Skip to content
Switches and routers stacked in a rack, patch cables running between their ports.

Services

Security Assessment & DevSecOps

Know the estate, harden it, and ship security with the code.

Know the estate, harden it, and ship security with the code.

A security report that arrives after the platform is built describes a problem. A guardrail in the pipeline prevents one. The difference in cost is roughly two orders of magnitude, and it is the reason this practice exists inside a security firm rather than next to one.

We design landing zones as code in your repository, wire security testing into the pipelines your teams already use, and tune it until the output is trusted — because a scanner nobody reads is worse than no scanner at all. Then we make the same controls produce their own audit evidence, timestamped and exportable, which is what makes an ISO 27001 or SOC 2 certificate affordable to keep.

And we watch the bill. FinOps usually returns fifteen to thirty per cent of cloud spend, which tends to fund the rest of the work.

Security Assessment & DevSecOps

Technical assessment

A structured read of an estate — organisational, cloud, industrial or Kubernetes — against what good looks like.

  • Infrastructure assessmentTypical duration: 2–4 weeks

    Network, servers, endpoints and directory reviewed for configuration weaknesses, missing patches and exposure, from the inside, with a prioritised fix list.

    You receive

    • Asset inventory as found
    • Prioritised findings with fixes
    • Patch and configuration baseline
  • Cloud security baseline (CSPM and CNAPP)Typical duration: 8–20 days

    A documented security baseline for your cloud accounts, enforced by policy as code and monitored continuously, so a new project starts compliant instead of being corrected later.

    You receive

    • Security baseline per provider
    • CSPM or CNAPP deployment and tuning
    • Guardrails as code
    • Exception and drift process
  • OT and industrial audit (IEC 62443)Typical duration: 10–25 daysDelivered with a qualified partner

    Assessment of industrial systems against IEC 62443 with a specialist partner, using passive techniques on production networks and a zone-and-conduit model as the output.

    You receive

    • Asset inventory and network mapping
    • Zone and conduit model
    • IEC 62443 gap analysis
    • Segmentation and hardening plan
  • Core and internet banking assessmentTypical duration: 3–6 weeks

    The banking platform and its customer channels reviewed end to end: transaction integrity, authentication, session handling, fraud controls and the interfaces between them.

    You receive

    • Threat model of the banking flows
    • Findings with regulatory mapping
    • Remediation plan agreed with IT and risk
  • Well-Architected reviewTypical duration: 3–8 days

    A review of an existing workload against the provider's framework, covering operational excellence, security, reliability, performance, cost and sustainability.

    You receive

    • Review findings by pillar
    • High-risk issue list
    • Prioritised improvement plan
    • Effort and saving estimates
  • Active Directory assessmentTypical duration: 1–3 weeks

    The paths from a standard user to domain admin, found with the same tooling attackers use, and the tiering model that closes them.

    You receive

    • Attack-path graph with the shortest routes
    • Ranked fixes by paths removed
    • Tiering and privileged-access design
  • Organisational and technical auditTypical duration: 5–15 days

    An audit that looks at both sides: how security is organised and decided, and how it is actually configured in the systems that matter.

    You receive

    • Audit report with findings and severity
    • Configuration review of critical systems
    • Prioritised remediation plan
    • Evidence pack reusable for certification
  • Kubernetes security auditTypical duration: 5–12 days

    Cluster review against the CIS Kubernetes benchmark: RBAC, admission control, network policy, workload identity, secrets handling and node hardening.

    You receive

    • CIS benchmark assessment
    • RBAC and admission policy review
    • Network policy design
    • Prioritised hardening plan
  • DevOps and DevSecOps maturity assessmentTypical duration: 5–12 days

    Measured against DORA metrics, OWASP SAMM, NIST SSDF and SLSA, with the difference between what the documentation claims and what the pipelines actually do.

