How we work
Straight advice, clear reasoning and no blurred responsibilities.
A good advisor should help your team make a sound decision and move on with the work.
We will explain what we know, what still needs checking and where the final responsibility sits. If another type of security service is a better fit, we will say so.
- More than 20 years' experience per consultant
- ISC2-certified
- HRD Corp accredited trainers
- Your work stays with a senior consultant
- 01Break
- 02Build
- 03Defend
- 04Fix
Experience behind the advice
The person on the call has done the work.
Our current retained work includes advising a regional dive-tourism operator. Every engagement is handled directly by a senior consultant.
- 20+ years
More than two decades spent doing the work, across offensive security, defence and remediation.
- ISC2-certified
Recognised professional certification, backed by practical technical experience.
- HRD Corp accredited
Accredited trainers who can explain the reasoning and help your team build capability.
- Senior-led
The consultant reviewing your issue is the person you speak to. Your work is not passed down to a junior team.
Operating principles
How we expect an advisory relationship to work.
- 01
Senior-led advisory
You deal directly with an experienced consultant who can make and explain the call.
- 02
Offensive and defensive perspective
We consider how a system may be attacked, how it will be defended and what happens if a control fails.
- 03
Practical recommendations
Recommendations are written for the engineers, IT owners and managers who need to act on them.
- 04
Clear scope boundaries
We agree what is included, what remains with your team and what needs a separate quotation.
- 05
Confidentiality-first approach
We ask only for the information needed and handle sensitive technical material carefully.
- 06
Human judgement and technical validation
We use evidence and the realities of your environment, not a checklist on its own.
Choosing the right service
A retainer is useful only when it matches the job.
Technical advisory, vCISO work, monitoring, pentesting and IT support are different services. You may need more than one, but each should have a clear owner and scope.
| Scope | Technical advisory | vCISO | SOC / MDR | Pentest | IT helpdesk |
|---|---|---|---|---|---|
| Primary focus | Technical decisions about applications, cloud, infrastructure, findings and remediation | Security leadership, governance, business risk and programme direction | Security monitoring, investigation and managed response | Point-in-time security testing against an agreed scope | Day-to-day user, device, software, and IT operations support |
| Engagement model | Recurring access to a senior technical advisor | Fractional or retained security leadership | Ongoing managed security service | Time-bound assessment or testing project | Ongoing support service or ticket-based engagement |
| Operational monitoring | Can review monitoring coverage and readiness; does not operate a 24/7 SOC | Sets direction and holds internal teams or providers accountable | Operates continuous monitoring and response workflows | Not normally included | Monitors IT service health where contracted, not security operations |
| Testing | Challenges designs and reviews findings; formal testing needs a separate scope | Commissions testing and oversees assurance work | Tests detections and response within the managed service | Performs formal offensive testing and reports findings | Tests changes and operational fixes within IT support scope |
| Governance | Explains technical risk and supports specific decisions | Leads governance, policy, compliance, and executive reporting | Provides operational security reporting and service governance | Provides assessment evidence for risk and assurance processes | Provides service management and operational records |
| Implementation | Advises on fixes and reviews the result; delivery owners make production changes | Directs programmes and follows up with accountable owners | Implements and tunes controls within the managed platform scope | Usually recommends fixes rather than implementing them | Implements supported IT changes and routine administration |
| Best fit | Teams that regularly face technical security questions without a senior specialist in-house | Organisations that need part-time security leadership and programme ownership | Organisations needing continuous detection and managed response capacity | Organisations needing an independent assessment of a defined target | Organisations needing reliable day-to-day IT support |
Not sure whether technical advisory is the right service?
Share the decision or problem you are dealing with. We will help you identify the right type of support, even if it is not ours.