Skip to content
All services
DevSecOps & secure CI/CDBuild

DevSecOps operating model

Security champions, threat modelling, fix deadlines, an exception register and a shared definition of done for up to 10 teams, tracked on a dashboard built from the tools you already have.

When you need it

Security depends on a few busy people. Teams do not know which findings to fix first or by when, threat modelling happens only when someone insists, and every exception is a one-off conversation that nobody writes down.

What sets the quote

  • One engineering organisation of up to 10 teams or 100 engineers.
  • Up to 10 security champions, usually one per team.
  • One 3-hour training session for up to 25 developers.
  • A dashboard built on your existing tools, with no new licences.
  • Larger organisations are quoted after the call.

What changes

  • Each team has a named security champion with an agreed role and time budget.
  • Teams threat model new features the same way, with STRIDE and a shared template.
  • Every vulnerability has a fix deadline set by severity, and every exception has an owner and an end date.
  • Security criteria are part of the definition of done, so they are checked in normal work rather than in a separate review.
  • Leaders see open findings, missed deadlines and exceptions on one dashboard.

What you get

  • Security champions programme for up to 10 champions: role, time budget, selection, meeting rhythm and onboarding
  • Threat modelling practice: when to run one, a STRIDE-based template and a first session run with one team
  • Vulnerability fix deadlines by severity, agreed with your leadership
  • Exception register with owners, end dates and a review rhythm
  • Security criteria for your definition of done
  • Dashboard on your existing tools, showing findings by age and severity, deadlines met and open exceptions
  • One 3-hour training session for up to 25 developers
  • Handover to your security owner, with a 90-day plan for the champions

This package often follows a DevSecOps gap check. The gap check shows where you stand against OWASP SAMM; this package puts the people and process parts of the 90-day plan in place, so the gates in your pipelines have owners and deadlines behind them.

Not included

  • New tool licences or tool rollouts
  • Fixing existing vulnerabilities
  • Security awareness training for staff outside engineering
  • Running the programme after handover (available as fractional platform and security architect support)

What we need from you

  • An executive sponsor who approves the fix deadlines and the champions' time budget.
  • Your security owner and engineering lead, about 3 hours a week each.
  • Up to 10 nominated champions for a 2-hour kickoff.
  • Read access to your issue tracker and security scanners for the dashboard, for example Jira and GitHub or GitLab security findings.
  • A 3-hour slot in your developers' calendars for the training session.

How it works

  1. Free 30-minute call, then a written fixed quote based on your team and engineer counts.

  2. Workshops with your leads to agree fix deadlines, the exception process and the definition of done.

  3. Select and onboard the champions, and run a first threat model with one team.

  4. Build the dashboard and deliver the training session.

  5. Handover and a 90-day plan for your security owner.

At a glance

Duration
3–4 weeks
Price
Fixed quote after a free 30-minute call
Delivered by
Our lead architect
Assess

DevSecOps gap check

In 1–2 weeks, a check of how your teams build and ship software, scored against OWASP SAMM and NIST SSDF, ending in a gap list and a 90-day plan.

Duration:1–2 weeks
Assess Popular

Pipeline security check

A one-week review of one CI/CD platform, from organisation settings to runners and secrets, with findings mapped to the OWASP Top 10 CI/CD Security Risks and SLSA.

Duration:1 week
Build

Keyless pipelines and secrets cleanup

Your pipelines move from long-lived cloud keys to short-lived federated tokens, with secret scanning and dependency gates that stop new leaks and risky dependencies before merge.

Duration:1–3 weeks

Not sure where to start?

Book a free 30-minute call. We learn what you need and tell you honestly whether and how we can help. There is no obligation.