FAMILY A · FIVE SERVICES
Governance, risk and compliance
The rules a business has to meet, the risks worth ranking above the rest, and the leadership to run all of it, whether that is needed for a single project or on an ongoing basis.
GRC-01
Gap and maturity assessment
Most boards approve security budgets without a clear picture of where the organisation actually stands, which means spend tends to follow the loudest vendor pitch rather than the biggest gap. This assessment measures current security practices, policies and technical controls against a chosen framework, such as ISO/IEC 27001 or NIST CSF, and scores maturity domain by domain.
The result is a gap list and a prioritised roadmap that puts budget against the highest-risk areas first, and gives the board a defensible answer when a regulator, insurer or acquirer asks how that priority was decided. It is typically the first phase of the Journey to Green maturity programme.
RSK-02
Strategy and risk management
Many risk registers are built once for an audit and never opened again, which means the document drifts further from actual exposure every month it sits untouched. This engagement builds a risk register with rated, owned risks and a security strategy tied to business risk rather than a generic template, reviewed on a cycle that keeps it current.
The practical effect is that attention and budget go to what could actually hurt the business, and if something does go wrong, the organisation can show a regulator or insurer that the risk was identified and actively managed rather than sitting unreviewed in a spreadsheet.
CMP-06
Compliance and regulatory support
Compliance evidence often lives in a folder that falls apart the moment an auditor asks a pointed follow-up question, because it was written to exist rather than to be tested. This service produces policies, procedures, RACI matrices and evidence packs for POPIA, ISO 27001, PCI DSS and sector-specific requirements, written the way an auditor actually reads them.
The direct benefit is fewer audit findings and less last-minute scrambling before a review. Reporting can be structured through the G-RISE governance framework where a board or regulator needs to see the evidence in a format built for that audience.
CSO-08
Virtual CISO (vCISO)
Many mid-market organisations have grown past the point where security can be a part-time responsibility bolted onto an IT manager's job, but a permanent CISO salary is hard to justify against the rest of the budget. This service provides ongoing security leadership on a part-time or retained basis: strategy, risk oversight, policy governance, incident escalation and board or exco reporting through the G-RISE framework.
The organisation gets board-level accountability and a single point of ownership for security decisions, without carrying the fixed cost of a full-time executive.
BCM-13
Business continuity management
Most organisations have a plan for defending their systems but nothing written down for what happens once a disruption actually stops the business trading, whether that is a cyberattack, a fire, a flood, or a key supplier going dark without warning. This service builds business continuity and disaster recovery planning to the ISO 22301 standard: identifying the processes that cannot be allowed to fail, setting realistic recovery time objectives, and testing the plan against a real scenario rather than filing it away unread.
The result is a board with an exercised, written answer to what happens if this stops working, instead of finding out the answer for the first time during the actual disruption.
FAMILY B · SEVEN SERVICES
Technical security
The hands-on work of finding weaknesses, watching for attacks, and building or engineering the systems that are supposed to catch them.
DET-03
Threat detection and incident response
Most organisations discover that their incident response plan does not work during a live incident, which is the worst possible time to find a gap in escalation paths or log coverage. This service builds detection use cases mapped to the log sources and tools already in place, an incident response plan with a clear escalation matrix, and tabletop exercises that test the plan before it is needed for real.
The benefit is a shorter, calmer response when something does happen: people know their role, evidence is captured correctly, and containment starts in minutes rather than after a round of confused phone calls.
VAP-04
Vulnerability assessment and penetration testing
A raw vulnerability scan produces hundreds of findings and very little guidance on which ones an attacker could actually reach and exploit, so teams either fix the wrong things first or burn out trying to fix everything. This service scopes testing to the systems, applications and network that matter, and ranks findings by exploitability and real-world impact rather than by scanner severity alone.
Reports are written for both engineers and management, with remediation steps that close the gap that matters most first. The result is a measurable reduction in actual attack surface, not just a shorter list of theoretical findings.
ARC-07
Security architecture review
Architecture diagrams usually describe how a network was designed at some point in the past, not how it has actually been configured after years of changes, exceptions and quick fixes. This review examines network, systems and control architecture as implemented today, including segmentation, access control and monitoring coverage, and produces sequenced recommendations rather than a single overwhelming list.
Closing the gap between the diagram and reality is what actually reduces the chance of an attacker moving freely once they get past the first control, and sequencing the fixes means the highest-impact changes happen first instead of the easiest ones.
