How we work

Straight advice, clear reasoning and no blurred responsibilities.

A good advisor should help your team make a sound decision and move on with the work.

We will explain what we know, what still needs checking and where the final responsibility sits. If another type of security service is a better fit, we will say so.

  • More than 20 years' experience per consultant
  • ISC2-certified
  • HRD Corp accredited trainers
  • Your work stays with a senior consultant
  1. 01Break
  2. 02Build
  3. 03Defend
  4. 04Fix

Experience behind the advice

The person on the call has done the work.

Our current retained work includes advising a regional dive-tourism operator. Every engagement is handled directly by a senior consultant.

  • 20+ years

    More than two decades spent doing the work, across offensive security, defence and remediation.

  • ISC2-certified

    Recognised professional certification, backed by practical technical experience.

  • HRD Corp accredited

    Accredited trainers who can explain the reasoning and help your team build capability.

  • Senior-led

    The consultant reviewing your issue is the person you speak to. Your work is not passed down to a junior team.

Operating principles

How we expect an advisory relationship to work.

  1. 01

    Senior-led advisory

    You deal directly with an experienced consultant who can make and explain the call.

  2. 02

    Offensive and defensive perspective

    We consider how a system may be attacked, how it will be defended and what happens if a control fails.

  3. 03

    Practical recommendations

    Recommendations are written for the engineers, IT owners and managers who need to act on them.

  4. 04

    Clear scope boundaries

    We agree what is included, what remains with your team and what needs a separate quotation.

  5. 05

    Confidentiality-first approach

    We ask only for the information needed and handle sensitive technical material carefully.

  6. 06

    Human judgement and technical validation

    We use evidence and the realities of your environment, not a checklist on its own.

Choosing the right service

A retainer is useful only when it matches the job.

Technical advisory, vCISO work, monitoring, pentesting and IT support are different services. You may need more than one, but each should have a clear owner and scope.

A practical comparison of technical advisory and other common security services
ScopeTechnical advisoryvCISOSOC / MDRPentestIT helpdesk
Primary focusTechnical decisions about applications, cloud, infrastructure, findings and remediationSecurity leadership, governance, business risk and programme directionSecurity monitoring, investigation and managed responsePoint-in-time security testing against an agreed scopeDay-to-day user, device, software, and IT operations support
Engagement modelRecurring access to a senior technical advisorFractional or retained security leadershipOngoing managed security serviceTime-bound assessment or testing projectOngoing support service or ticket-based engagement
Operational monitoringCan review monitoring coverage and readiness; does not operate a 24/7 SOCSets direction and holds internal teams or providers accountableOperates continuous monitoring and response workflowsNot normally includedMonitors IT service health where contracted, not security operations
TestingChallenges designs and reviews findings; formal testing needs a separate scopeCommissions testing and oversees assurance workTests detections and response within the managed servicePerforms formal offensive testing and reports findingsTests changes and operational fixes within IT support scope
GovernanceExplains technical risk and supports specific decisionsLeads governance, policy, compliance, and executive reportingProvides operational security reporting and service governanceProvides assessment evidence for risk and assurance processesProvides service management and operational records
ImplementationAdvises on fixes and reviews the result; delivery owners make production changesDirects programmes and follows up with accountable ownersImplements and tunes controls within the managed platform scopeUsually recommends fixes rather than implementing themImplements supported IT changes and routine administration
Best fitTeams that regularly face technical security questions without a senior specialist in-houseOrganisations that need part-time security leadership and programme ownershipOrganisations needing continuous detection and managed response capacityOrganisations needing an independent assessment of a defined targetOrganisations needing reliable day-to-day IT support

Not sure whether technical advisory is the right service?

Share the decision or problem you are dealing with. We will help you identify the right type of support, even if it is not ours.