SOC status:Duty analyst on shift

UK Cyber Defence

Consulting · Compliance · Engineering · Incident readiness

Practical work,clear deliverables.

Gap assessments, programmes, engineering and exercises delivered by practitioners who also run a SOC and test systems for a living. Every engagement ends with something you can use: a plan, a policy set, a hardened configuration, a report, a rehearsed team.

ISO 27001NIS2 · DORA · PCI DSSSecurity engineeringTabletop exercises

01Approach

Engineering for resilience, not just for the audit.

Compliance checklists describe a defensible environment; they do not create one. Our consulting work is grounded in what our SOC and incident responders see real adversaries do — commodity malware, targeted identity compromise, cloud misconfiguration abuse, lateral movement — and it produces changes that hold up under that pressure. Engagements run as one-off projects, targeted uplifts or multi-month programmes alongside your own teams.

Compliance
ISO 27001 · NIS2 · DORA · PCI DSS 4.0 · NIST CSF · Cyber Essentials
Engineering
Identity · Cloud · Segmentation · Endpoint and EDR · OT/IoT · Logging
Readiness
IR plans · Playbooks · Tabletop exercises · Forensic readiness
Commercials
Fixed price for defined work; day rate for advisory

Engagements

What we deliver

01

ISO 27001 programme

From gap assessment to certification, with an ISMS built to be maintained rather than admired.

02

NIS2 and DORA readiness

Scope, gap, roadmap and evidence for organisations in or supplying the regulated sectors.

03

PCI DSS 4.0

Scoping, gap analysis and the monitoring evidence retailers and payment environments now need.

04

Identity security uplift

Microsoft 365 and Entra ID hardening, privileged access, MFA and conditional access, identity lifecycle and administrative boundaries.

05

Cloud security uplift

Azure, AWS and hybrid cloud reviewed and hardened: IAM, networking, storage, Key Vault, policies and workload controls.

06

Segmentation and Zero Trust

Separation between IT, OT, cloud and user environments; secure remote access with device trust and conditional access.

07

SOC visibility and logging

A defensible telemetry architecture — Sysmon, audit policies, EDR tuning, cloud-native logging — so detection actually has something to work with.

08

OT and IoT security

Mapping and segmenting industrial networks, securing engineering workstations and monitoring legacy systems that cannot be patched.

09

Incident response planning

Plans and playbooks written for the people who will use them at 2 a.m., with forensic readiness so evidence survives the first hour.

10

Tabletop exercises

Board-level and technical scenarios, facilitated, scored and reported. Regulator-aligned for financial services.

11

Security architecture review

A second opinion on designs, migrations and the thing the vendor is trying to sell you.

12

Supplier and M&A due diligence

Fast, structured assessments when the deadline is a deal.

How we work

With your teams, not around them

  1. _01Engineering workshopsHands-on sessions to review architecture, identify gaps and design remediation that fits how you operate.Design
  2. _02Pairing sessionsWorking directly with your engineers to configure systems, validate changes and apply baselines.Build
  3. _03Documentation and standardsBaselines, configuration templates and reference architectures tailored to your environment.Keep
  4. _04Operational playbooksIdentity, cloud, endpoint and OT playbooks that support SOC and incident response workflows.Run
  5. _05Continuous improvementRegular reviews of posture, attack paths and detections based on real adversary behaviour.Improve

Questions

Do you only work with regulated organisations?

No. Regulated firms have the sharpest deadlines, but most of our consulting clients simply want to be able to answer a customer's security questionnaire with confidence.

Fixed price or day rate?

Fixed price for defined engagements such as a gap assessment, an uplift project or an exercise; day rate for open-ended advisory work.

Can you implement as well as advise?

Yes. The same engineers who design the change can pair with your team to make it, and our SOC can then confirm the telemetry is arriving.

Start a conversation

Describe the deadline. We will describe the plan.