Cloud foundation check
In 1–2 weeks, we review your AWS, Azure or Google Cloud foundation against the CIS benchmark and tie every finding to evidence, the affected resources and a fix.
Every service has a clear scope and a written fixed quote. A senior architect leads the work.
Review, build, run
Every area follows the same path: a short review first, then the build, then ongoing care. You can start small and add the next step later.
The base your systems run on in AWS, Azure or Google Cloud: account structure, secure networks, moves from your own data centre or between clouds, disaster recovery and lower monthly bills. All built as code.
In 1–2 weeks, we review your AWS, Azure or Google Cloud foundation against the CIS benchmark and tie every finding to evidence, the affected resources and a fix.
A one-week review of how traffic enters, leaves and crosses your AWS, Azure or Google Cloud networks, with evidence for every finding, a target Zero Trust design and a prioritised roadmap.
In 1–2 weeks, we assess what you run on-premises or in another cloud, with a migration approach per application, a wave plan and a cost estimate for AWS, Azure or Google Cloud.
Lower your AWS, Azure or Google Cloud bill in one to two weeks by changing how the platform is built, from NAT and data transfer paths to commitments, with the quick wins delivered as code.
A production-ready foundation on AWS, Azure or Google Cloud in 3 to 6 weeks, with single sign-on, guardrails, a hub network, central logging and a keyless pipeline, all built as code.
A Zero Trust network for the AWS, Azure or Google Cloud estate you already run, with a hub, private endpoints, central DNS and egress through a cloud firewall, built in 3 to 6 weeks without downtime.
Move workloads from on-premises, another region or another cloud in planned steps, with a disaster recovery pattern that meets your RPO and RTO targets and restore tests that prove it.
Up to about 30 preventive guardrails for AWS, Azure or Google Cloud, each with a test that proves it refuses a non-compliant change, and evidence mapped to CIS, ISO 27001 Annex A and NIST CSF.
Run your applications in containers without looking after servers: serverless options (ECS on Fargate, Azure Container Apps, Cloud Run) or Kubernetes (EKS, AKS, GKE, OpenShift).
A one-week, read-only review of your Kubernetes clusters or serverless container runtime, with evidence for every finding, a hardening plan ordered by risk and a readout with your team.
A platform for your containerised services on ECS on Fargate, Azure Container Apps or Google Cloud Run in 3–7 weeks, built as code with one reusable service module for every team.
A Kubernetes platform on EKS, AKS, GKE or managed OpenShift in 5–6 weeks, run through GitOps, with access, policies, secrets and scaling in place and your first services onboarded.
Build and release pipelines with security built in: no stored cloud passwords, automatic security scans, signed releases, infrastructure changes reviewed before they go live, and GitHub Enterprise with developer accounts your company manages.
In 1–2 weeks, a check of how your teams build and ship software, scored against OWASP SAMM and NIST SSDF, ending in a gap list and a 90-day plan.
A one-week review of one CI/CD platform, from organisation settings to runners and secrets, with findings mapped to the OWASP Top 10 CI/CD Security Risks and SLSA.
Your pipelines move from long-lived cloud keys to short-lived federated tokens, with secret scanning and dependency gates that stop new leaks and risky dependencies before merge.
A pipeline that scans every change, builds each image once, promotes it by digest and asks for approval before production, for one app in 2–3 weeks or up to 10 repositories in 4–5 weeks.
A keyless pipeline for your Terraform or OpenTofu code that plans on every pull request, applies only after approval, checks every plan against policy and reports drift on a schedule.
Signed images, SBOMs and build provenance to SLSA Build Level 2 for up to 10 repositories, checked at deploy time so that only images your pipeline built can run.
Security champions, threat modelling, fix deadlines, an exception register and a shared definition of done for up to 10 teams, tracked on a dashboard built from the tools you already have.
A GitHub enterprise on GitHub.com or GHE.com (EU) where every developer account comes from your identity provider, built as code in 2–3 weeks, or 4–6 weeks with your repositories moved in.
Who and what can sign in, and what they may do: Microsoft 365 and Entra ID security, admin access, internal certificates (PKI), and your domains and DNS kept safe and managed as code.
A one-week review of your PKI and certificates, covering the CA hierarchy, certificate inventory, TLS settings and revocation, rated red, amber or green, with an expiry risk list and a roadmap.
A one-week, non-intrusive check of your domains, DNS, email authentication and internet-facing endpoints, with every finding tied to evidence and a fix. It is not a penetration test.
Conditional Access, phishing-resistant MFA and just-in-time admin rights for Microsoft 365, plus Intune policies, Defender for Endpoint and disk encryption for Windows and macOS, designed and rolled out in 1–3 weeks.
Business applications moved from passwords and legacy federation to Entra ID single sign-on, with hybrid sync, tenant and domain moves, and one corporate sign-in for AWS and Google Cloud where you need it.
