service · 05strategy · roadmap · governance · virtual ciso
a strategy your board will follow.
We set where security goes over the next three years — costed, sequenced and tied to business risk — then stay alongside as senior leadership on tap.
weeks to a three-year strategy
year roadmap, costed and sequenced
on a rolling, fixed monthly fee
01what changes for you
A direction the board can back, spend tied to risk rather than a vendor's pitch, and governance that actually runs — with senior leadership on tap after.
A three-year strategy tied to business objectives and risk appetite.
Every roadmap item linked to a risk, a gap or an obligation — not a vendor's pitch.
Sequenced against the Microsoft estate you already run. No rip-and-replace.
Policies and control ownership checked against what actually runs.
Guardrails for Copilot and other AI agreed before the data goes somewhere it shouldn't.
A virtual CISO for board reporting, risk and vendor reviews.
02what we typically find
Most security programmes grow by reaction — the last incident, the last audit finding, the last vendor pitch. The result is tools nobody fully owns, a roadmap that is really a wish list, and a board that hears about security only when something goes wrong.
03our approach
Four stages, each with a gate you sign. Senior consultants only — the people who scope are the people who deliver.
understand the business
see what really runs
build the strategy
stay alongside
04what you get
05who it's for
A clear direction, and the decisions that need their name on them.
An investment case, not a wish list.
A roadmap that fits the technology plan.
A mandate, a budget line and senior support.
Sources: DSIT, Cyber Security Breaches Survey 2025/26 (30 April 2026); DSIT, Cyber Governance Code of Practice (April 2025).
Strategy in six to eight weeks; vCISO on a monthly retainer. We're not another platform trying to 'transform' your cyber tech.