For the CISO
Evidence you can take to a board without translation, and a posture measurement that moves between quarters.
What you receive
- Quarterly board pack in plain language
- Posture trend measurement
- Peer-sector benchmark
- Budget-case support
When you need this
Three situations that call for it. If none of them is yours, it probably is not the right spend.
Your first board paper is due in six weeks
You inherited a control estate you did not choose and a risk register written to survive an audit rather than to inform a decision. This produces a baseline that can be defended in a room that will not read a heat map, and a second measurement to compare it against.
The board asks whether it could happen here
A named breach in your sector has made cyber a standing agenda item, and nobody in the room can honestly answer the question. We test the path that attack actually used against your own estate and report what held, what did not, and how sure we are of each.
Your budget ask was cut and you must re-ask
Security loses budget arguments because it is presented as insurance against something that has not happened yet. Two measurements taken two quarters apart turn the ask into a delta rather than a warning — what moved, what did not, and what the last round of funding bought. A finance director can interrogate that and still refuse it.
How it runs
Where you actually are
A working session to establish what is already in place and what your regulator, your auditor or your board is going to ask for. Usually the gap is narrower than feared and differently shaped.
What the obligation really requires
We separate what the text mandates from what a consultancy has told you it mandates. Several of the controls sold against these regimes are not required by them.
A scoped programme
The specific modules and engagements that close the gap, sequenced by what your deadline is and what depends on what — not by what is easiest to sell you.
Evidence, not a gap report
The output is the artefact your assessor accepts: test results, control evidence and a record of what changed. A document describing your gaps is not evidence that you closed them.
No lock-in
Scoping costs nothing and carries no obligation. If the answer is that you do not need this, that is a legitimate outcome of the call.
Who turns up
The engineer on your scoping call is on the delivery team. We do not hand you to a different group after signature.
Scope
What this does not cover
We do not act as your CISO or sign off risk decisions on your behalf — the accountability stays with the person the regulation names.
Certification audits are not included; ISO 27001 and PCI DSS readiness sits in a separate engagement under By mandate.
Awareness and phishing training programmes are not part of this; social engineering testing is bought separately under Services.
- NIS2 Directive (EU) 2022/2555, Art. 20
- Management bodies must approve the risk-management measures, oversee implementation, and can be held liable for failing to.
- ISO/IEC 27001:2022 Clause 9.3
- Top management must review the ISMS at planned intervals using measurement results, not verbal assurance from the security team.
- DORA Regulation (EU) 2022/2554, Art. 5
- The management body of a financial entity holds ultimate responsibility for ICT risk and must keep itself current on it.
If the scope is wrong
Tell us on the call. Re-scoping before we start costs nothing; discovering it at the readout costs you the engagement.
Questions
The ones we are actually asked.
Will the board pack say that we are secure?
No — that is not a sentence an honest report can contain. It states what was tested, what was found, our confidence in each finding, and what moved since the previous measurement, which is a thing a board can act on.
Is a posture score not just an invented number?
Every score is a model, ours included. What matters is whether you can see the method and the inputs behind it — we will walk you through the calculation rather than ask you to trust a dial, and if the weighting is wrong for your estate we would rather change it than defend it.
Can you present this to the board yourselves?
Yes, and it is often better if we do — awkward questions land differently when the person answering does not report to the audit committee. We will not present a figure we cannot defend line by line.
See what an attacker sees
We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.
30 min
A scoping call, with an engineer rather than a sales rep.
What it costs
Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.
Under attack now?
Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.