Security programme management
Structuring and management of a multi-year security programme: roadmap, milestone tracking, coordination of internal and external stakeholders, reporting to management. We manage coordination complexity so you can focus on decisions.
Infrastructure redesign
Security-focused support for infrastructure redesign: target architecture design, technical choice review, risk identification during the project phase, security validation before production cutover.
Secure development
Integration of security practices into your software development lifecycle: security requirements definition, design review, security testing in CI/CD pipelines, developer training in secure coding practices.
Remediation
Management of vulnerability remediation following an audit or incident. Prioritisation of actions, coordination with technical teams, tracking closure of identified findings and verification of fix effectiveness.
SOC project
Scoping and management of a security operations centre build-out: use case definition, data source selection, writing of operational procedures and analyst runbooks, support for team upskilling.
CERT / CSIRT project
Construction or structuring of an incident response capability: charter, qualification and escalation processes, relationships with national and sectoral CERTs, tooling, simulation exercises. We can provide operational interim support during the ramp-up phase.