Skip to content

Services

Cybersecurity

Security work that ends in a defensible position, not in a document.

Hold the walls, and know where they are thin.

Most mid-size companies do not have a security problem in the abstract. They have a specific one: an audit they cannot answer, an insurer asking questions they cannot evidence, a customer questionnaire with forty items, or the quiet knowledge that nobody has ever tested whether the backups restore.

So this practice starts with an honest picture — what you hold, what it is worth, and where the walls are thin — and ends with the walls actually repaired. We assess, we test, we design, and we stay for the part most reports skip: the remediation, and the retest that proves it worked.

Every technical audit we run includes that retest in the price. An open finding is not a finding closed.

Cybersecurity

Governance, risk and strategy

Know what you hold, what it is worth, and what would hurt if it fell.

  • Cyber maturity assessmentTypical duration: 3–8 days

    A structured read of where you stand against NIST CSF 2.0 or ISO 27001, scored by domain, with the gaps that matter ranked by exposure rather than by framework order.

    You receive

    • Maturity scoring by domain with evidence
    • Ranked gap register with owners
    • Costed 18-month improvement plan
    • Executive summary for the board
  • Risk analysis (EBIOS RM / ISO 27005)Typical duration: 8–20 days

    A risk analysis built on your real business scenarios: what an attacker would want, the paths available, and the treatment decisions that follow.

    You receive

    • Business and technical asset inventory
    • Strategic and operational attack scenarios
    • Risk register with treatment decisions
    • Residual risk statement for management
  • Cyber strategy and master planTypical duration: 10–20 days

    A multi-year security plan tied to budget, headcount and regulatory deadlines, so the next three board meetings already have their agenda.

    You receive

    • Target operating model and roles
    • Three-year roadmap with budget envelopes
    • Investment cases per initiative
    • Board-level KPI set
  • Policy frameworkTypical duration: 8–15 days

    An information security policy set your teams can actually follow, mapped to the frameworks you answer to, with the approval and review cycle already defined.

    You receive

    • Information security policy and charter
    • Topic-specific policies and standards
    • Control-to-policy mapping
    • Review and approval calendar
  • Third-party and supply-chain securityTypical duration: 5–15 days

    Supplier risk handled as a process rather than a spreadsheet: tiering, due diligence, contractual security clauses and the evidence NIS2 and DORA expect you to hold.

    You receive

    • Supplier tiering model and register
    • Due-diligence questionnaires by tier
    • Contractual security and audit clauses
    • Monitoring and review process
  • Awareness and trainingTypical duration: Recurring

    Role-based training that changes behaviour, including the management body modules NIS2 requires directors to complete, and phishing simulation with coaching rather than blame.

    You receive

    • Annual awareness plan by population
    • Executive and board modules
    • Phishing simulation campaigns
    • Participation and progress reporting
  • Cyber insurance and M&A due diligenceTypical duration: 3–10 days

    The evidence an insurer or an acquirer will ask for, gathered and challenged before they ask, so the premium or the valuation reflects your real posture.

    You receive

    • Insurer questionnaire pack with evidence
    • Control gap analysis against policy conditions
    • Target posture assessment for M&A
    • Remediation plan with cost estimates

Audit and offensive security

Test the walls before someone else does, then fix what the test found.

  • Organisational and technical auditTypical duration: 5–15 days

    An audit that looks at both sides: how security is organised and decided, and how it is actually configured in the systems that matter.

    You receive

    • Audit report with findings and severity
    • Configuration review of critical systems
    • Prioritised remediation plan
    • Evidence pack reusable for certification
  • Application pentest (web, API, mobile)Typical duration: 5–12 daysRetest includedDelivered with a qualified partner

    Manual testing of your applications and APIs against the OWASP methodology, delivered with a PASSI-qualified partner. The retest after remediation is included in the price.

    You receive

    • Technical report with reproducible proofs
    • Severity and exploitability rating
    • Developer-facing remediation guidance
    • Retest report and attestation
  • Infrastructure pentestTypical duration: 5–10 daysRetest included

    External and internal testing of your network, exposed services and Active Directory, aimed at the paths an attacker would actually take to reach your data.

    You receive

    • External and internal attack paths
    • Active Directory findings and privilege escalation
    • Prioritised remediation plan
    • Retest report
  • Cloud configuration audit (AWS, Azure, GCP, M365)Typical duration: 3–8 daysRetest included

    A configuration review against CIS benchmarks and the provider's own guidance, covering identity, network, logging, storage exposure and the tenant settings people forget.

