Service 02 · Cybersecurity

Security work,
scoped to the risk.

We help organizations assess, harden, and monitor their environments — from identity and access through endpoint, network, and application security — with the documentation auditors and oversight bodies expect to see.

What we do

We treat security as a program, with documentation to match.

Assessments & audits

Risk assessments, control reviews, and gap analyses against recognized frameworks — with findings written for remediation, not just compliance binders.

Identity & access management

Directory consolidation, SSO, MFA, and privileged access — built around the roles and joiner/mover/leaver realities of the organization.

Endpoint & network security

EDR, patch hygiene, segmentation, and zero-trust network design — implemented for the environments that actually exist, not idealized ones.

SIEM, monitoring & detection

Log aggregation, detection engineering, and alert triage — tuned so the signal reaches the right humans at the right time.

Incident response, BC/DR & recovery

Tabletop exercises, incident-response playbooks, and business continuity / disaster recovery planning — paired with hands-on response when something is actually happening, plus post-incident writeups that feed back into controls.

Policy, governance & training

Written policies, control mappings, and role-appropriate awareness training — calibrated to what the organization will actually operate and enforce.

Who it's for

Built around two kinds of buyers, with different constraints.

State & local government

Agencies operating under state or federal cybersecurity and data-handling mandates — working to the control baselines and audit obligations their environment requires.

  • Works to agency control baselines and audit obligations.
  • Supports multi-entity environments and shared service models.
  • Documents findings and controls for oversight review.
  • Transitions operational ownership to internal security teams.

Enterprise clients

Organizations with an existing security function that need specialist support — assessments, IR capacity, program build-out, or named roles to extend the team.

  • Integrates with existing GRC, SOC, and IT operations processes.
  • Works alongside tool vendors and MSSPs where relevant.
  • Flexes between advisory, assessment, and hands-on engineering.
  • Leaves playbooks and documentation the team can operate from.

Security assessment, program, or response?

Share the scope, the framework, or a short summary of where you are. We'll reply within one business day.