Our Practice

The standards we build to —
not just sell.

Every engagement is anchored to the same recognised frameworks, whether or not it's billable. This page is the reference — the frameworks we practice, and the checklists we hand to clients for free. Looking for what we deliver? See our Services.

Frameworks are the tools.
People are the practice.

NIST, ISO, and CIS tell you what "good" looks like. They don't patch a server, report a phishing email, or say no to a risky shortcut under deadline pressure — your people do. Every checklist above exists to make that easier for them, not to replace them.

01

Listen First

Every engagement starts with the people, culture, and constraints inside your organisation — not a framework checklist applied blind.

02

Plain Language

We translate ISO clauses and NIST functions into instructions a non-security employee can actually follow — jargon protects no one.

03

Train the Humans

Firewalls don't click phishing links or reuse passwords. We invest as much in awareness and culture as we do in tooling.

04

Stay Alongside

Retained advisory through implementation, not a report handed over and forgotten — the same people who assess you help you fix it.

A shared vocabulary for security posture.

We map every audit, assessment, and roadmap back to a recognised standard — so findings are defensible to a board, a regulator, or an auditor, not just to us.

Framework
NIST Cybersecurity
Framework 2.0
Our baseline structure for assessing and communicating security posture in language leadership can act on.
Govern Identify Protect Detect Respond Recover
Architecture
Zero Trust Architecture
(NIST SP 800-207)
Never trust, always verify. The default posture for every network and identity design we recommend.
Verify Explicitly Least Privilege Assume Breach
Management System
ISO/IEC 27001:2022
The international benchmark for an information security management system — what we audit against and help build.
Risk Assessment Annex A Controls ISMS Continual Improvement
Controls
CIS Critical Security
Controls v8
Prioritised, practical safeguards mapped to real-world attack patterns — our default hardening baseline.
Basic Foundational Organizational 18 Controls
Threat Model
MITRE ATT&CK
How we model adversary behaviour in red-team engagements and detection engineering.
Tactics Techniques Procedures Threat-Informed Defense
Regulation — India
Digital Personal Data
Protection Act, 2023
India's data protection law, and what it concretely means for how our clients collect, store, and process data.
Consent Fiduciary Duties Data Principal Rights Breach Notification
Human Risk
Security Culture &
Human Risk Management
The framework behind our people-first belief — because most of the frameworks above only work if the humans using them buy in.
Awareness Behaviour Culture Security Champions

Best practice you can act on this week.

No audit required. These are the checks we run first on every engagement — tick them off as you go through your own environment.

Identity & Access Hygiene
0/5

Identity is the perimeter now — most breaches start with a compromised or over-privileged account.

  • Enforce MFA on all privileged and external-facing accounts
  • Apply least-privilege / just-in-time access via PIM
  • Review and remove stale accounts & guest access quarterly
  • Enable Conditional Access based on risk signals
  • Rotate and vault all service account credentials
Email & Phishing Defense
0/5

Still the single most common way in — the fixes are cheap relative to the risk they close.

  • Enforce SPF, DKIM, and DMARC (reject policy) on all sending domains
  • Enable Safe Links / Safe Attachments or equivalent sandboxing
  • Run quarterly phishing simulations with tracked click-rates
  • Flag external senders visibly in the inbox
  • Maintain a one-click "report phishing" workflow
Patch & Vulnerability Management
0/5

Attackers overwhelmingly exploit known, unpatched vulnerabilities — not novel zero-days.

  • Maintain an accurate, current asset inventory
  • Patch critical/high CVEs within a defined SLA
  • Run authenticated vulnerability scans monthly
  • Track exceptions with compensating controls, not silence
  • Prioritise by exploitability, not CVSS score alone
Backup & Ransomware Recovery
0/5

A backup you haven't tested restoring isn't a backup — it's a hope.

  • Follow the 3-2-1 rule: 3 copies, 2 media types, 1 offsite
  • Test full restores quarterly, not just backup completion
  • Keep at least one immutable or air-gapped copy
  • Document and rehearse a recovery runbook with RTO/RPO targets
  • Separate backup admin credentials from domain admin
Cloud Configuration Baseline
0/5

Most cloud incidents trace back to misconfiguration, not a novel exploit.

  • No public storage buckets or open management ports by default
  • Enforce MFA and Conditional Access at the identity provider layer
  • Centralise logging with defined retention
  • Apply CIS Benchmarks for each cloud provider in use
  • Tag and review unused or orphaned resources monthly
Incident Response Readiness
0/5

The plan you write during an incident is worse than the plan you wrote and rehearsed beforehand.

  • Maintain a written, tested IR plan with named roles
  • Pre-establish legal, forensics, and PR contacts before an incident
  • Define severity tiers and escalation timelines (NIST SP 800-61)
  • Run at least one tabletop exercise per year
  • Keep an offline copy of the IR plan itself

A common language for maturity.

Every assessment we run places you somewhere on this ladder — and gives you the specific, sequenced steps to move up it.

01
Ad Hoc
Reactive, undocumented, dependent on individuals.
02
Repeatable
Informal but consistent practices, not yet written down.
03
Defined
Documented and standardised across the organisation.
04
Managed
Measured and monitored against defined KPIs.
05
Optimized
Continuously improved, threat-informed, board-visible.
Next Steps

Ready to put people
at the centre of your practice?

If you'd rather have our people run the assessment — and train yours — than run it yourself, that's what our Cybersecurity practice is for.

Schedule a consultation See our services