    You receive

    • Findings mapped to CIS benchmarks
    • Identity and network exposure review
    • Infrastructure-as-code remediation snippets
    • Retest and drift check
  • Red TeamTypical duration: 15–40 daysDelivered with a qualified partner

    A goal-oriented, intelligence-led exercise run with a specialist partner: realistic tradecraft against your detection capability, with a purple-team debrief so the blue team gains from it.

    You receive

    • Scenario and rules of engagement
    • Attack narrative with timeline
    • Detection and response gap analysis
    • Purple-team debrief workshop
  • Secure code reviewTypical duration: 5–12 daysRetest included

    Manual review of the parts of your codebase where a flaw is expensive: authentication, authorisation, data access, cryptography and the handling of untrusted input.

    You receive

    • Findings with code references
    • Secure coding recommendations
    • Rule tuning for your SAST tooling
    • Developer debrief session
  • OT and industrial audit (IEC 62443)Typical duration: 10–25 daysDelivered with a qualified partner

    Assessment of industrial systems against IEC 62443 with a specialist partner, using passive techniques on production networks and a zone-and-conduit model as the output.

    You receive

    • Asset inventory and network mapping
    • Zone and conduit model
    • IEC 62443 gap analysis
    • Segmentation and hardening plan

Architecture and protection

Identity, data and infrastructure designed so a single mistake is not fatal.

  • Zero Trust architectureTypical duration: 10–25 days

    A target architecture where access decisions are made per request against identity, device and context, and a migration path that does not require replacing everything at once.

    You receive

    • Target architecture and principles
    • Access policy model
    • Phased migration plan
    • Reference configurations
  • Identity and privileged access managementTypical duration: 10–30 days

    Joiner-mover-leaver that works, least privilege that survives contact with reality, and privileged accounts held in a vault with session recording rather than in a password manager.

    You receive

    • Identity governance model and role design
    • Privileged access architecture
    • Joiner-mover-leaver process
    • Access review and recertification cycle
  • Microsoft 365 and Entra ID hardeningTypical duration: 5–15 days

    Conditional access, privileged identity management, tenant restrictions and mail security configured to a documented baseline, with the drift checks that keep it in place.

    You receive

    • Hardening baseline and rationale
    • Conditional access policy set
    • Mail security configuration (SPF, DKIM, DMARC)
    • Drift monitoring plan
  • Data protection and encryptionTypical duration: 5–15 days

    Classification that people apply, encryption and key management that hold up to audit, and data loss prevention tuned to your real flows rather than to the vendor's demo.

    You receive

    • Data classification scheme and labels
    • Encryption and key management design
    • DLP rule set and tuning plan
    • Data flow map with residency
  • Vulnerability managementTypical duration: Recurring

    A continuous cycle with defined scan coverage, risk-based prioritisation and service levels for remediation, reported in terms the executive committee can act on.

    You receive

    • Scanning coverage and schedule
    • Risk-based prioritisation model
    • Remediation SLAs by severity
    • Monthly reporting pack
  • Backup security and resilience (3-2-1-1-0)Typical duration: 3–8 days

    Backups an attacker cannot reach and a restore you have actually tested, built to the 3-2-1-1-0 rule with immutability and an offline copy.

    You receive

    • Backup architecture review
    • Immutability and isolation design
    • Restore test protocol and results
    • Recovery time and point objectives

Detection, response and continuity

See the attack, contain it, and keep the business running while you do.

  • Managed SOC and MDRTypical duration: RecurringDelivered with a qualified partner

    Round-the-clock detection and response delivered white label with a PDIS-qualified partner, with use cases written for your environment and a named escalation path.

    You receive

    • Detection use-case catalogue
    • Log source onboarding plan
    • Escalation and response runbooks
    • Monthly detection performance review
  • Incident response plan and playbooksTypical duration: 5–12 days

    A response plan with named roles, decision thresholds and the regulatory notification clocks already built in, plus playbooks for the scenarios you will actually face.

    You receive

    • Incident response plan and severity scale
    • Playbooks for ransomware, fraud, data breach
    • Regulatory notification timelines
    • Contact and escalation matrix
  • Cyber crisis exerciseTypical duration: 3–6 days

    A tabletop or simulation for the crisis unit, with management and communications in the room. NIS2 and DORA both expect this to have happened, and to be documented.

