Services
Advisory work with a defined end state.
Every engagement starts from the same question: who or what is allowed to do what in your environment, and can you prove it to someone who is not inclined to take your word for it. Three practices, one method.
01 — CONSULTING
Cybersecurity consulting
Identity governance and administration, access risk, security operations maturity, and audit readiness for NIS2, DORA, ISO/IEC 27001 and SOC 2. Most breaches and most audit findings come back to entitlements nobody owns and evidence nobody kept.
- Access risk for users and AI agents
- SOC maturity, detection coverage and incident response readiness
- Compliance readiness and evidence design for NIS2/KSC, DORA, ISO/IEC 27001, SOC 2
02 — QUANTUM-SAFE
Migration to quantum-safe algorithms
A structured path from “we think we use TLS everywhere” to a documented, prioritised, tested transition to the NIST post-quantum standards — with crypto-agility built in so the next algorithm change is a configuration exercise rather than a programme.
- Cryptographic inventory and CBOM — where keys, certificates and algorithms actually live
- Risk ranking by data lifetime, exposure and migration effort
- Target architecture: ML-KEM, ML-DSA, SLH-DSA, hybrid modes and PKI implications
- Supplier and product assurance — what to demand in contracts and roadmaps
- Pilot, rollout plan and evidence aligned to the EU roadmap milestones
03 — AI AGENTS
Security of AI agents
Autonomous agents combine reasoning, memory, tools and multi-step execution. That produces failure modes traditional application security never had to consider — goal hijacking, tool misuse, memory poisoning and agents that quietly accumulate privilege.
- Threat modelling against the OWASP Top 10 for Agentic Applications
- Agent identity and entitlement design — treating agents as governed non-human identities
- Tool and MCP server review, supply-chain assurance, sandboxing
- Guardrails, human-in-the-loop design and blast-radius limits
- Agent red-teaming, logging and forensics; governance under the EU AI Act and ISO/IEC 42001
Engagement models
Three ways to start.
Assessment sprint
2–4 weeks · fixed price
A defined question answered with evidence: where do we stand, what is the exposure, what should we do first. Ends with a findings report, a prioritised roadmap and a costed next step.
Advisory retainer
Monthly · capped days
A senior second opinion on tap — design reviews, vendor selection, board and regulator questions, and steady progress on a roadmap your own team is delivering.
Programme delivery
3–12 months · milestone-based
Hands-on ownership of a defined workstream — an IGA rollout, a cryptographic migration wave, an agent governance framework — with your team trained to run it afterwards.