Service 01
Cybersecurity consulting
Identity governance, access risk, security operations and audit readiness. The work that decides whether an incident is contained in an hour or discovered in a forensic report six months later.
The problem is rarely the tooling
Most organisations we meet already own capable products. What they do not have is an agreed answer to a short list of questions: who owns this entitlement, why does this account still exist, what would we detect if this credential were abused tonight, and where is the evidence that any of this is true.
That gap is where audit findings, failed certifications and slow incident response all come from. It is also entirely fixable — but by design and discipline rather than by another licence.
Where we work
Identity governance and administration
IGA programmes fail in predictable ways: a role model built in a workshop that nobody can maintain, certification campaigns that reviewers rubber-stamp, connectors that drift out of sync, and a joiner-mover-leaver process that handles joiners well and leavers badly.
- Programme design, or rescue of a stalled implementation
- Role mining and a role model sized to what your organisation can actually maintain
- Joiner-mover-leaver design, including the mover case that most programmes quietly skip
- Access certification that produces real decisions — scoped, risk-weighted and measurable
- Segregation of duties rulesets, mitigation controls and exception governance
- Privileged and non-human identity: service accounts, tokens, machine identities and now agents
Access risk for users and AI agents
Business applications are where access risk becomes financial risk.
- Authorisation concept review and clean-up planning
- Bringing On-Prem and SaaS applications under central governance instead of local administration
- Cross-application segregation of duties, including the combinations that only appear across systems
Security operations
A SOC is judged by what it catches, not by how many log sources it ingests. We assess detection coverage against the threats that actually apply to your business, and fix the operating model around it — triage, escalation, on-call, handover, post-incident review.
- Detection coverage assessment and use-case backlog, mapped to MITRE ATT&CK
- SOC operating model, staffing and shift design; build-versus-outsource decisions
- Incident response readiness, tabletop exercises and regulator notification playbooks
- Identity-centric detection: the alerts that catch credential and entitlement abuse
Compliance readiness
Compliance work goes badly when it is treated as a documentation exercise bolted on at the end. It goes well when the control and its evidence are designed together. We work backwards from what an assessor will ask for.
- NIS2 and national implementations — in Poland, the amended National Cybersecurity System Act (KSC)
- DORA for financial entities, including ICT third-party risk and register of information
- ISO/IEC 27001 gap analysis, statement of applicability and internal audit preparation
- SOC 2 readiness — control design, evidence automation and surviving the observation window
What you receive
- A findings report written for two audiences — an executive summary that survives a board pack, and detail your engineers can act on
- A prioritised roadmap with effort, dependencies and the risk each item removes
- Target-state designs, policies and runbooks for the tools you already own
- An evidence pack mapped to the framework you are being assessed against
- A working session with your team so the knowledge stays after the engagement ends
Common questions
Our IGA rollout has stalled. Can you take it over?
Often, yes — and usually the first job is to find out why it stalled rather than to restart it. Stalled programmes typically have a role model that outgrew its maintainers, connector scope that was underestimated, or no accountable owner on the business side. We diagnose that before proposing anything.
Do you resell or implement a specific IGA product?
No. We hold no reseller agreements and take no vendor commission, which is precisely why our platform recommendations are worth something. We work with what you have wherever that is defensible.
We need to be NIS2-compliant. How long does that take?
It depends entirely on where you start, and any consultancy that quotes a duration before looking is guessing. What we can say is that a two-to-four week readiness assessment will tell you the size of the gap, which obligations bite first for your entity classification, and what a realistic schedule looks like against the national deadlines.
Tell us where it hurts.
A failed certification campaign, an audit finding you cannot close, a SOC that is busy but not effective. Thirty minutes will tell us both whether we can help.