Services

Advisory built for
mission-critical work.

Independent, evidence-based cybersecurity and AI assurance — from first gap assessment to executive sign-off.

AI Security & Governance

Adopt AI without inheriting its risk.

AI management systems aligned to ISO/IEC 42001, Responsible AI policy, and security assessments of AI products embedded in your supply chain.

  • ISO 42001 readiness & gap assessment
  • AI risk & impact assessments
  • AI product and model supply-chain review
  • Responsible AI policy and guardrails

Government & Defence Assurance

ISM and PSPF compliance you can evidence.

Evidence-based assessments against the ISM, PSPF and NIST SP 800-53 — with SSPs, SRMPs and practical uplift plans, built by an assessor who has worked inside Defence-industry security programs.

  • ISM control assessments & gap analysis
  • PSPF maturity & annual reporting support
  • NIST SP 800-53 control mapping
  • SSP, SRMP & Statement of Applicability
  • IRAP preparation & system authorisation

Critical Infrastructure

SOCI obligations, made operational.

All-hazards risk management programs for energy, telecommunications and transport operators — from CIRMP and TSRMP design to AESCSF maturity audits.

  • CIRMP / TSRMP development
  • AESCSF V2 assessments
  • All-hazards: cyber, physical, supply chain, natural
  • Board-ready attestation support

Audit & Certification

Audits that leave you stronger.

ISO 27001, PCI DSS and SWIFT CSF audits and readiness programs that prioritise cost-efficient remediation over box-ticking.

  • ISO 27001 lead audit & readiness
  • PCI DSS gap analysis & roadmaps
  • Group-wide multi-entity coverage
  • Executive & Board reporting

Third-Party & Supplier Risk

Trust, verified across your ecosystem.

Supplier assurance programs that scale — assessments, tabletop exercises with global cloud providers, and threat-intelligence-driven monitoring.

  • TPRM program design
  • Hyperscaler & SaaS assessments
  • CTI-informed supplier monitoring
  • GRC platform (ServiceNow IRM) uplift

Executive Advisory

Clarity for the Board and C-suite.

Workshops and advisory that translate cyber and AI risk into decisions — KRIs, KCIs and reporting that executives actually use.

  • Board & executive workshops
  • KRI / KCI design
  • Risk appetite & control objectives
  • Bid and tender strategy

What you get

Deliverables built for decisions.

Examples of the outputs behind the services above. Data shown is illustrative.

Risk you can see shrink

Findings translated into a likelihood × consequence picture, showing how each recommended control moves the risk. Toggle the view to see the shift.

Illustrative example
Likelihood → Consequence →
L · Low M · Medium H · High E · Extreme
  1. R1 Prompt injection in AI agents Extreme Medium
  2. R2 Shadow AI & unsanctioned tools High Low
  3. R3 Third-party model data leakage High Medium
  4. R4 Ransomware across IT/OT High Low
  5. R5 Privileged access misuse High Low
  6. R6 Unpatched systems (ISM controls) Extreme Medium

Every layer of your AI stack

AI risk runs from the people prompting a model down to the suppliers hosting it. Each layer is assessed with its own threats and controls.

  1. 01

    People & process

    Threats

    • Over-reliance on outputs
    • Shadow AI use

    Controls

    • AI use policy
    • Human oversight
  2. 02

    Apps & agents

    Threats

    • Prompt injection
    • Excessive agency

    Controls

    • Tool allowlisting
    • Least privilege
  3. 03

    Models

    Threats

    • Model theft
    • Insecure output handling

    Controls

    • Model inventory
    • Output validation
  4. 04

    Data & pipelines

    Threats

    • Training data poisoning
    • Sensitive data disclosure

    Controls

    • Data provenance
    • DLP & classification
  5. 05

    Suppliers & infra

    Threats

    • Third-party model risk
    • Supply chain compromise

    Controls

    • Supplier assurance
    • ISM security controls

One program, many frameworks

A unified control set mapped across AI, security and critical-infrastructure obligations, with maturity tracked against a clear target.

Current state Target state
Illustrative
AI governance maturity, current versus target Governance: current 2, target 4; Risk & impact: current 1.5, target 4; Data: current 3, target 4; Model security: current 1.5, target 3.5; Supply chain: current 2, target 4; Monitoring: current 2.5, target 4 (scale 0 to 5). 12345 GovernanceRisk & impactDataModel securitySupply chainMonitoring
Average uplift target: +1.8 maturity levels across six domains.
Strong coverage Partial Limited
Indicative mapping
Indicative coverage of control themes across frameworks
Control themeISO 42001ISMNIST 800-53ISO 27001SOCI
Governance & accountability Strong Strong Strong Strong Strong
Risk & impact assessment Strong Strong Strong Strong Strong
Access & privilege Partial Strong Strong Strong Partial
Supplier & supply chain Strong Strong Strong Strong Strong
AI data quality & bias Strong Limited Limited Limited Limited
Incident response & recovery Partial Strong Strong Strong Strong
Monitoring & improvement Strong Strong Strong Strong Strong

How we'll work

A clear path, every time.

  1. 01

    Discover

    Scope, context and obligations — what you must meet, and what matters to your mission.

  2. 02

    Assess

    Evidence-based review through workshops, walkthroughs and artefact analysis.

  3. 03

    Prioritise

    A risk-ranked, cost-aware roadmap that leverages what you already have.

  4. 04

    Uplift

    Hands-on support to close gaps, plus Board-ready reporting on progress.