Services
Improbus provides general consultancy services within several technology fields. Below — some of our areas of expertise. Not extensive. Not exhaustive. If you want to find out whether we can help with your specific need, contact us.
Advisory Services
Independent expertise across security, technology governance, and legal proceedings — eight focus areas:
- Technical SecurityHands-on technical security: Hardening, defensive engineering, and control implementation.
- Technology ManagementArchitecture, lifecycle, and risk-aware operation of technology.
- GRCGovernance, Risk & Compliance — ISO 27001, NIS2, GDPR, and NSM; policy, risk, and audit.
- EvidenceSecurement, collection & retrieval of digital evidence, with chain of custody.
- CourtsExpert witness testimony and reports.
- Law EnforcementSupport to agencies and investigators.
- Law FirmsStrategic advisory and technical consultation.
- Private InvestigatorsDigital evidence and forensic support to licensed investigators.
Consultancy Services
Hands-on technical consulting across audit, privacy, network, and messaging — twelve core practices:
- Data RecoveryForensic and operational recovery.
- Security AuditAssessments, gap analysis, and remediation.
- InfoSecPolicy, controls, and operations.
- PrivacyPersonal security & data protection.
- Comms SecurityEncrypted, authenticated channels.
- Network DefenseFirewall, IDS/IPS, and segmentation.
- Mail / MXSpam & phishing prevention.
- Endpoint SecurityEDR, device hardening, and baselines.
- Identity & AccessSSO, MFA, and least-privilege design.
- Cloud SecuritySecure configuration for public & private cloud.
- Security Awareness & PhishingTraining programs and simulated phishing to harden the human layer.
- Security ArchitectureZero-trust design, segmentation, and secure reference architectures.
Enterprise Services
Operations support for hardened, security-aware infrastructure — sixteen engagement areas:
- Data CentersOperation & maintenance for enterprise stacks.
- CommunicationsOperation of enterprise comms platforms.
- HardeningBaseline configuration & continuous review.
- Identity & AccessIAM, SSO, MFA, and least-privilege enforcement.
- Monitoring & SIEMCentralized logging, alerting, and correlation.
- Backup & RecoveryResilient backups with tested restores.
- Patch & LifecycleOrchestrated patching and end-of-life tracking.
- VirtualizationHypervisor and container-platform operations.
- Storage & DatabasesHardened, encrypted, high-availability data stores.
- Cloud & HybridSecure operation across public, private, and on-prem.
- Zero-Trust NetworkingIdentity-based access and microsegmentation across the estate.
- Disaster Recovery & BCPTested recovery plans, runbooks, and business-continuity exercises.
- OT / ICS SecurityProtection and segmentation for industrial control and SCADA systems.
- Email & Collaboration SecurityM365/Workspace hardening, anti-phishing, and DLP.
- Container & Kubernetes SecurityImage scanning, runtime protection, and admission control.
- Endpoint Management (UEM)Unified device management, configuration baselines, and compliance.
Digital Forensics
The process of investigating and analyzing digital devices, networks, and systems to collect and preserve evidence related to cyber incidents or crimes. We combine techniques, tools, and procedures to identify, contain, and remediate security incidents — malware, breaches, and insider threats. Digital Forensics & Incident Response is abbreviated DFIR. Goal: Uncover root cause, minimize impact, and prevent recurrence.
The Improbus Method (IMP)
- Pre-AssessEvaluate the situation with a quick pre-assessment — scope, severity, and immediate exposure.
- ContainStop the spread: Isolate affected systems, freeze and suspend compromised accounts and sessions, and preserve evidence.
- Emergency OperationsEnsure alternative core systems stay operational — NS, MX, WEB, FW, NMS, and more.
- CollectIdentify and preserve logs, traffic, system images, and artifacts under chain of custody.
- AnalyzeDetermine what happened, how, when, and who was involved.
- RemediateEradicate malware and footholds, close the root cause, and patch and harden.
- Rebuild and RestoreRebuild compromised systems and restore from clean, known-good backups.
- VerifyConfirm integrity, validate before return to production, and monitor for re-entry.
Incident Response
Immediate response to a security incident — e.g. response after a cyberattack or breach. Limit damage, lower costs, and save time. Cover internal and external communications.
CSIRT phases — eight steps
- PreparationBuild the capability before you need it — runbooks, tooling, access, and trained responders on call.
- IdentificationDetect and confirm the incident; establish scope, entry point, and severity.
- ContainmentStop the spread by isolating affected systems while preserving evidence for analysis.
- EradicationRemove the root cause — malware, footholds, and compromised credentials.
- RecoveryRestore systems from a clean state and verify they are fully operational and monitored.
- Lessons learnedCapture what happened, what worked, and what didn't, in a blameless review.
- Future planningFeed findings back into controls, training, and the next preparedness cycle.
- ReportingBrief stakeholders, regulators, and insurers — appropriately scoped and evidence-backed.
Preparedness Exercises
Cyber preparedness is an ongoing discipline. We organize exercises around all six functions of the NIST Cybersecurity Framework 2.0 — Govern, Identify, Protect, Detect, Respond, and Recover — with Govern as the overarching function that informs the other five.
-
Govern
Set the strategy, roles, and policy that steer every other function.
- Organizational context (GV.OC)Understand the mission, stakeholders, and the legal and regulatory obligations that shape cybersecurity risk decisions.
- Risk management strategy (GV.RM)Set risk appetite and tolerance, and decide how cybersecurity risk is prioritized and acted on.
- Roles, responsibilities & authorities (GV.RR)Assign clear ownership and accountability for cybersecurity across the organization.
- Policy (GV.PO)Establish, communicate, and enforce a cybersecurity policy that everyone follows.
- Oversight (GV.OV)Monitor and review the risk management strategy to confirm it works, and adjust it.
- Supply chain risk (GV.SC)Manage the cybersecurity risk that suppliers, vendors, and partners introduce.
-
Identify
Know what you have and where the risk is.
- Asset management (ID.AM)Keep a live inventory of hardware, software, data, and services, so you always know what has to be protected.
- Risk assessment (ID.RA)Find, analyze, and prioritize the threats and vulnerabilities facing your operations.
- Improvement (ID.IM)Feed lessons from tests, exercises, and real incidents back into the security program.
-
Protect
Put safeguards in place to limit or contain impact.
- Identity & access (PR.AA)Manage identities, strong authentication, and least-privilege access to systems and data.
- Awareness & training (PR.AT)Give every employee the security awareness and role-based training the job needs.
- Data security (PR.DS)Protect the confidentiality, integrity, and availability of data through classification and encryption.
- Platform security (PR.PS)Harden and securely configure systems, software, and services before they go live.
- Infrastructure resilience (PR.IR)Build network and technology architecture that keeps working under stress and attack.
-
Detect
Find attacks and anomalies fast.
- Continuous monitoring (DE.CM)Watch assets, networks, and services continuously for the signs of compromise.
- Adverse-event analysis (DE.AE)Analyze anomalies and events to confirm an incident and establish its scope.
-
Respond
Act decisively once something is detected.
- Incident management (RS.MA)Execute and coordinate the response the moment an incident is declared.
- Incident analysis (RS.AN)Investigate to establish scope, impact, and root cause.
- Reporting & communication (RS.CO)Notify and coordinate with stakeholders, regulators, and partners.
- Mitigation (RS.MI)Contain and eradicate the threat to stop it spreading further.
-
Recover
Restore operations and fold in the lessons.
- Recovery execution (RC.RP)Restore systems and data from a known-good state, in the right order.
- Recovery communication (RC.CO)Coordinate the restoration with internal teams and external parties.