An independent consultancy for organisations where the consequences of failure reach beyond the balance sheet.
Cyber and information security is our foundation and our core practice. It is also what gives us the depth and breadth to advise on AI — because knowing how to use AI safely starts with knowing exactly what unsafe looks like. We have spent careers finding out.
The highest chartered designation in the security profession, spanning cyber, physical and personnel security.
Chartered status in cyber security specifically, awarded against the UK Cyber Security Council standard.
Very few practitioners in the UK hold both. Our practice is led by someone who does.
Independently audited against the UK government-backed scheme — the standard we help our own clients reach.
CISO expertise and leadership across the full spectrum — governance, risk and compliance, security assurance and penetration testing, identity and privileged access, infrastructure security, security architecture, and CISO as a Service. Delivered inside FTSE 100 estates, critical national infrastructure and national health data.
What AI is used for, what data it touches, who owns it and what controls hold it — then the governance framework and the secure operating model underneath.
We came to AI from security, not the other way round. That order matters, and it shows up in the work.
Our people have spent their careers securing airline groups, energy utilities, national health data and government estates. That is the practice, and it remains the majority of what we do. It is also precisely why boards ask us about AI — because the questions that decide whether AI can be used safely are identity, data classification, supplier assurance and incident response. Those are cyber security questions wearing different clothes.
Chartered practitioners, ISO 27001 lead auditors, an NCSC working relationship, and delivery inside estates where downtime is measured in grounded aircraft.
An AI policy is only as strong as the controls beneath it. We can write both, and we will tell you when the foundation has to come first.
Using AI safely is not a separate discipline. It is security, applied to something new.
AI is already entering your business through staff, suppliers, client expectations and everyday tools. It is usually live across the organisation before anyone can say who owns it, what data it touches, or whether its use could be defended to a client, an insurer or a regulator.
Most AI advice starts with the tools. We start with the conditions under which their use can be defended — and we build the secure operating model underneath the policy, because that is what makes the policy true.
Neither requires a programme commitment. Both give your board something it can act on.
An honest read on where your controls actually stand, benchmarked against the framework your regulators and insurers already use.
A fixed-scope, fixed-fee review your board can commission on its own authority — rather than a study that ends in a slide deck.
Security is the thread running through all of it. Most engagements draw on more than one practice.
Governance, risk and compliance, security assurance and penetration testing, identity and privileged access management, infrastructure security, security architecture, and CISO as a Service.
Defensibility reviews, readiness discovery, AI risk frameworks, secure operating model design, policy suites, fractional Information Security Officer and AI literacy training.
Managed cloud security across AWS, Azure and GCP, secure DevOps and code control, CI/CD pipelines, technical modernisation and secure cloud migration.
Federated automation strategy, target operating models, auditable benefits realisation, process and communication mining, and agentic orchestration.
Our clients operate critical national infrastructure, handle national health data and run global operations. References are available at C-suite level.
Cyber risk out of tolerance and inconsistent across group companies. We built a group cyber security capability without removing federated control — clearing the critical vulnerability backlog, delivering a NIS-D corrective action plan, and standing up group IDAM with MFA and a SOC.
Senior involvement in a national advisory panel shaping data security policy — co-authoring the review that introduced ten national data security standards, and designing the compliance toolkit that became mandatory across the health sector and its suppliers.
AI was already live across the firm and nobody could say who owned it. We mapped four distinct classes of AI activity, each needing a different kind of governance, and delivered a board-ready report structured as decisions rather than observations.
Bring us the thing you are least comfortable with — a certification deadline, a client questionnaire you cannot answer, an identity estate nobody fully understands, or AI already running across the business without an owner. We will give you a straight read on where you stand.
Arrange the briefingNo preparation required. No obligation to proceed.