Discover
Understand the operational mission, system boundaries, critical assets, stakeholders, dependencies and constraints.
Approach
Our approach is evidence-based, technology-neutral and designed to support real decisions.
Understand the operational mission, system boundaries, critical assets, stakeholders, dependencies and constraints.
Analyse threats, vulnerabilities, consequences, existing controls, architecture and current maturity.
Define target-state controls, security patterns, treatment options, responsibilities and priorities.
Develop roadmaps, implementation guidance, assurance criteria, monitoring requirements and governance.
Working principles
Safety and operational availability come first.
Recommendations must be implementable in the client environment.
Risk is communicated in business and operational terms.
Existing investments are reused where appropriate.
Controls are proportionate to consequence and exposure.
Standards and frameworks