About
What this practice does
Independent cyber and technology-risk advisory: security strategy, architecture review, industrial and critical-systems security, and assurance work for organizations that need practical, implementable decisions rather than generic findings.
How engagements are run
Every engagement is scoped in writing before work begins. Scope, deliverables, duration, and price are agreed up front. If the work turns out to be smaller than scoped, the scope is reduced rather than filled.
What this practice does not do
No implementation of third-party products for commission. No certification issuance — that is the auditor's or accreditation body's role, and mixing the two compromises both. No retainers that exist to consume budget rather than deliver a named outcome.
Independence
There are no reseller agreements, referral fees, or vendor partnerships behind any recommendation made in an engagement.
Request a Cybersecurity Assessment
Get a senior-led assessment of your cyber and technology risk, and a prioritized plan to act on it.
Request a Cybersecurity Assessment