Let's talk
Security Review & Risk Assessment

Know what to protect. Know what to tackle first.

We review your systems, information and existing security work, then turn the findings into practical priorities that fit your business.

Services

  1. 01

    Asset Registry Setup

    Records are scattered, making it hard to see which systems and information the business relies on.

    What changes

    A usable record of your systems and information, with clear ownership.

    What we deliver
    • A populated register of the systems, devices, services and information within the agreed scope.
    • Key details for each entry, including its purpose, owner, location and business importance.
    • A simple process for keeping the register current as the business changes.
    Ask about this service: Asset Registry Setup
  2. 02

    Risk Assessment Workshop

    You need to assess security concerns against how the business actually works.

    What changes

    A shared view of what could go wrong, how it would affect the business and which risks deserve attention.

    What we deliver
    • A focused workshop covering important systems, information, existing protections and possible security incidents.
    • A risk register with agreed criteria for assessing likelihood and business impact.
    • A findings summary with initial priorities, assumptions and questions that need follow-up.
    View service: Risk Assessment Workshop
  3. 03

    Risk Treatment Plan

    You know the risks, but the actions, ownership and timing still need to be worked through.

    What changes

    Clear actions for the risks you choose to address, with owners and a realistic sequence.

    What we deliver
    • Options for handling each agreed risk, with the costs and tradeoffs explained.
    • A treatment plan with actions, proposed owners, dependencies and target dates.
    • A record of agreed decisions, remaining risks and when to review them.
    Ask about this service: Risk Treatment Plan
  4. 04

    Control Baseline Definition

    You need consistent security practices that fit the business and are realistic to maintain.

    What changes

    A clear set of minimum protections, so teams and suppliers know what is expected.

    What we deliver
    • An agreed set of security requirements based on your risks, customer expectations and existing practices.
    • Plain descriptions of each required protection and where it should apply.
    • A record of gaps, responsibilities, exceptions and review dates.
    Ask about this service: Control Baseline Definition
  5. 05

    Business Impact Analysis

    You need to know how disruption would affect customers, revenue and daily work.

    What changes

    Recovery priorities based on business impact, with clear limits on how long key activities can be disrupted.

    What we deliver
    • A review of essential business activities and how the impact of disruption grows over time.
    • A record of the people, information, systems and suppliers those activities depend on.
    • Agreed recovery priorities and target timeframes for checking against your technical recovery plans.
    View service: Business Impact Analysis
  6. 06

    Critical Systems Mapping

    The business relies on connected systems, but those dependencies are not recorded in one place.

    What changes

    A clear map of the systems behind essential work, so key dependencies are easier to protect.

    What we deliver
    • A list of the systems that support your essential business activities.
    • A map of their key connections, information flows and external dependencies.
    • Named owners, known dependency risks and gaps to investigate.
    Ask about this service: Critical Systems Mapping
  7. 07

    Security Risk Prioritization Sprint

    Security findings keep adding up, while time and budget stay limited.

    What changes

    A manageable order for the work, with urgent risks separated from improvements that can wait.

    What we deliver
    • A review of existing findings, recommendations and work already planned or underway.
    • A ranked improvement list based on business impact, urgency, effort and dependencies.
    • A focused set of next steps, with the reasons for priorities and deferred work recorded.
    View service: Security Risk Prioritization Sprint
  8. 08

    Information Classification Starter

    Your team needs a clear way to decide what information can be shared, and with whom.

    What changes

    Simple information categories and handling rules your team can use in daily work.

    What we deliver
    • A small set of information categories based on sensitivity and business impact.
    • Practical rules for access, sharing, storage and disposal, with examples from your business.
    • An initial classification of agreed information types, with owners and a guide for applying the approach.
    Ask about this service: Information Classification Starter
Working together

Know what to expect before we start.

We agree scope, pricing and timing before work begins, then take responsibility for the agreed work and keep you informed.

We take care of

The agreed reviews, workshops and documentation, with clear findings and practical next steps.

Your input

Your priorities, access to relevant information and people, and approval of decisions that affect the business.

Get in touch

What do you need
taken care of?

An informal 30-minute call to discuss your needs and see how we could work together.