Cases

Every engagement began the same way. None ended the same way.

Every one started with an assessment. What came next followed from what we found.

Not every conversation ends in a mandate. If the assessment shows you can do it yourself, the report says so and we do not propose a mandate.

The cases

The assessment

A trading company

Their largest customer had set a deadline: ISO 27001 or no new framework agreement. No ISMS, no security staff.

  • After three weeks we had a strategy with a defensible timeline, and the customer accepted it. The pressure was off.
  • After eight months the ISMS stood: risk register, Statement of Applicability, 22 management documents, approved by leadership. Certification is underway.
  • A GRC platform is set up, followed by vCISO on a mandate.
  • From day one we run the conversations with the major customer's risk team.

To the ISO 27001 roadmap

A fund-owned company

The IT had grown instead of being built. No governance, no documentation, no CIO. At the next due diligence that would have been a deduction.

  • The IT estate documented and consolidated: duplicate tools and licences retired, running costs reduced.
  • Migrated from on-premise to the cloud.
  • Two acquisitions technically integrated.
  • Governance put in place: decision paths, accountabilities, identities and access, the HR system as the source, reporting to the fund.
  • The mandate was extended.

To Portfolio

A fintech

Regulated, but no view of attacks inside its own house. The ISMS existed on paper, not in operation.

  • Managed detection selected and set up. Operated by a partner who can do that around the clock.
  • EDR rolled out across the estate.
  • ISMS consulting, out of what the assessment had found.
  • A penetration test at the end, with an offensive security partner.
  • Today the operation sees attacks, and the ISMS holds up to inspection.

To Detection: MDR and EDR

An insurer

The ISMS stood, but their own IT could not run the standards. The CISO saw his DORA requirements unimplemented, and IT was never told what to do technically. A binding cryptography standard had to be ready before the DORA deadline, not a whole program.

  • A cryptography standard based on DORA and ISO 27001.
  • A logging standard and a logging concept.
  • Translated between CISO and IT: a document fitted exactly to their own stack. The IT lead could implement precisely and measure progress, the CISO got his DORA compliance.
  • Both written so their own team understands it and can run it. That was the condition, not the bonus.

To Standards your own IT can run

A software company

After an incident: attackers had taken over accounts through phishing. The acute response ran through the cyber insurer; we came afterwards, for the rebuild. Inside the house no one had seen what happened, and access had never been put in order.

  • Access and identities put in order: accounts, rights, who may reach what, from one source.
  • MDR and EDR rolled out across the house.
  • An ISMS set up: governance, responsibilities, a state that holds.
  • Six to eight weeks from forensic report to a provable state.
  • Today the operation sees an attack, and the door it came through is closed.

To Detection: MDR and EDR

References

You do not get a logo wall.

You get a phone call: thirty minutes with one of our clients, in confidence.

Request a first call