Services
Small engagements, written outputs. We are usually brought in where a decision has to be documented.
Technical assurance review
A structured review of an estate against its own stated design and control objectives: network and service topology, identity and access paths, backup and restore reality, change and monitoring practice. Deliverable is a findings register with evidence, not a slide deck.
Regulatory and audit readiness
Preparation for supervisory or certification review under DORA, NIS2, ISO 27001 and sector schemes. We reconcile the control framework with what is actually implemented, and mark clearly where the evidence is missing.
Technical due diligence
For acquirers and investors: cost-to-serve, single points of failure, licensing exposure and the migration work implied by the current architecture. Typically two to three weeks.
Sourcing, transition and exit
Requirements definition, supplier evaluation and a transition plan your own engineers can run. We also run exits — handing a service back from a managed provider without losing the operational history.
Engagement model
| Format | Typical duration | Output |
|---|---|---|
| Assurance review | 3–6 weeks | Findings register, remediation plan, evidence pack |
| Audit readiness | 4–8 weeks | Control mapping, gap log, walkthrough support |
| Due diligence | 2–3 weeks | Report with costed risks and integration dependencies |
| Advisory retainer | Monthly | Named adviser, fortnightly review, escalation cover |
We do not resell hardware, hosting or software. Where a supplier is involved, we say so in writing.