Services

Security services built around real business risk.

Practical security, assurance and risk consultancy to help you understand and manage risk, meet security requirements and make informed decisions.

01 · Supplier Assurance

Supplier Security Assurance

Independent security assurance throughout the supplier lifecycle.

We help organisations understand and manage the security risks associated with third parties, from initial procurement and due diligence through to ongoing assurance and supplier audits.

  • Pre-procurement security assessments
  • Supplier security questionnaires and due diligence
  • Supply chain risk assessments
  • Supplier audits and assurance reviews
  • Definition of security requirements and schedules
  • Review of Security Management Plans
  • Assessment of supplier security controls
  • Cloud and third-party security assurance
  • Advice to commercial, procurement and risk owners
02 · Risk

Information Security & Risk

Practical security and risk management that supports informed decision-making.

We help organisations identify, assess and manage information security risks, providing practical advice and assurance that supports business objectives and regulatory requirements.

  • Security risk assessments
  • Supply chain risk assessments
  • Risk treatment plans
  • Executive risk summary reporting
  • Security strategies and methodologies
  • Policies, processes and procedures
  • Governance and assurance
  • ISO 27001 implementation support
  • Secure by Design (SbD) reviews
  • NCSC CAF assessments
  • Data Privacy Impact Assessments
03 · Procurement

Procurement & Tender Security

Build security into procurement from the outset.

We help procurement and commercial teams translate security requirements into clear, measurable tender requirements and assess supplier responses against them.

  • Security requirements and tender schedules
  • Security criteria and evaluation methodology
  • Tender response evaluation
  • Identification of security gaps and exceptions
  • Security clarification questions
  • Advice to procurement and commercial teams
04 · Cloud

Cloud Security

Independent assurance of cloud services and products.

We assess the security posture of cloud suppliers and evaluate cloud-based products and services, including SaaS applications, helping organisations understand security risks before they adopt or procure them.

  • Cloud supplier security assessments
  • SaaS product and application security evaluations
  • Assessment against the NCSC Cloud Security Principles
  • Cloud security assurance
  • Data location and offshore security reviews
  • Security architecture and control reviews
  • Identification and assessment of security risks and gaps
  • Security requirements and recommendations
05 · Governance

Security Governance & Compliance

Build effective security governance and demonstrate assurance.

We help organisations establish practical security governance, policies and assurance arrangements that support recognised standards, regulatory requirements and business objectives.

  • Security governance frameworks
  • Security policies, standards and procedures
  • Security control frameworks
  • Compliance and maturity assessments
  • ISO 27001 governance and assurance
  • NIS2 readiness and security requirements
  • Security assurance activities
  • Management reporting and governance support
06 · Incident Support

Incident & Assurance Support

Independent security support when you need it.

We provide practical security support during incidents and assurance activities, helping organisations understand whether security controls and supplier obligations are working as intended.

  • Security incident support
  • Post-incident audits of control effectiveness
  • Review of contractual security requirements
  • Assessment of supplier security controls
  • Review of Security Management Plans and supplier policies
  • Security assurance and remediation advice
  • Independent security advice