Admin access split into tiers, done from separate admin accounts on dedicated workstations and granted just in time, built with PIM, Conditional Access and Intune in 2–3 weeks.
A private CA hierarchy on one platform, with automated enrolment and renewal, working revocation and expiry alerts, built as code in 3–4 weeks.
Every DNS zone and record managed in code with pull request review and drift detection, imported in place with zero record changes or moved to a new provider, in 2–3 weeks.
SPF, DKIM and DMARC at reject for up to 5 sending domains, MTA-STS with TLS reporting, and parked domains locked down, staged over 8–12 weeks with a check before every step.
Make your systems harder to attack, and show it: hardened servers, finding and fixing vulnerabilities, alerts on risky cloud changes, threat modelling and Zero Trust reviews.
In 1–2 weeks, a review of identity for people, devices and workloads, cloud guardrails and CI/CD, with every control checked as declared, refused and in effect, ending in a maturity rating per area and a roadmap.
A STRIDE threat model of one system or major feature, built with your team in two half-day sessions over one to two weeks, with a data-flow diagram, trust boundaries and prioritised mitigations in your backlog.
Linux and Windows Server hardened to CIS Benchmarks Level 1 in two to six weeks, built as code with golden images, enforced settings, drift checks and compliance evidence for every host.
Scanning for hosts, containers, Kubernetes, serverless functions and code dependencies, with triage rules, fix deadlines by severity, ticket integration and a weekly report, set up in two to five weeks.
Central audit logs and about 15 or 25 tested alert rules for high-risk changes in AWS, Azure or Google Cloud, each with a runbook and routed to your on-call tool, tickets or chat, in two to four weeks.
An incident response plan, cloud runbooks and forensic readiness that help you prepare for the NIS2 reporting deadlines, tested in a tabletop exercise with your team over two to three weeks.
A senior security architect on agreed days each month, typically 2, 4 or 6, for your security roadmap, design reviews, customer questionnaires, policies, supplier reviews and incident advice.
Use AI in development and in your products without losing control: rules for AI coding assistants, safe access to AI models with checks before new AI features go live, and cloud platforms built for AI.
In 1–2 weeks, a read-only review of the AI tools, model keys, agents and data flows in your organisation, with the risks ranked and a 30/60/90-day plan to fix them.
Let your engineers use AI coding agents on real repositories, with written working agreements, grounded answers, read-only cloud access and human consent before every production change.
Give your applications one controlled route to AI models with a keyless fallback, keep model calls in EU regions and hold generative features back until evaluation and data-protection sign-off.
A governed place in your cloud for AI agents and AI-enabled apps, built as code in four to six weeks: inherited guardrails, approved models and regions only, and a keyless identity for every agent.
New web apps, APIs and integrations, and older applications moved to modern containers, on a secure base from day one.
A discovery of 1–2 weeks that turns a product idea into a first-release scope, an architecture, a build estimate and a delivery plan, before you commit budget to the build.
A web app or MVP with its API, built in your own AWS, Azure or Google Cloud environment in 4 to 12 weeks, with infrastructure as code, CI/CD and security gates from the first commit.
Tested integrations with your suppliers, partners and payment providers that handle timeouts, retries and duplicate messages, so one slow partner cannot stall your product. Built in 2 to 8 weeks.
Older applications, including .NET and IIS apps, moved into containers on Amazon ECS on AWS Fargate, Azure Container Apps or Cloud Run, with CI/CD and a tested rollback for every release.
Senior advice when you need it: a working session with an architect, written comparisons of technology options, a 12-month roadmap or a part-time architect.
A 90-minute working session with a senior architect on one hard architecture question, followed by a written memo with the recommendation and next steps within three working days.
A written recommendation on a platform choice that is expensive to reverse, such as Microsoft 365 or Google Workspace, an identity platform, an AI platform or a cloud, with licensing and costs worked out.
A review of your cloud, your workplace platform and your applications over three weeks, ending in a 12-month roadmap with effort and cost ranges, and one presentation to your board.
A senior cloud and platform architect on your team for a set number of days each month, without a full-time hire. Decisions get reviewed and your platform backlog moves every month.
We keep things running after go-live: monitoring, updates and fixes for your cloud platform and applications, with optional 24/7 cover for critical incidents.
Business-hours care for your cloud platform: monitoring and alerting, monthly patching, backup and restore checks, a monthly block of change hours and a monthly report, with 24/7 cover as an add-on.
Business-hours care for your live web and mobile apps: security and dependency updates, uptime and error monitoring, backup checks and a monthly allowance of hours for fixes and small changes.
An add-on to Platform Care or App Care: an engineer acknowledges a P1 incident within 30 minutes, 24/7/365, with cover starting after 4–6 weeks of onboarding.
Book a free 30-minute call. We learn what you need and tell you honestly whether and how we can help. There is no obligation.