What usually brings people to this.
- Cyber security incidents and anomalies
- Security configuration issues
- Poor compliance status
A systematic evaluation of your security posture, on-premises and in cloud
We review the design and configuration of your IT infrastructure — on-premises or cloud — against cyber security best practice. The primary goal is to identify potential vulnerabilities, risks and weaknesses in the architecture and confirm that it adheres to recognised standards. The output is a risk-rated set of findings with a remediation plan and a target design.
-
01
Network security architecture
Review of network security design and control placement.
-
02
Server infrastructure security
Security architecture review across server and compute infrastructure.
-
03
Endpoint security architecture
Review of endpoint protection design and coverage.
-
04
Cloud security architecture
Security architecture review of cloud infrastructure and its integration points.
How the engagement runs.
A defined sequence, so you know what is happening at any point and what comes out of each stage.
-
01
Define security requirements
Establish the standard the architecture will be measured against.
- Business and regulatory drivers
- Applicable frameworks
- Scope and boundaries
-
02
Identify and classify assets
Know what is being protected and how much it matters.
- Asset inventory
- Data classification
- Criticality rating
-
03
Design security architecture components
Map the controls that should exist across the estate.
- Network controls
- Identity and access
- Endpoint and workload controls
-
04
Threat modelling and risk assessment
Work out what could realistically go wrong and what it would cost.
- Threat modelling
- Risk identification
- Impact and likelihood rating
-
05
Implement security controls
Define the controls to be put in place and their sequence.
- Control selection
- Prioritisation
- Implementation planning
-
06
Test and validate the architecture
Confirm the controls work as designed.
- Control validation
- Configuration verification
- Gap confirmation
-
07
Document and communicate security policies
Leave the organisation able to maintain the posture.
- Policy documentation
- Standards and procedures
- Stakeholder briefing
What you receive.
- 01Risk assessment and findings
- 02Security posture evaluation against an industry framework such as ISO 27001 or NIST
- 03Recommendations and remediation plans
- 04Short-term and long-term target design
What changes afterwards.
- Improved security posture
- Improved compliance posture
- Strategic alignment between security and business direction
- Improved user experience
Technologies and frameworks in scope
- ISO 27001
- NIST
- Azure
- AWS
Before you get in touch.
Does this cover cloud as well as on-premises infrastructure?
Yes — the review covers network, server, endpoint and cloud security architecture, whichever combination applies to your estate.
Do you just report findings, or design the fix as well?
Both — the output includes recommendations and remediation plans plus a short-term and long-term target design, not only a list of gaps.
Which frameworks is this assessed against?
ISO 27001 and NIST.
How long does the review take?
15 days for assessment plus one week for reporting.