Cyber Resilience & Readiness

You have an audit, a finding, or an incident.

This is the practice we have been in longest, and the reason clients trust us with the AI work. It is well-made and current — SOC 2 and ISO 27001 readiness, second-line operating models, incident response you have actually rehearsed, and the capability programmes that build the next cohort.

Where this connects

The same discipline, pointed at a newer problem.

Twenty years of assessing, auditing and challenging systems is what makes the AI work credible — and the two practices share a single question. What data does this touch, where must it never go, who approves what, and how would we know if it went wrong?

If you arrived here with a supervisory finding or an incident, that is the work in front of us and we will not use it as an excuse to sell you something else. If you arrived here because AI is now in the risk register, the two conversations are the same conversation.

See AI governance and assurance →
Strategy, governance and assurance

A defensible security story, evidenced rather than asserted.

Boards and regulators expect a risk-based strategy, governance with real teeth, controls that are evidenced, and reporting that translates technical posture into business language. Most organisations have fragments. Few have the full picture — and almost none have discovered which parts are aspirational until they were tested for real.

  • Cybersecurity strategy and 18–36 month roadmaps aligned to NIST CSF 2.0, ISO 27001, MAS TRM, the Singapore Cybersecurity Act and equivalent African frameworks.
  • SOC 2 Type I and Type II readiness assessments and pre-audit remediation.
  • ISO 27001 ISMS design, scoping and implementation support.
  • Cyber maturity assessments benchmarked against peer institutions.
  • Second Line of Defence operating model design — RCSA, KRIs, issue and action tracking.
  • Security governance: committee charters, RACI, escalation pathways, board reporting packs.
  • Technology risk reporting frameworks for boards and regulators.
Resilience and incident readiness

Finding out which parts were aspirational — before someone else does.

An incident response plan nobody has run is a document, not a capability. These engagements exist to find the gap between the two while it is still cheap to find.

  • Cyber resilience simulations and ransomware tabletop exercises for executive teams.
  • Incident response playbook design and stress-testing.
  • Crisis communication protocols, including regulator and customer notification.
  • Board-level crisis decision-making exercises.
  • Ransomware decision frameworks — pay/don’t-pay, legal, sanctions.
  • Post-incident reviews and lessons-learned facilitation.
  • Resilience reviews aligned to regulators’ operational resilience expectations.
Capability development

Building the next cohort, not just the current posture.

Capability programmes fail in predictable ways: curriculum written to a vendor’s certification path, a range nobody integrates into teaching, graduates the market does not hire. This work is about the architecture that avoids that.

  • Cyber academy advisory — strategy, governance model, partnership architecture, sustainability planning.
  • Curriculum design for cyber skills programmes at entry, intermediate and executive levels.
  • Cyber range requirements specification and curriculum integration.
  • Workforce capability mapping (NICE Framework, SFIA, regional equivalents).
  • Executive education for boards and audit committees.
  • Train-the-trainer programmes for in-country instructor development.
What you get

Typical deliverables

Strategy and posture

Cyber strategy paper · maturity heatmap · technology risk reporting framework · board reporting templates.

Audit readiness

SOC 2 readiness gap report · ISMS scope and Statement of Applicability · evidence library structure.

Second line

RCSA workbook · KRI definitions · issue and action tracking design · committee charters and RACI.

Incident readiness

Tabletop design and after-action report · refreshed incident response playbook · crisis communication templates · post-incident review.

Capability

Academy strategy paper · curriculum architecture · cyber range requirements specification · capability map.

Who this is for

Where this work usually starts

A supervisory finding

A regulator or auditor has raised something and the response needs to be credible, evidenced and quick.

An audit on the horizon

First SOC 2 or ISO 27001, and nobody is sure how far off ready actually is.

A function being rebuilt

A new CISO or CIO inheriting fragments, needing a defensible plan and a second line that works.

An incident just happened

You want an independent post-mortem rather than an internal one, and a playbook that reflects what actually occurred.

Never exercised under pressure

An executive team with a plan on paper and no idea how it behaves at 2am.

Building national capability

Universities, skills bodies and development partners designing programmes that have to produce hireable graduates.

Start here

Start with what’s actually in front of you.

A 30-minute call, no charge. If the answer is that you need an auditor rather than an advisor, you’ll get that too.