Consulting

Cybersecurity consulting under European regulation

Readiness consulting for NIS2, DORA and ISO 27001 — and the security work that has to hold up underneath them.

European security obligations moved from guidance to law, with personal accountability attached at management level. We help organisations get ready for them without turning the programme into a documentation exercise: assess what you actually run, fix the architecture-level weaknesses first, and leave behind controls your own team can operate. Because we build AI systems as well as review them, we cover the failure modes — prompt injection, agent privilege escalation, sensitive data leakage through model responses — that most security practices are still catching up to.

Request a security assessment

01

Regulatory readiness

European security regulation stopped being optional. These are the frameworks our clients are measured against — we prepare you for them; we are not a certification body and cannot issue a certificate.

1.1

NIS2 Readiness & Gap Assessment

Determine whether you fall in scope as an essential or important entity, map the directive's obligations — risk management, incident reporting timelines, supply-chain duties, management accountability — against what you run today, and get a prioritised remediation path.

1.2

DORA Readiness Consulting

For financial entities and their ICT providers: operational resilience testing, third-party risk registers, and incident classification aligned to the regulation's reporting windows.

1.3

ISO/IEC 27001 Readiness Consulting

Scope definition, statement of applicability, and control implementation aimed at a certification audit you can actually pass. The certificate is issued by an accredited body, not by us — our job is making sure that body finds what it needs when it arrives.

1.4

GDPR Security Controls

Article 32 technical and organisational measures made concrete: encryption posture, access control, retention enforcement, and breach-notification readiness with defined owners.

1.5

Executive & Board Reporting

Translating technical risk into the language management is now personally accountable for under NIS2, with a register that survives scrutiny.

02

Architecture & assessment

Finding the weaknesses that matter before someone else does — starting with design, not just scan output.

2.1

Security Architecture Review

Threat modelling across your trust boundaries, identity model, network segmentation, and data flows. Most serious findings live in the design, where no scanner will surface them.

2.2

Cloud Security Posture

IAM policy sprawl, over-permissive roles, exposed storage, unencrypted state, and drift between infrastructure-as-code and what is actually deployed.

2.3

Application & API Assessment

Authentication and authorisation logic, injection surfaces, and business-logic abuse paths — reviewed against the code, not only from the outside.

2.4

Secrets & Credential Hygiene

History-wide scanning for leaked credentials, plus a rotation and storage model that keeps them out of repositories for good.

03

Securing AI systems

AI deployments introduce failure modes traditional security programmes were never designed to catch. This is where our two practices meet.

3.1

LLM Application Security

Prompt injection, indirect injection through retrieved content, tool-use privilege escalation, and output handling — assessed against the OWASP Top 10 for LLM applications.

3.2

Agent Permission Design

Scoping what an autonomous agent may read, write, and spend; where a human must approve; and how every action is logged for later reconstruction.

3.3

Sensitive Data Leakage Testing

Adversarial probing for extraction of personal data, credentials, and proprietary content from model responses and retrieval layers.

04

Response & resilience

What happens on the worst day, decided before the worst day.

4.1

Incident Response Planning

Runbooks, roles, communication trees, and regulator-notification templates matched to NIS2 and GDPR clocks — rehearsed rather than filed.

4.2

Tabletop Exercises

Facilitated scenarios with your engineering and management teams, designed to surface the decision that nobody currently owns.

4.3

Detection & Logging Design

Deciding what to log, where it goes, how long it is kept, and which signals are worth waking someone for — sized to your team, not to a vendor's licence tier.

4.4

Backup & Recovery Validation

Testing restores rather than trusting backup jobs, with recovery objectives written down and measured.

Frameworks & tooling we work with

NIS2DORAISO/IEC 27001GDPR Article 32OWASP Top 10OWASP LLM Top 10MITRE ATT&CKSTRIDECIS BenchmarksTerraformKubernetesHashiCorp VaultSOPS / ageSigstoreOpenTelemetry

These are the frameworks and tools our assessments are written against. We are a consultancy, not a certification or accreditation body: we hold no certification under these frameworks and cannot issue one. Our work is preparing your organisation, its controls, and its evidence for the auditors and regulators who do.

KEEP IN TOUCH · 004

Expand your horizons,soar to new heights.

The foundation of business growth is the ability to establish and maintain contact with forward-thinking and innovative organizations — gaining insight, access, and momentum.

Let's stay in touch.