Preparedness
Tabletop exercises, IR plans, and CSIRT readiness — built across the six NIST CSF functions so the work is ready before the incident.
Cyber preparedness is a continuous discipline, not a one-off project. We organise the work around the NIST Cybersecurity Framework functions — Identify, Protect, Detect, Respond, Recover, and Govern — and treat each as an equal cluster of practical, measurable controls. Every cluster below carries the same number of focus areas so the picture stays balanced: No single function is over-weighted, and nothing falls through the gaps.
Identify
You cannot protect what you do not know you have. The Identify cluster establishes a current, trustworthy picture of assets, risk, and exposure that every later function depends on.
Focus areas
- Asset inventoryA maintained register of systems, data, identities, and services — the foundation everything else builds on.
- Risk assessmentVulnerabilities and threats weighed by likelihood and impact, internal and external alike.
- Business-impact analysisWhich processes matter most, what they depend on, and how long they can be down.
- Threat intelligenceTracking the landscape and tuning defences to the threats that actually apply to you.
Protect
Protect turns the picture from Identify into safeguards. The aim is to reduce the attack surface and limit blast radius so that, when something does get through, it is contained by design.
Focus areas
- Hardening & patchingSecure baselines kept current across software, hardware, and firmware.
- Network securityFirewalls, IDS/IPS, segmentation, and encryption to break attacker movement.
- Identity & accessStrong authentication, least privilege, and disciplined access controls.
- Supply-chain controlsVendors and partners are part of your perimeter; their risk is your risk.
Detect
Detection buys time. The faster an anomaly surfaces and reaches the right person, the smaller the eventual incident. This cluster is about visibility and the proof that it works.
Focus areas
- Continuous monitoringTelemetry across networks, endpoints, and systems, watched for anomalies and abuse.
- Escalation pathsClear, rehearsed routes from alert to the person who can act on it.
- Testing & simulationPenetration tests, red-team exercises, and phishing drills that probe the defences.
- DocumentationRecords of incidents, responses, and lessons so detection keeps improving.
Respond
When prevention fails, a rehearsed response is what limits the damage. We build the plans, run the exercises, and connect them to our Incident Response and Digital Forensics work.
Focus areas
- Incident plan & playbooksRoles, responsibilities, and runbooks that hold up under pressure.
- Tabletop exercisesScenario rehearsals and training that turn the plan into muscle memory.
- Backup & recoveryRegular backups with tested restores — recovery you have proven, not assumed.
- Comms, legal & complianceWhat to say and to whom, aligned with GDPR, NIS2, and sector rules.
Recover
Recovery is where the business comes back. A rehearsed, prioritised recovery turns a bad day into a manageable one — and proves that "we can restore" is a fact, not a hope.
Focus areas
- Recovery planningPrioritised, tested plans to bring systems and data back in the right order.
- Restore from known-goodRebuild from a clean, verified state and confirm integrity before returning to production.
- Recovery communicationsKeep stakeholders, customers, and regulators informed through the restoration.
- Post-incident improvementTurn each recovery into measurable improvements so the next one is faster.
Govern
Governance keeps the other five functions funded, owned, and accountable over time. Without it, preparedness erodes quietly between audits.
Focus areas
- Policy & standardsClear rules, ownership, and standards that make expectations explicit.
- Budget & resourcingChronic underfunding becomes a vulnerability of its own.
- Board-level reportingRisk reported in terms leadership can act on and be accountable for.
- Adaptability & collaborationDefences shift as threats shift; experience is shared with peers and experts.
Ethical standards
Transparency and responsibility underpin every engagement. We are explicit about scope, limitations, and findings; we report honestly even when the news is unwelcome; and we handle evidence, data, and disclosures with integrity and proportionality.
What an engagement looks like
Typically 4–12 weeks: Assessment of current state, prioritised gaps, and a phased plan with measurable outcomes. We deliver under SoW with stakeholder review at each phase.