Cyber 360 Flash
Three weeks to a clear picture: maturity, exposure and the ten things to fix first.
- Duration
- 3 weeks
- Price
- €6,000 to €9,000
- excl. VAT, indicative
Four practices, held by one team.
Services
Security work that ends in a defensible position, not in a document.
Most mid-size companies do not have a security problem in the abstract. They have a specific one: an audit they cannot answer, an insurer asking questions they cannot evidence, a customer questionnaire with forty items, or the quiet knowledge that nobody has ever tested whether the backups restore.
So this practice starts with an honest picture — what you hold, what it is worth, and where the walls are thin — and ends with the walls actually repaired. We assess, we test, we design, and we stay for the part most reports skip: the remediation, and the retest that proves it worked.
Every technical audit we run includes that retest in the price. An open finding is not a finding closed.
Know what you hold, what it is worth, and what would hurt if it fell.
A structured read of where you stand against NIST CSF 2.0 or ISO 27001, scored by domain, with the gaps that matter ranked by exposure rather than by framework order.
A risk analysis built on your real business scenarios: what an attacker would want, the paths available, and the treatment decisions that follow.
A multi-year security plan tied to budget, headcount and regulatory deadlines, so the next three board meetings already have their agenda.
An information security policy set your teams can actually follow, mapped to the frameworks you answer to, with the approval and review cycle already defined.
Supplier risk handled as a process rather than a spreadsheet: tiering, due diligence, contractual security clauses and the evidence NIS2 and DORA expect you to hold.
Role-based training that changes behaviour, including the management body modules NIS2 requires directors to complete, and phishing simulation with coaching rather than blame.
The evidence an insurer or an acquirer will ask for, gathered and challenged before they ask, so the premium or the valuation reflects your real posture.
Test the walls before someone else does, then fix what the test found.
An audit that looks at both sides: how security is organised and decided, and how it is actually configured in the systems that matter.
Manual testing of your applications and APIs against the OWASP methodology, delivered with a PASSI-qualified partner. The retest after remediation is included in the price.
External and internal testing of your network, exposed services and Active Directory, aimed at the paths an attacker would actually take to reach your data.
A configuration review against CIS benchmarks and the provider's own guidance, covering identity, network, logging, storage exposure and the tenant settings people forget.
A goal-oriented, intelligence-led exercise run with a specialist partner: realistic tradecraft against your detection capability, with a purple-team debrief so the blue team gains from it.
Manual review of the parts of your codebase where a flaw is expensive: authentication, authorisation, data access, cryptography and the handling of untrusted input.
Assessment of industrial systems against IEC 62443 with a specialist partner, using passive techniques on production networks and a zone-and-conduit model as the output.
Identity, data and infrastructure designed so a single mistake is not fatal.
A target architecture where access decisions are made per request against identity, device and context, and a migration path that does not require replacing everything at once.
Joiner-mover-leaver that works, least privilege that survives contact with reality, and privileged accounts held in a vault with session recording rather than in a password manager.
Conditional access, privileged identity management, tenant restrictions and mail security configured to a documented baseline, with the drift checks that keep it in place.
Classification that people apply, encryption and key management that hold up to audit, and data loss prevention tuned to your real flows rather than to the vendor's demo.
A continuous cycle with defined scan coverage, risk-based prioritisation and service levels for remediation, reported in terms the executive committee can act on.
Backups an attacker cannot reach and a restore you have actually tested, built to the 3-2-1-1-0 rule with immutability and an offline copy.
See the attack, contain it, and keep the business running while you do.
Round-the-clock detection and response delivered white label with a PDIS-qualified partner, with use cases written for your environment and a named escalation path.
A response plan with named roles, decision thresholds and the regulatory notification clocks already built in, plus playbooks for the scenarios you will actually face.
A tabletop or simulation for the crisis unit, with management and communications in the room. NIS2 and DORA both expect this to have happened, and to be documented.
On-call response with a PRIS-qualified partner: containment first, then evidence preservation, root cause, and the report your insurer and regulator will ask for.
Business impact analysis, continuity strategy and a recovery plan that has been tested, not just written, with the cyber scenario treated as a first-class case.
Continuous watch on what is exposed in your name: domains, certificates, leaked credentials and third-party breaches, filtered to what is worth acting on.
The two surfaces that grew fastest, secured with the same rigour as the rest.
A documented security baseline for your cloud accounts, enforced by policy as code and monitored continuously, so a new project starts compliant instead of being corrected later.
Security review of AI systems against the OWASP Top 10 for LLM applications: prompt injection, data leakage through context, tool and agent permissions, and model supply chain.
Adversarial testing of an assistant, RAG system or agent: jailbreaks, indirect prompt injection through retrieved content, data exfiltration and abuse of connected tools.
Three weeks to a clear picture: maturity, exposure and the ten things to fix first.
A crisis unit that has met, rehearsed and knows who calls the regulator.
What you are buying, in security terms, in time for it to affect the price.
A senior security leader on your management team for a defined number of days each month: strategy, board reporting, supplier reviews, incident decisions and the compliance calendar.
Detection and response around the clock, delivered with a PDIS-qualified partner, with detection use cases written for your environment and a single point of contact on our side.
Continuous scanning of what you own and what is exposed in your name, with findings filtered, prioritised and tracked to closure rather than published as a raw list.
Discuss this service — Vulnerability and attack-surface management
A year-round programme rather than an annual module: short role-based content, phishing simulation with coaching, and reporting that holds up as NIS2 evidence.
If the honest answer is "I do not know what state we are in", Cyber 360 Flash answers that in three weeks for a fixed price.