Technical advisory services

Practical security advice for the systems you build and run.

We help your technical owners work through difficult security questions, from attack paths and architecture to hardening and remediation.

The retainer covers advice, review and decision support. Monitoring, formal testing and hands-on implementation are separate work.

  • More than 20 years' experience per consultant
  • ISC2-certified
  • HRD Corp accredited trainers
  • Your work stays with a senior consultant
  1. 01Break
  2. 02Build
  3. 03Defend
  4. 04Fix

What retained advisory means

You do not have to start from zero each time.

Because we work with you month to month, we learn the systems, people and constraints behind the question. That makes it easier to give useful advice when something new comes up. Your team still owns its systems, operations and implementation.

Service pillars

Break. Build. Defend. Fix.

These are the four angles we use to examine a technical security issue. A real client question often touches more than one.

01

Break

We look at the system as an attacker would and separate credible attack paths from theoretical noise.

  • Exploitability assessment
  • Attack paths
  • Abuse cases
  • Pentest triage
  • Vulnerability validation
  • Attacker review

02

Build

We challenge application, API, cloud and identity decisions before they become costly to change.

  • Application security
  • API security
  • Architecture review
  • Authentication and authorisation
  • Secure SDLC
  • CI/CD security
  • Cloud design

03

Defend

We review whether hardening, monitoring and recovery arrangements will hold up under a realistic incident.

  • Hardening
  • Identity
  • Logging and monitoring guidance
  • Detection readiness
  • Ransomware resilience
  • Backups
  • M365, cloud, and infrastructure defense

04

Fix

We turn findings into an ordered fix plan that the responsible teams can understand and deliver.

  • Triage
  • Remediation guidance
  • Compensating controls
  • Risk priority
  • Retest guidance
  • Monthly tracking
  • Practical recommendations

What happens when you raise a question

  1. Send us the question, design, finding or concern.

  2. We check the context and ask for anything material that is missing.

  3. We work out the realistic exposure, impact and control gaps.

  4. We explain the options and recommend a practical course of action.

  5. We record agreed actions and follow up during the monthly cycle.

Scope boundaries

What is part of the retainer, and what is not.

Covered by the retainer

  • Scheduled technical advisory sessions
  • Questions through the agreed client channel
  • Triage of findings and remediation options
  • Review of agreed designs, controls or technical documents
  • A written record of priorities, owners and next steps

Not covered by the retainer

  • 24/7 monitoring, alert handling or managed detection and response
  • Formal penetration testing, red teaming or a full source-code audit
  • Emergency incident response, forensic investigation or malware analysis
  • Certification, auditor sign-off or a guarantee that an audit will pass
  • Helpdesk support or making changes directly in production
  • Unlimited reviews, unlimited response time or a guarantee that no breach will occur

Need one of the excluded services? We can help define the requirement or quote it separately where appropriate, subject to consultants' availability. Nothing starts until the scope, fee and responsibilities are agreed in writing.

Bring us the question that is slowing the team down.