Know what to protect. Know what to tackle first.
We review your systems, information and existing security work, then turn the findings into practical priorities that fit your business.
Services
- 01
Asset Registry Setup
Records are scattered, making it hard to see which systems and information the business relies on.
What changesA usable record of your systems and information, with clear ownership.
What we deliverAsk about this service: Asset Registry Setup- A populated register of the systems, devices, services and information within the agreed scope.
- Key details for each entry, including its purpose, owner, location and business importance.
- A simple process for keeping the register current as the business changes.
- 02
Risk Assessment Workshop
You need to assess security concerns against how the business actually works.
What changesA shared view of what could go wrong, how it would affect the business and which risks deserve attention.
What we deliverView service: Risk Assessment Workshop- A focused workshop covering important systems, information, existing protections and possible security incidents.
- A risk register with agreed criteria for assessing likelihood and business impact.
- A findings summary with initial priorities, assumptions and questions that need follow-up.
- 03
Risk Treatment Plan
You know the risks, but the actions, ownership and timing still need to be worked through.
What changesClear actions for the risks you choose to address, with owners and a realistic sequence.
What we deliverAsk about this service: Risk Treatment Plan- Options for handling each agreed risk, with the costs and tradeoffs explained.
- A treatment plan with actions, proposed owners, dependencies and target dates.
- A record of agreed decisions, remaining risks and when to review them.
- 04
Control Baseline Definition
You need consistent security practices that fit the business and are realistic to maintain.
What changesA clear set of minimum protections, so teams and suppliers know what is expected.
What we deliverAsk about this service: Control Baseline Definition- An agreed set of security requirements based on your risks, customer expectations and existing practices.
- Plain descriptions of each required protection and where it should apply.
- A record of gaps, responsibilities, exceptions and review dates.
- 05
Business Impact Analysis
You need to know how disruption would affect customers, revenue and daily work.
What changesRecovery priorities based on business impact, with clear limits on how long key activities can be disrupted.
What we deliverView service: Business Impact Analysis- A review of essential business activities and how the impact of disruption grows over time.
- A record of the people, information, systems and suppliers those activities depend on.
- Agreed recovery priorities and target timeframes for checking against your technical recovery plans.
- 06
Critical Systems Mapping
The business relies on connected systems, but those dependencies are not recorded in one place.
What changesA clear map of the systems behind essential work, so key dependencies are easier to protect.
What we deliverAsk about this service: Critical Systems Mapping- A list of the systems that support your essential business activities.
- A map of their key connections, information flows and external dependencies.
- Named owners, known dependency risks and gaps to investigate.
- 07
Security Risk Prioritization Sprint
Security findings keep adding up, while time and budget stay limited.
What changesA manageable order for the work, with urgent risks separated from improvements that can wait.
What we deliverView service: Security Risk Prioritization Sprint- A review of existing findings, recommendations and work already planned or underway.
- A ranked improvement list based on business impact, urgency, effort and dependencies.
- A focused set of next steps, with the reasons for priorities and deferred work recorded.
- 08
Information Classification Starter
Your team needs a clear way to decide what information can be shared, and with whom.
What changesSimple information categories and handling rules your team can use in daily work.
What we deliverAsk about this service: Information Classification Starter- A small set of information categories based on sensitivity and business impact.
- Practical rules for access, sharing, storage and disposal, with examples from your business.
- An initial classification of agreed information types, with owners and a guide for applying the approach.
Know what to expect before we start.
We agree scope, pricing and timing before work begins, then take responsibility for the agreed work and keep you informed.
The agreed reviews, workshops and documentation, with clear findings and practical next steps.
Your priorities, access to relevant information and people, and approval of decisions that affect the business.
What do you need
taken care of?
An informal 30-minute call to discuss your needs and see how we could work together.