Results

Delivered where failure carries consequences

Our clients run critical national infrastructure, global operations and professional practices carrying client confidentiality obligations. Thirteen engagements, spanning AI governance, cyber transformation, multi-cloud security, intelligent automation and national-scale data security. References are available at C-suite level.

FeaturedProfessional services

AI was already live across the firm. Nobody could say who owned it

A professional services firm with UK and international offices commissioned an independent read on where it actually stood. We mapped four distinct classes of AI activity — each needing a different kind of governance — assessed the information risk and the cyber baseline beneath it, and delivered a board-ready report structured as decisions rather than observations.

4
Classes of AI activity mapped, each with its own governance shape
2
Production tools with no organisation-controlled source code
7
Board decisions, each with a named internal owner
90 days
Stabilisation and acceleration plan, sequenced
Read the full case study

Published in anonymised form under engagement confidentiality.

AI Governance & Assurance

Governing AI before regulation forces the issue

Alongside the featured readiness discovery above, our AI governance work spans custom risk frameworks, EU AI Act preparation and AI by Design adoption. Explore the practice

Cyber & Information Security

Delivered where a breach is more than a line in the accounts

Group-scale transformation, secure architecture, privileged access, enterprise data governance, and national-scale standards work in government and health. Explore the practice

01FTSE 100 aviation CNI

Strategic cyber transformation

Cyber risk out of tolerance and inconsistent across group companies. We built a group capability without removing federated control.

1.5 → 3.0NIST CSF maturity, on an £18.4m programme
02FTSE 100 aviation CNI

Safe skies: secure architecture

Secure architectures for critical aviation systems — cloud migration, BYOD, network segmentation, legacy retirement and NCA collaboration.

6 monthsData centre exit ahead of plan
03Critical IT, global aviation

Securing privileged access

An automated, highly available PAM solution enforcing governance across AWS, Azure and on-premise environments.

100%Privileged accounts onboarded, session recorded
05Critical IT, global aviation

Enterprise security & GDPR compliance

Post-breach, an enterprise-wide GDPR framework with full data mapping and formalised controller and processor obligations.

Enterprise-wideGDPR framework across all product lines
07FTSE 100 aviation CNI

Data transformation & governance

A group-wide data strategy across seven airline brands, aligned to a £2bn+ transformation portfolio.

>40%Lower audit risk and breach exposure
08Government & energy CNI

National cyber governance & energy CNI

Created a jurisdiction’s first national cyber body, sole-authored its National Cyber Security Strategy.

ZeroMajor nonconformities at ISO 27001 Stage 2
09Health sector

National health data security strategy

Co-authored the review introducing ten national data security standards, and designed the sector-wide compliance toolkit.

£150m+Sector cyber investment unlocked
10FTSE 100 aviation CNI

Embedding security into business as usual

The companion to case study 01 — making programme remediation stick once the programme team goes home.

SustainedNIST CSF compliance embedded in daily operation

Case studies 01 and 10 describe the same group programme viewed from two angles — the transformation itself, and the work of embedding it into daily operation afterwards. They share their headline figures.

Cloud Security & Software Engineering

Velocity without widening the attack surface

Multi-cloud security unification, automated build pipelines, group tooling rationalisation and the metrics that make code quality measurable. Explore the practice

Intelligent Automation

Automation with the value proven, not asserted

Federated automation capability, target operating models, and the auditable benefits reporting that shows where the return actually landed. Explore the practice

The next step

Talk to the people who delivered these

You work directly with our senior practitioners — the same people named on these engagements. Tell us what you are facing and we will tell you honestly whether we are the right firm for it.

Arrange a conversation

References available at C-suite level on request.