Advisory
When nobody senior owns security.
Sometimes the gap is not a control, it is that nobody is accountable. This is the work of standing in that role: setting direction, answering the board, and making the calls that need making.
What is included
- Virtual CISO (vCISO)
- Fractional security leadership for organisations without a full-time security executive: strategy, programme governance, board reporting, vendor management.
- M&A security due diligence
- Technical security due diligence for acquisitions and investments: posture assessment, hidden liabilities, remediation cost, post-acquisition planning.
- Compliance gap analysis
- Structured assessment against regulatory requirements and industry frameworks, with a prioritised remediation roadmap.
- Cyber insurance readiness
- Preparation for cyber insurance applications and renewals through control assessment, evidence gathering and gap remediation.
Who this is for
Companies too small for a full-time CISO but too exposed to have nobody. Acquirers who need to know what they are buying. Teams preparing for a cyber insurance renewal.