    You receive

    • DORA metrics baseline
    • OWASP SAMM and NIST SSDF scoring
    • SLSA level assessment
    • Prioritised improvement backlog

Technical assistance

Hardening, architecture, identity, encryption and backups — the engineering that closes what the assessments found.

  • Microsoft 365 and Entra ID hardeningTypical duration: 5–15 days

    Conditional access, privileged identity management, tenant restrictions and mail security configured to a documented baseline, with the drift checks that keep it in place.

    You receive

    • Hardening baseline and rationale
    • Conditional access policy set
    • Mail security configuration (SPF, DKIM, DMARC)
    • Drift monitoring plan
  • Hardening guides developmentTypical duration: 2–4 weeks

    Configuration standards for your operating systems, databases, network gear and cloud services, derived from CIS and vendor baselines and cut to what you actually run.

    You receive

    • Hardening guide per platform
    • Compliance check scripts
    • Exception process
  • Zero Trust architectureTypical duration: 10–25 days

    A target architecture where access decisions are made per request against identity, device and context, and a migration path that does not require replacing everything at once.

    You receive

    • Target architecture and principles
    • Access policy model
    • Phased migration plan
    • Reference configurations
  • Identity and privileged access managementTypical duration: 10–30 days

    Joiner-mover-leaver that works, least privilege that survives contact with reality, and privileged accounts held in a vault with session recording rather than in a password manager.

    You receive

    • Identity governance model and role design
    • Privileged access architecture
    • Joiner-mover-leaver process
    • Access review and recertification cycle
  • Data protection and encryptionTypical duration: 5–15 days

    Classification that people apply, encryption and key management that hold up to audit, and data loss prevention tuned to your real flows rather than to the vendor's demo.

    You receive

    • Data classification scheme and labels
    • Encryption and key management design
    • DLP rule set and tuning plan
    • Data flow map with residency
  • Backup security and resilience (3-2-1-1-0)Typical duration: 3–8 days

    Backups an attacker cannot reach and a restore you have actually tested, built to the 3-2-1-1-0 rule with immutability and an offline copy.

    You receive

    • Backup architecture review
    • Immutability and isolation design
    • Restore test protocol and results
    • Recovery time and point objectives
  • Application security supportTypical duration: Recurring

    A security engineer on call for your development teams: design reviews, threat models, findings triage and the awkward questions before release.

    You receive

    • Fixed days a month with your teams
    • Design and release reviews recorded
    • Quarterly view of recurring weaknesses

DevSecOps

Controls inside the pipeline, producing their own audit evidence as they run.

  • Secure SDLC designTypical duration: 8–20 days

    Security requirements, review gates and acceptance criteria defined per stage, light enough that teams keep them and firm enough to satisfy an auditor.

    You receive

    • Secure SDLC definition per stage
    • Security requirements catalogue
    • Gate and exception process
    • Team onboarding material
  • Threat modellingTypical duration: 3–10 days

    Structured threat modelling of your critical services, run as a workshop with the engineers who build them, producing backlog items rather than a document nobody reopens.

    You receive

    • Data flow diagrams
    • Threat model per critical service
    • Mitigation backlog items
    • Repeatable method for your teams
  • CI/CD pipeline hardeningTypical duration: 8–20 days

    Hardening of GitHub Actions, GitLab CI or Azure DevOps: least-privilege runners, pinned actions, protected branches, signed artefacts and no long-lived credentials.

    You receive

    • Pipeline threat model and findings
    • Hardened reference workflows
    • Runner and credential architecture
    • Branch and release protection rules
  • SAST, DAST, SCA and IaC scanningTypical duration: 8–20 days

    Security testing wired into the pipeline with thresholds that block what matters and stay quiet otherwise, because a scanner nobody trusts is a scanner nobody reads.

    You receive

    • Tool selection and integration
    • Rule tuning and baseline suppression
    • Break-build policy by severity
    • Triage workflow and ownership
  • Secrets managementTypical duration: 5–15 days

    Secrets out of repositories and pipelines, into a vault with short-lived credentials and workload identity, plus detection for the ones already leaked.