    You receive

    • Tailored scenario and injects
    • Facilitated exercise session
    • Observation report with findings
    • Improvement plan and evidence pack
  • Incident response and forensicsTypical duration: On callDelivered with a qualified partner

    On-call response with a PRIS-qualified partner: containment first, then evidence preservation, root cause, and the report your insurer and regulator will ask for.

    You receive

    • Containment and eradication support
    • Forensic analysis and timeline
    • Root cause report
    • Post-incident hardening plan
  • Business continuity and disaster recoveryTypical duration: 10–25 days

    Business impact analysis, continuity strategy and a recovery plan that has been tested, not just written, with the cyber scenario treated as a first-class case.

    You receive

    • Business impact analysis
    • Continuity and recovery strategy
    • Disaster recovery runbooks
    • Test plan and exercise results
  • Threat intelligence and attack-surface monitoringTypical duration: Recurring

    Continuous watch on what is exposed in your name: domains, certificates, leaked credentials and third-party breaches, filtered to what is worth acting on.

    You receive

    • External attack surface inventory
    • Credential leak monitoring
    • Sector threat briefings
    • Monthly actionable alert digest

Cloud and AI security

The two surfaces that grew fastest, secured with the same rigour as the rest.

  • Cloud security baseline (CSPM and CNAPP)Typical duration: 8–20 days

    A documented security baseline for your cloud accounts, enforced by policy as code and monitored continuously, so a new project starts compliant instead of being corrected later.

    You receive

    • Security baseline per provider
    • CSPM or CNAPP deployment and tuning
    • Guardrails as code
    • Exception and drift process
  • AI and LLM securityTypical duration: 5–15 days

    Security review of AI systems against the OWASP Top 10 for LLM applications: prompt injection, data leakage through context, tool and agent permissions, and model supply chain.

    You receive

    • AI system architecture and data flow review
    • OWASP LLM Top 10 assessment
    • Guardrail and monitoring design
    • Secure usage guidance for builders
  • AI Red TeamTypical duration: 5–12 days

    Adversarial testing of an assistant, RAG system or agent: jailbreaks, indirect prompt injection through retrieved content, data exfiltration and abuse of connected tools.

    You receive

    • Adversarial test plan and corpus
    • Findings with reproducible prompts
    • Guardrail effectiveness measurement
    • Remediation and retest

Cyber 360 Flash

Three weeks to a clear picture: maturity, exposure and the ten things to fix first.

Duration
3 weeks
Price
€6,000 to €9,000
excl. VAT, indicative

Discuss this pack — Cyber 360 Flash

vCISO

A senior security leader on your management team for a defined number of days each month: strategy, board reporting, supplier reviews, incident decisions and the compliance calendar.

What is included

  • Named senior consultant
  • Security roadmap and budget ownership
  • Board and executive reporting
  • Supplier and customer security reviews
  • Escalation availability during incidents

Available tiers

  • Essential · 2 days per month
  • Standard · 4 days per month
  • Extended · 8 days per month
CyberCompliance

Discuss this service — vCISO

White-label SOC and MDR

Delivered with a qualified partner

Detection and response around the clock, delivered with a PDIS-qualified partner, with detection use cases written for your environment and a single point of contact on our side.

What is included

  • 24/7 monitoring and triage
  • Detection use cases for your stack
  • Containment actions by agreement
  • Monthly detection performance review
  • Escalation to incident response
Cyber

Discuss this service — White-label SOC and MDR

Vulnerability and attack-surface management

Continuous scanning of what you own and what is exposed in your name, with findings filtered, prioritised and tracked to closure rather than published as a raw list.

What is included

  • Internal and external scanning
  • External attack surface discovery
  • Risk-based prioritisation
  • Remediation tracking against SLAs
  • Monthly reporting
CyberCloud

Discuss this service — Vulnerability and attack-surface management

Continuous awareness

A year-round programme rather than an annual module: short role-based content, phishing simulation with coaching, and reporting that holds up as NIS2 evidence.

What is included

  • Annual plan by population
  • Phishing simulation campaigns
  • Short role-based modules
  • Executive and board sessions
  • Participation evidence for audits
Cyber

Discuss this service — Continuous awareness

Where would you start?

If the honest answer is "I do not know what state we are in", Cyber 360 Flash answers that in three weeks for a fixed price.