(C) Security Consulting
A sounding board for the decisions that are expensive to get wrong.
On-call access to senior offensive security expertise: architecture reviews, threat models, and roadmaps from people who spend the rest of their week breaking systems like yours.
Who this is for
You do not need another headcount. You need a second opinion you can trust.
Most of our consulting clients have capable teams already. What they lack is someone senior, external, and unpolitical to pressure-test a decision before it ships.
CISOs
Specialised input across fast-moving projects, without adding a permanent hire or a large consultancy retainer.
CTOs & Heads of Engineering
A security-first lens on product architecture early enough that fixing it is still cheap.
Security Managers
Extra senior bandwidth to scale a programme when the team is already at capacity.
Founders & startups
Getting audit-ready, answering enterprise security questionnaires, or surviving funding due diligence.
Services
Five things we are repeatedly asked for.
01
Architecture & design review
1–2 WEEKS
We read your designs and diagrams the way an attacker would, then walk your engineers through where the trust boundaries actually sit versus where you assumed they did. Best done before build, not after.
Deliverable
Annotated findings against your architecture, with prioritised design changes
02
Threat modeling
1–2 WEEKS
A structured workshop mapping assets, entry points, and abuse cases for a specific system or feature, then a written model your team can maintain and reuse rather than rebuild each quarter.
Deliverable
Threat model document, abuse-case register, and a workshop your team can re-run
03
Risk assessment
2–3 WEEKS
Where your real exposure is, ranked by likelihood and business impact rather than by scanner severity. Includes the awkward finding about the system nobody owns.
Deliverable
Risk register with owners, ratings, and recommended treatment
04
Security roadmap & planning
2–4 WEEKS
A programme you can actually fund and staff, sequenced against your growth plans and risk appetite. Written so it survives contact with a budget conversation.
Deliverable
12–18 month roadmap with sequencing, budget framing, and success measures
05
Second brain for your CISO/CTO
ONGOING
On-call access for the decisions that do not warrant a project: vendor assessments, incident questions, board-paper review, or simply testing an assumption before you commit to it.
Deliverable
Named consultant, agreed response time, written summaries of each decision
How we engage
Three models. Pick the one that fits your cadence.
All three are fixed-fee and fully confidential under mutual NDA. Unused hours in a retainer roll forward one quarter.
MODEL 01
Fixed-scope project
A defined piece of work with a start, an end, and a written deliverable. Quoted as a fixed fee from scope.
·Written scope before signature
·Fixed fee, no day-rate creep
·Deliverable plus live walkthrough
BEST FOR: A SPECIFIC REVIEW OR THREAT MODEL
MODEL 02
On-call hours
A block of senior hours drawn down as you need them, across whatever comes up that quarter.
·Blocks from 10 hours upward
·Named consultant, agreed SLA
·Unused hours roll forward one quarter
BEST FOR: CONTINUOUS, UNPREDICTABLE DEMAND
MODEL 03
Fractional advisory
A recurring monthly commitment: regular reviews, board-paper input, and programme oversight.
·Fixed monthly fee
·Monthly review cadence
·Board and audit support included
BEST FOR: TEAMS WITHOUT A FULL-TIME CISO
Terms & assurances
What you are signing up to.
CONFIDENTIALITY
Mutual NDA before any material is shared. We do not name consulting clients publicly, ever, not even as a logo.
INDEPENDENCE
We sell no products and take no vendor commissions, so a recommendation is never a resale.
WHO YOU GET
A named senior consultant holding CISSP and OSCP. Not a delivery pod, not a rotating bench.
CONFLICT OF INTEREST
If we have consulted on a system, we will tell you before also pentesting it, so you can choose an independent tester.
Start with a call. No pitch deck.
Thirty minutes with a senior consultant to work out whether we are useful to you. If we are not, we will tell you.