Find out where your security actually stands
How it works
It ends with a document rather than a follow-up call.
- 01
You tell us what you run
A few questions at booking, including which domain worries you most.
- 02
A working session, not a pitch
All eight domains, then a hard look at the one you named.
- 03
You get it in writing
Where you stand, and what deserves a real look. Yours to keep either way.
What we look at
Eight domains. We pass across all of them and go deep on the one you name when you book — sixty minutes is triage, not an assessment, and the summary says which ones deserve a real look.
- 01
Identity and Access
Human and workload identity, least privilege, standing and just-in-time access, federation, and the secrets behind them.
- 02
Vulnerability Management
Finding what is exposed, deciding what matters, and closing it — triaged rather than filed at you.
- 03
Data Protection
Classification, encryption and key custody, residency and retention, and who your data is shared with — including third parties and connected applications.
- 04
Network Security
Segmentation and isolation, what enters and what leaves, private connectivity, and what is reachable from the internet.
- 05
Workload Protection
Hardened baselines and what runs on them — including the dependencies, base images and infrastructure code your workloads are built from.
- 06
Logging and Monitoring
What is recorded, where it lands, how long it is kept, and whether an alert still reaches a person.
- 07
Incident Response and Continuity
Detection through to containment, and the backups behind it — immutable, and restored in a test rather than in an incident.
- 08
Governance, Risk and Compliance
Policy and the standards it maps to, the risk register, exceptions and when they expire, and the evidence an auditor asks for.
Is this for you?
- You build or run software, and security has become someone's explicit problem
- You are moving to the cloud, or already there and unsure what you inherited
- Your developers are using AI assistants and nobody has approved that yet
- An audit, a customer questionnaire or a board question started this
Frequently asked questions
- Is this really free, or is it a sales call?
- Free, and it is not a sales call. You get the written summary whether or not we ever work together, and you are welcome to hand it to another firm. We do this because the fastest way to show how we work is to do a small piece of it. If the summary says you have no urgent problem, that is what it will say.
- Do you need access to our systems?
- No. The session is a conversation about architecture, process and access — no credentials, no scanning, no connection to anything you run. If a finding warrants hands-on testing to confirm, we will say so and scope it separately as paid work.
- What do we need to prepare?
- Nothing formal. An architecture diagram helps if one exists, but an honest description of how code reaches production is worth more than a document that was accurate two years ago. The people who actually run the systems are the ones worth having in the room.
- Who from your side attends?
- A consultant who delivers this work — the same person who would scope any engagement that follows. You will not be handed to someone else after a contract is signed.
- What happens with what we tell you?
- It stays between us, and we will sign your NDA before the session if you would like one in place. Nothing from the session appears in a customer story or anywhere else without your written permission.
- What if we want you to fix what you find?
- Then we scope it and quote it like any other mandate, with the hours broken down by role. Our pricing page shows what a full engagement of each type runs to, so you know the scale before you ask.
Sixty minutes, and you will know where you stand
The worst outcome is a written summary telling you that your priorities are already in the right order. Most organisations do not get that answer.