    You receive

    • Secret inventory and leak scan
    • Vault and workload identity design
    • Rotation and revocation process
    • Pipeline integration
  • Software supply-chain securityTypical duration: 10–25 days

    SBOM generation, dependency policy, artefact signing and provenance to SLSA levels, aligned with what the Cyber Resilience Act will require you to produce.

    You receive

    • SBOM generation and storage
    • Dependency and licence policy
    • Artefact signing and provenance
    • CRA alignment mapping
  • Infrastructure-as-code security and policy as codeTypical duration: 8–20 days

    Policies expressed as code and enforced before deployment, so a non-compliant resource fails the pull request instead of appearing in an audit six months later.

    You receive

    • Policy catalogue as code
    • Pre-deployment enforcement in CI
    • Exception and waiver workflow
    • Coverage reporting
  • Container image securityTypical duration: 5–12 days

    Minimal base images, reproducible builds, registry scanning and signing, with a patch path that does not require rebuilding every service by hand.

    You receive

    • Golden base image set
    • Build and scan pipeline
    • Image signing and admission policy
    • Patch and rebuild process
  • Platform engineering and internal developer platformTypical duration: 20–60 days

    Paved paths that make the secure option the fastest option: golden templates, self-service environments and GitOps delivery with the guardrails already inside.

    You receive

    • Platform architecture and GitOps model
    • Golden path templates
    • Self-service environment provisioning
    • Platform documentation and onboarding
  • Runtime securityTypical duration: 8–20 days

    Detection of what happens after deployment: anomalous process behaviour, container escapes, unexpected network flows, with response actions defined in advance.

    You receive

    • Runtime detection deployment
    • Detection rule tuning
    • Response playbooks
    • Integration with the SOC
  • SRE practicesTypical duration: 10–25 days

    Service level objectives, error budgets, incident review without blame, and toil measured so that automation is funded by evidence rather than by conviction.

    You receive

    • SLI and SLO definitions
    • Error budget policy
    • Incident review process
    • On-call design and toil baseline
  • Observability and security telemetryTypical duration: 8–20 days

    One telemetry pipeline serving both engineering and security, with retention set by regulatory requirement rather than by default configuration.

    You receive

    • Telemetry pipeline architecture
    • Log source coverage and retention policy
    • Security detection feeds
    • Cost and volume control
  • Compliance as codeTypical duration: 10–25 days

    Controls for ISO 27001, SOC 2, NIS2 and DORA implemented as automated checks that produce their own timestamped evidence, which is what makes a certificate affordable to keep.

    You receive

    • Control-to-check mapping
    • Automated evidence collection
    • Continuous compliance dashboard
    • Auditor-ready evidence export
  • Release and change governanceTypical duration: 5–12 days

    Change management that satisfies auditors without a weekly committee: approvals in the pull request, deployment records generated automatically, emergency path documented.

    You receive

    • Change policy and approval model
    • Automated change records
    • Emergency change procedure
    • Audit evidence mapping
  • Disaster recovery automationTypical duration: 8–20 days

    Recovery expressed as code and tested on a schedule, so the recovery time objective is a measured number rather than an aspiration in a document.

    You receive

    • Recovery architecture as code
    • Automated recovery runbooks
    • Scheduled recovery testing
    • Measured RTO and RPO evidence

Foundation and migration

A landing zone built as code, then workloads moved onto it without a rebuild.

  • Secure landing zone with infrastructure as codeTypical duration: 10–25 days

    Account structure, network, identity, logging, encryption and guardrails delivered as code in your repository, so every new environment inherits the same baseline.

    You receive

    • Account and subscription topology
    • Network, identity and logging baseline
    • Terraform or Bicep modules in your repository
    • Guardrail policies and exception process
  • Migration programme managementTypical duration: Scoped per engagement

    Wave planning, runbooks, cutover rehearsals and rollback criteria, with the security and compliance checks built into each wave rather than added at the end.

