admission control, network policy, workload identity, secrets handling and node hardening.

    You receive

    • CIS benchmark assessment
    • RBAC and admission policy review
    • Network policy design
    • Prioritised hardening plan
  • Container image securityTypical duration: 5–12 days

    Minimal base images, reproducible builds, registry scanning and signing, with a patch path that does not require rebuilding every service by hand.

    You receive

    • Golden base image set
    • Build and scan pipeline
    • Image signing and admission policy
    • Patch and rebuild process
  • Platform engineering and internal developer platformTypical duration: 20–60 days

    Paved paths that make the secure option the fastest option: golden templates, self-service environments and GitOps delivery with the guardrails already inside.

    You receive

    • Platform architecture and GitOps model
    • Golden path templates
    • Self-service environment provisioning
    • Platform documentation and onboarding
  • Runtime securityTypical duration: 8–20 days

    Detection of what happens after deployment: anomalous process behaviour, container escapes, unexpected network flows, with response actions defined in advance.

    You receive

    • Runtime detection deployment
    • Detection rule tuning
    • Response playbooks
    • Integration with the SOC
  • SRE practicesTypical duration: 10–25 days

    Service level objectives, error budgets, incident review without blame, and toil measured so that automation is funded by evidence rather than by conviction.

    You receive

    • SLI and SLO definitions
    • Error budget policy
    • Incident review process
    • On-call design and toil baseline
  • Observability and security telemetryTypical duration: 8–20 days

    One telemetry pipeline serving both engineering and security, with retention set by regulatory requirement rather than by default configuration.

    You receive

    • Telemetry pipeline architecture
    • Log source coverage and retention policy
    • Security detection feeds
    • Cost and volume control
  • Compliance as codeTypical duration: 10–25 days

    Controls for ISO 27001, SOC 2, NIS2 and DORA implemented as automated checks that produce their own timestamped evidence, which is what makes a certificate affordable to keep.

    You receive

    • Control-to-check mapping
    • Automated evidence collection
    • Continuous compliance dashboard
    • Auditor-ready evidence export
  • Release and change governanceTypical duration: 5–12 days

    Change management that satisfies auditors without a weekly committee: approvals in the pull request, deployment records generated automatically, emergency path documented.

    You receive

    • Change policy and approval model
    • Automated change records
    • Emergency change procedure
    • Audit evidence mapping
  • Disaster recovery automationTypical duration: 8–20 days

    Recovery expressed as code and tested on a schedule, so the recovery time objective is a measured number rather than an aspiration in a document.

    You receive

    • Recovery architecture as code
    • Automated recovery runbooks
    • Scheduled recovery testing
    • Measured RTO and RPO evidence
  • Managed DevSecOps retainerTypical duration: Recurring

    A standing engineering capacity that keeps the pipeline, the guardrails and the evidence working as your platform changes, with a named engineer and a monthly review.

    You receive

    • Named engineer and agreed capacity
    • Pipeline and guardrail maintenance
    • Finding triage and remediation support
    • Monthly review and roadmap

Secure Cloud Start

A landing zone delivered as code in your repository, with guardrails and cost control from the first account.

Duration
6–10 weeks
Price
€20,000 to €40,000
excl. VAT, indicative

Discuss this pack — Secure Cloud Start

DevSecOps Kickstart

Security controls inside your pipeline, tuned so the team keeps them after we leave.

Duration
6–8 weeks
Price
€18,000 to €30,000
excl. VAT, indicative

Discuss this pack — DevSecOps Kickstart

Kubernetes Secure

A cluster audit against the CIS benchmark, with the hardening applied and verified.

Duration
3–4 weeks
Price
€8,000 to €15,000
excl. VAT, indicative

Discuss this pack — Kubernetes Secure

Managed DevSecOps

Standing engineering capacity that keeps pipelines, guardrails and compliance evidence working as your platform changes, with a named engineer and a monthly review.

What is included

  • Named engineer and agreed capacity
  • Pipeline and guardrail maintenance
  • Finding triage and remediation support
  • Compliance evidence upkeep
  • Monthly review and roadmap
Cloud

Discuss this service — Managed DevSecOps

Managed FinOps

Continuous cost management: allocation kept accurate, commitments managed, waste removed each month, and savings reported as measured figures.

What is included

  • Cost allocation upkeep
  • Commitment and discount management
  • Monthly rightsizing actions
  • Anomaly detection and alerts
  • Measured savings reporting
Cloud

Discuss this service — Managed FinOps

Vulnerability and attack-surface management

Continuous scanning of what you own and what is exposed in your name, with findings filtered, prioritised and tracked to closure rather than published as a raw list.

What is included

  • Internal and external scanning
  • External attack surface discovery
  • Risk-based prioritisation
  • Remediation tracking against SLAs
  • Monthly reporting
CyberCloud

Discuss this service — Vulnerability and attack-surface management

Two common entry points

Secure Cloud Start if the foundation needs building. DevSecOps Kickstart if the code ships weekly and security is still outside the pipeline.