Cyber Resilience
Knowing your controls are covered is not the same as knowing your organisation would cope. We test how your people, systems, and suppliers hold up under pressure, then help you strengthen what that exposes. Findings are mapped to the frameworks you already report against, such as NIST CSF 2.0, ISO/IEC 27001, APRA CPS 230, and HKMA C-RAF.
Incident Response Readiness
Best for: Organisations that need to know their response plans work
A plan that has not been exercised is a document, not a capability. We review your incident response and business continuity arrangements, then run a facilitated tabletop with the people who would actually participate, testing decision authority, escalation, and external communication under time pressure.
Scenarios are built from your real exposure: ransomware, third-party outage, data breach, and, where relevant, AI-specific failures such as a model giving customers materially wrong information or an agent acting outside its authority. Few plans cover the last two.
Security Testing Design and Oversight
Best for: Organisations commissioning security testing and wanting it to answer the right questions
Penetration tests and red team exercises are often scoped by the firm performing them. That produces competent testing of what was easy to define, and silence on everything outside it. We work on your side of that transaction.
We define what needs testing and why, translate it into a scope and brief that vendors can price comparably, help you select the right firm for the job, and stay involved while the work runs. Where AI systems and agents are in scope, we specify the testing that conventional providers often leave out, such as prompt-level manipulation, permission and scope boundaries, data exposure through model inputs and outputs.
When findings arrive, we review them independently, separate the commercially material from the noise, and track remediation through to a retest that evidences closure.
Third-Party Security Due Diligence
Best for: Organisations answering security questionnaires, or sending them
Security questionnaires are now standard procurement practice at large and regulated organisations. If you sell to them, you answer one. If you buy from anyone material, you should be sending one. Both sides are often handled ad hoc, by people with other jobs.
We work in both directions. On the response side, we build and maintain your evidence set, so questionnaires are answered consistently and quickly rather than reconstructed from scratch each time, and so the answers hold up if anyone checks. On the assessment side, we evaluate vendors and partners against a defined control baseline mapped to NIST CSF 2.0 or ISO/IEC 27001, including, where the vendor supplies AI capability, what their model does with your data.
The output is a clear view of which findings are commercially material and which are noise
