For IT & Infrastructure
Consolidate overlapping tooling and stop paying for alerts nobody has time to read.
What you receive
- Tooling consolidation assessment
- Alert volume reduction programme
- Runbook and automation build
- Out-of-hours coverage
When you need this
Three situations that call for it. If none of them is yours, it probably is not the right spend.
The SIEM renewal quote arrived and doubled
Log volume grows with the estate, licensing is priced on it, and renewal is the first moment anyone asks what the ingest is for. The assessment separates logs that feed a detection from logs nobody has queried in a year, so the cut is made against use rather than against volume. Tiering and filtering at the collector move the same bill without forcing that decision.
Two engineers left and the rota has gaps
Out-of-hours cover built on goodwill fails quietly — the alert fires, someone reads it at nine the next morning, and the dwell time is a whole night. Runbooks and covered hours move the decision to the moment it happens rather than to the standup.
You now run two of every security tool
A migration, an acquisition or a change of platform leaves duplicated agents, overlapping coverage and two consoles describing one event. Consolidation starts by proving which tool sees what, so the one you switch off is the one you can afford to lose.
How it runs
Where you actually are
A working session to establish what is already in place and what your regulator, your auditor or your board is going to ask for. Usually the gap is narrower than feared and differently shaped.
What the obligation really requires
We separate what the text mandates from what a consultancy has told you it mandates. Several of the controls sold against these regimes are not required by them.
A scoped programme
The specific modules and engagements that close the gap, sequenced by what your deadline is and what depends on what — not by what is easiest to sell you.
Evidence, not a gap report
The output is the artefact your assessor accepts: test results, control evidence and a record of what changed. A document describing your gaps is not evidence that you closed them.
No lock-in
Scoping costs nothing and carries no obligation. If the answer is that you do not need this, that is a legitimate outcome of the call.
Who turns up
The engineer on your scoping call is on the delivery team. We do not hand you to a different group after signature.
Scope
What this does not cover
We do not take over service desk work, patch deployment or endpoint builds — the scope stops at security operations.
Network and server architecture redesign is out of scope; we assess how the estate is monitored, not how it should be laid out.
Licence negotiation with your vendors stays with you; we identify what is redundant, we do not sit in the commercial meeting.
- ISO/IEC 27001:2022 Annex A 8.15
- Logs of activities, exceptions and faults must be produced, protected from tampering and analysed — storage alone is not the control.
- ISO/IEC 27001:2022 Annex A 8.16
- Networks, systems and applications must be monitored for anomalous behaviour and the results acted on, not merely collected.
- CIS Controls v8, Control 8
- Collection is Safeguard 8.2, retention for a minimum of 90 days is 8.10, and review is 8.11 — three separate obligations, and meeting the retention one says nothing about the other two.
If the scope is wrong
Tell us on the call. Re-scoping before we start costs nothing; discovering it at the readout costs you the engagement.
Questions
The ones we are actually asked.
Will you recommend a tool that you resell?
The assessment names what is redundant regardless of who supplies it, ourselves included. If the tool that should survive is one we do not sell, you will get that in writing rather than in a footnote.
How much alert volume can actually be removed?
We will not put a percentage on it before seeing your data, and a percentage quoted beforehand belongs to somebody else's estate. Most of the reduction comes from deduplication and tuning rather than from switching detections off.
Do fewer alerts mean we will miss something?
It can, and that is the real risk in any tuning programme. Every suppression is recorded with its reason and its date, so a miss traces back to a decision somebody made rather than to a gap nobody can explain.
See what an attacker sees
We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.
30 min
A scoping call, with an engineer rather than a sales rep.
What it costs
Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.
Under attack now?
Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.