Architecture and access
We assess assets, networks, identities and trust boundaries.
- Asset inventory and criticality
- MFA, privileged access and joiner/mover/leaver lifecycle
- Segmentation, remote access and suppliers
We turn fragmented configuration and process into a clear map of risk, ownership and remediation order.
The objective is not checklist compliance. Standards provide a reference, while priority comes from impact on operations, data and the organisation’s ability to detect and handle an incident.
We assess assets, networks, identities and trust boundaries.
We test the ability to maintain and restore operations.
Technical controls are connected to ownership and process.
We start with critical services, data, obligations and tolerance for downtime.
We speak with owners, review configuration and request proof that controls operate.
Selected risks are checked with tools and safe tests instead of relying on declarations.
Findings become initiatives, owners, dependencies and a realistic sequence.
Having backup files is not the same as restoring a service within the required time.
This is a documentation example, not a finding from a specific organisation.
No defined RTO/RPO for a critical service
Restore testing excludes dependencies and keys
Results have no owner or acceptance criterion
Remediation starts with a controlled restoration exercise
No. We can assess readiness and gaps, while certification is issued by an accredited certification body.
Technical validation can be included, but a full penetration test is a separate, deeper engagement. Both scopes can be combined where justified.
We need a project owner and short access to people responsible for IT, security and critical processes. The schedule is designed not to block operations.
We will agree critical systems, requirements and the level of detail needed by leadership and IT.