SOC-09
SOC strategy, design, build and operationalisation
A security operations centre that gets bolted together reactively, tool by tool, tends to generate more alert noise than usable signal, which is how real incidents end up buried under thousands of low-value notifications and analysts burn out chasing false positives. This service covers the full path from strategy through to a running SOC: the build-versus-buy-versus-hybrid decision, technology selection, detection use case design, staffing model, and playbooks, followed by hands-on support through build and operationalisation until the SOC is running independently.
What the organisation ends up with is a SOC tuned to detect what actually matters in its own environment, resourced at a level the business can sustain, rather than a generic template copied from a vendor's reference architecture.
SMA-10
SOC maturity and effectiveness review
Organisations that already run a SOC, whether in-house or through an outsourced provider, rarely get an independent, objective view of whether it is actually effective, efficient, and worth what it costs, rather than merely active. High alert volume and a fully staffed shift roster are not the same thing as good detection coverage, and a SOC can look mature on paper while running on expensive, poorly tuned tooling and detection logic nobody has revisited in years. This review verifies maturity against a recognised model, audits the existing detection use cases and incident response playbooks line by line for gaps, staleness and coverage against relevant attack techniques, and includes an efficiency review of licensing, staffing and tooling spend against what the SOC actually needs to do its job.
For leadership, this answers a direct question that is otherwise hard to get a straight answer to: whether the organisation is actually getting what it is paying for from its SOC, in-house or outsourced, where the use cases and playbooks have gone stale, and exactly where the next investment, or the next cut, should go.
NET-14
Network and cloud security engineering
A report that ends at "here's what's wrong" still leaves someone with the job of actually fixing a misconfigured firewall rule or an overly permissive cloud access policy, and that hands-on work often falls into the gap between an audit team and an already stretched IT department. This service provides the engineering itself: firewall and secure web gateway configuration, cloud security architecture, network segmentation, and access control, implemented rather than only described.
Clients get the fix as well as the finding, without needing to source a separate contractor to carry out what the assessment recommended.
WEB-15
Web, DNS and threat security
A large share of breaches start with a single click: a malicious link, a lookalike domain, a compromised website, and once that traffic reaches an employee's browser, the rest of the security stack is already playing catch-up. This service designs, implements and manages DNS-layer security, secure web gateways, and web threat filtering, drawing on platforms proven at enterprise scale, including protecting one of South Africa's largest banks.
Stopping malicious traffic before it reaches a browser takes the pressure off every control downstream that would otherwise have to catch what got through.
FAMILY C · TWO SERVICES
People and culture
Technology can be perfectly configured and a business can still be breached through a person, which is why this is treated as its own discipline rather than an afterthought.
AWA-05
Security awareness training
Generic annual training gets clicked through without changing a single habit, which is a problem given that staff remain the most common way attackers get in. This service builds role-based training and phishing simulations around the scenarios your staff are actually likely to face, with separate treatment for finance, HR and executive teams who carry higher risk.
Progress is measured, not assumed: click-through rates on simulated phishing should fall and reporting rates should rise over successive rounds, which gives management a number to point to rather than a certificate of attendance.
POL-16
Policy, research and culture
Most cybersecurity policy documents and awareness programmes are written from a template, because building one from first principles takes research most consultancies are not set up to do, which is why so much of it reads as generic and does not hold up under real scrutiny. This service develops national and organisational cybersecurity policy, and researches and builds genuine security culture change, grounded in published, peer-reviewed research rather than a repurposed slide deck.
It draws on work that has been defended in front of national policy bodies and international academic conferences long before it reaches a client, which is a different standard of scrutiny than most policy or awareness content is built to survive.
FAMILY D · TWO SERVICES
Artificial intelligence
AI is moving into daily business use faster than most governance structures have caught up with it.
AIS-11
AI security review
Organisations are adopting AI tools and models faster than they are assessing the new risks that come with them: data leaking through prompts, models that can be manipulated into unintended behaviour, over-permissioned AI agents with more system access than any single employee would be granted, and shadow AI usage that nobody has approved or reviewed. This service reviews AI systems and integrations for security exposure, data handling practices, access controls, and realistic misuse scenarios, and produces a prioritised remediation list.
The organisation gets to keep using AI for the advantage it offers, without quietly opening a new category of data breach that nobody signed off on.
AIG-12
AI policy and governance development
In most organisations, staff are already using AI tools without any formal policy in place, which means decisions about what data is safe to share with which tool are being made ad hoc by individual employees rather than by the business. This service develops an AI usage and governance policy covering approved tools, data classification rules, and oversight roles, in line with relevant standards such as ISO/IEC 42001 or the NIST AI Risk Management Framework.
The organisation gets a defensible, board-approved position on AI use in place before a regulator, client or auditor asks for one, which is considerably cheaper than explaining after the fact why no such position existed.