SERVICES

Twelve service lines, scoped to run alone or together

Each service below can be engaged as a fixed-scope project or combined into a longer programme. Reference codes follow the same convention used in the control documentation and SOPs produced for clients.

GRC-01

Gap and maturity assessment

Most boards approve security budgets without a clear picture of where the organisation actually stands, which means spend tends to follow the loudest vendor pitch rather than the biggest gap. This assessment measures current security practices, policies and technical controls against a chosen framework, such as ISO/IEC 27001 or NIST CSF, and scores maturity domain by domain.

The result is a gap list and a prioritised roadmap that puts budget against the highest-risk areas first, and gives the board a defensible answer when a regulator, insurer or acquirer asks how that priority was decided. It is typically the first phase of the Journey to Green maturity programme.

RSK-02

Strategy and risk management

Many risk registers are built once for an audit and never opened again, which means the document drifts further from actual exposure every month it sits untouched. This engagement builds a risk register with rated, owned risks and a security strategy tied to business risk rather than a generic template, reviewed on a cycle that keeps it current.

The practical effect is that attention and budget go to what could actually hurt the business, and if something does go wrong, the organisation can show a regulator or insurer that the risk was identified and actively managed rather than sitting unreviewed in a spreadsheet.

DET-03

Threat detection and incident response

Most organisations discover that their incident response plan does not work during a live incident, which is the worst possible time to find a gap in escalation paths or log coverage. This service builds detection use cases mapped to the log sources and tools already in place, an incident response plan with a clear escalation matrix, and tabletop exercises that test the plan before it is needed for real.

The benefit is a shorter, calmer response when something does happen: people know their role, evidence is captured correctly, and containment starts in minutes rather than after a round of confused phone calls.

VAP-04

Vulnerability assessment and penetration testing

A raw vulnerability scan produces hundreds of findings and very little guidance on which ones an attacker could actually reach and exploit, so teams either fix the wrong things first or burn out trying to fix everything. This service scopes testing to the systems, applications and network that matter, and ranks findings by exploitability and real-world impact rather than by scanner severity alone.

Reports are written for both engineers and management, with remediation steps that close the gap that matters most first. The result is a measurable reduction in actual attack surface, not just a shorter list of theoretical findings.

AWA-05

Security awareness training

Generic annual training gets clicked through without changing a single habit, which is a problem given that staff remain the most common way attackers get in. This service builds role-based training and phishing simulations around the scenarios your staff are actually likely to face, with separate treatment for finance, HR and executive teams who carry higher risk.

Progress is measured, not assumed: click-through rates on simulated phishing should fall and reporting rates should rise over successive rounds, which gives management a number to point to rather than a certificate of attendance.

CMP-06

Compliance and regulatory support

Compliance evidence often lives in a folder that falls apart the moment an auditor asks a pointed follow-up question, because it was written to exist rather than to be tested. This service produces policies, procedures, RACI matrices and evidence packs for POPIA, ISO 27001, PCI DSS and sector-specific requirements, written the way an auditor actually reads them.

The direct benefit is fewer audit findings and less last-minute scrambling before a review. Reporting can be structured through the G-RISE governance framework where a board or regulator needs to see the evidence in a format built for that audience.

ARC-07

Security architecture review

Architecture diagrams usually describe how a network was designed at some point in the past, not how it has actually been configured after years of changes, exceptions and quick fixes. This review examines network, systems and control architecture as implemented today, including segmentation, access control and monitoring coverage, and produces sequenced recommendations rather than a single overwhelming list.

Closing the gap between the diagram and reality is what actually reduces the chance of an attacker moving freely once they get past the first control, and sequencing the fixes means the highest-impact changes happen first instead of the easiest ones.

CSO-08

Virtual CISO (vCISO)

Many mid-market organisations have grown past the point where security can be a part-time responsibility bolted onto an IT manager's job, but a permanent CISO salary is hard to justify against the rest of the budget. This service provides ongoing security leadership on a part-time or retained basis: strategy, risk oversight, policy governance, incident escalation and board or exco reporting through the G-RISE framework.

The organisation gets board-level accountability and a single point of ownership for security decisions, without carrying the fixed cost of a full-time executive.

SOC-09

SOC strategy, design, build and operationalisation

A security operations centre that gets bolted together reactively, tool by tool, tends to generate more alert noise than usable signal, which is how real incidents end up buried under thousands of low-value notifications and analysts burn out chasing false positives. This service covers the full path from strategy through to a running SOC: the build-versus-buy-versus-hybrid decision, technology selection, detection use case design, staffing model, and playbooks, followed by hands-on support through build and operationalisation until the SOC is running independently.

What the organisation ends up with is a SOC tuned to detect what actually matters in its own environment, resourced at a level the business can sustain, rather than a generic template copied from a vendor's reference architecture.

SMA-10

SOC maturity evaluation

Organisations that already run a SOC, whether in-house or through an outsourced provider, rarely get an independent, objective view of whether it is actually effective rather than merely active. High alert volume and a fully staffed shift roster are not the same thing as good detection coverage. This evaluation assesses people, process and technology against a recognised maturity model, benchmarks detection coverage against relevant attack techniques, and produces a prioritised improvement roadmap.

For leadership, this answers a direct question that is otherwise hard to get a straight answer to: whether the organisation is actually getting what it is paying for from its SOC, in-house or outsourced, and exactly where the next investment should go.

AIS-11

AI security review

Organisations are adopting AI tools and models faster than they are assessing the new risks that come with them: data leaking through prompts, models that can be manipulated into unintended behaviour, over-permissioned AI agents with more system access than any single employee would be granted, and shadow AI usage that nobody has approved or reviewed. This service reviews AI systems and integrations for security exposure, data handling practices, access controls, and realistic misuse scenarios, and produces a prioritised remediation list.

The organisation gets to keep using AI for the advantage it offers, without quietly opening a new category of data breach that nobody signed off on.

AIG-12

AI policy and governance development

In most organisations, staff are already using AI tools without any formal policy in place, which means decisions about what data is safe to share with which tool are being made ad hoc by individual employees rather than by the business. This service develops an AI usage and governance policy covering approved tools, data classification rules, and oversight roles, in line with relevant standards such as ISO/IEC 42001 or the NIST AI Risk Management Framework.

The organisation gets a defensible, board-approved position on AI use in place before a regulator, client or auditor asks for one, which is considerably cheaper than explaining after the fact why no such position existed.

Not sure which service fits?

Describe the problem and we will recommend a scope, whether that is one service or a combination.

Get a recommendation
WhatsApp us