    You receive

    • Wave plan and dependency map
    • Migration runbooks per workload
    • Cutover and rollback criteria
    • Programme reporting and risk log
  • Application modernisation and containersTypical duration: 20–60 days

    Containerisation and refactoring of applications where it pays, with base images, build pipelines and platform targets defined once and reused.

    You receive

    • Modernisation assessment per application
    • Reference container build and base images
    • Deployment manifests and pipelines
    • Developer documentation
  • Hybrid and multi-cloud networkingTypical duration: 10–25 days

    Connectivity between data centres, clouds and sites designed for segmentation and observability, not just for reachability.

    You receive

    • Target network architecture
    • Segmentation and routing design
    • Connectivity implementation plan
    • Network observability baseline

Governance, operations and cost

Who owns what, how it is monitored, and why the bill stopped growing.

  • Cloud governance and operating modelTypical duration: 8–20 days

    Who can create what, who pays for it, who secures it and who is called at night — written down, agreed, and enforced by policy rather than by memory.

    You receive

    • Operating model and RACI
    • Account and environment standards
    • Policy and guardrail catalogue
    • Governance forum and cadence
  • Resilience, multi-cloud and DORA exit planTypical duration: 10–25 days

    A documented, tested exit strategy for critical cloud services, which DORA requires financial entities to hold and most contracts quietly assume will never be used.

    You receive

    • Criticality and concentration analysis
    • Exit strategy per critical service
    • Portability and data extraction design
    • Exit test plan and results
  • ObservabilityTypical duration: 8–20 days

    Metrics, logs and traces that answer real questions, with service level objectives defined with the business and alerting that does not wake people for nothing.

    You receive

    • Observability architecture
    • Service level objectives and error budgets
    • Dashboard and alert design
    • Runbook integration
  • Data platform and governanceTypical duration: 10–25 days

    A data platform with ownership, quality and lineage defined from the start, and access controls that let analytics happen without opening the whole warehouse.

    You receive

    • Target data architecture
    • Data ownership and stewardship model
    • Access control and classification design
    • Quality and lineage approach

Secure Cloud Start

A landing zone delivered as code in your repository, with guardrails and cost control from the first account.

Duration
6–10 weeks
Price
€20,000 to €40,000
excl. VAT, indicative

Discuss this pack — Secure Cloud Start

DevSecOps Kickstart

Security controls inside your pipeline, tuned so the team keeps them after we leave.

Duration
6–8 weeks
Price
€18,000 to €30,000
excl. VAT, indicative

Discuss this pack — DevSecOps Kickstart

Kubernetes Secure

A cluster audit against the CIS benchmark, with the hardening applied and verified.

Duration
3–4 weeks
Price
€8,000 to €15,000
excl. VAT, indicative

Discuss this pack — Kubernetes Secure

Cyber 360 Flash

Three weeks to a clear picture: maturity, exposure and the ten things to fix first.

Duration
3 weeks
Price
€6,000 to €9,000
excl. VAT, indicative

Discuss this pack — Cyber 360 Flash

Managed DevSecOps

Standing engineering capacity that keeps pipelines, guardrails and compliance evidence working as your platform changes, with a named engineer and a monthly review.

What is included

  • Named engineer and agreed capacity
  • Pipeline and guardrail maintenance
  • Finding triage and remediation support
  • Compliance evidence upkeep
  • Monthly review and roadmap
SOCAssessment

Discuss this service — Managed DevSecOps

Managed FinOps

Continuous cost management: allocation kept accurate, commitments managed, waste removed each month, and savings reported as measured figures.

What is included

  • Cost allocation upkeep
  • Commitment and discount management
  • Monthly rightsizing actions
  • Anomaly detection and alerts
  • Measured savings reporting
SOCAssessment

Discuss this service — Managed FinOps

Two common entry points

Secure Cloud Start if the foundation needs building. DevSecOps Kickstart if the code ships weekly and security is still outside the pipeline.