Skip to content
A long meeting table set with chairs in a bright, empty boardroom.

Services

Strategic Advisory

A security strategy the board can fund and the CISO can execute.

A security strategy the board can fund and the CISO can execute.

Most security programmes fail at the join between the board and the engineers. The board is asked to fund controls it cannot evaluate; the engineers are handed a budget with no sequence. Strategic advisory is the work of building that join.

We start with where you stand — a maturity assessment scored against NIST CSF 2.0 or ISO 27001 with the gaps ranked by exposure — and turn it into a three-year master plan with costs, owners and the order things have to happen in. The same method applies to the cloud: which providers, how sovereign, where the data may sit, and what an exit would cost.

Where you need the function and not just the plan, a virtual CISO carries it: a senior specialist at a fixed number of days a month who attends your committees, owns the roadmap and answers for it.

Strategic Advisory

Strategy and roadmap

Where you stand, where you need to be, and the sequence of decisions in between.

  • Cyber maturity assessmentTypical duration: 3–8 days

    A structured read of where you stand against NIST CSF 2.0 or ISO 27001, scored by domain, with the gaps that matter ranked by exposure rather than by framework order.

    You receive

    • Maturity scoring by domain with evidence
    • Ranked gap register with owners
    • Costed 18-month improvement plan
    • Executive summary for the board
  • Cyber strategy and master planTypical duration: 10–20 days

    A multi-year security plan tied to budget, headcount and regulatory deadlines, so the next three board meetings already have their agenda.

    You receive

    • Target operating model and roles
    • Three-year roadmap with budget envelopes
    • Investment cases per initiative
    • Board-level KPI set
  • Cloud strategy and opportunity studyTypical duration: 8–20 days

    Application-by-application analysis of what to retire, retain, rehost, replatform or rebuild, with the business case and the regulatory constraints in the same table.

    You receive

    • Application portfolio assessment
    • Migration strategy per application
    • Business case with total cost of ownership
    • Roadmap with sequencing and dependencies
  • Hyperscaler and sovereign cloud selectionTypical duration: 5–12 days

    A structured comparison of AWS, Azure, GCP, OVHcloud, Scaleway, S3NS and Bleu against your technical, contractual, sovereignty and exit requirements.

    You receive

    • Weighted requirement matrix
    • Provider comparison with evidence
    • Sovereignty and exit analysis
    • Recommendation and decision record
  • Sovereignty and data residency assessmentTypical duration: 5–12 days

    Where your data physically sits, who can legally compel access to it, and what it would take to change that — documented for the regulator and the board.

    You receive

    • Data residency map
    • Extraterritorial access analysis
    • Sovereignty risk assessment
    • Options and cost of change

vCISO

A senior security leader on your management team for a defined number of days each month: strategy, board reporting, supplier reviews, incident decisions and the compliance calendar.

What is included

  • Named senior consultant
  • Security roadmap and budget ownership
  • Board and executive reporting
  • Supplier and customer security reviews
  • Escalation availability during incidents

Available tiers

  • Essential · 2 days per month
  • Standard · 4 days per month
  • Extended · 8 days per month
AdvisoryGRC

Discuss this service — vCISO

Start with the assessment

A cyber maturity assessment takes four to six weeks and gives you the scored picture and the costed plan the board will ask for.