The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
Proposal
The name comes from something that repeats in almost every environment: a small fraction of the actions delivers most of the risk reduction. We survey how your security stands today, score each discipline and hand you the plan in the order worth executing. If you only need a quick read before deciding, there is the health check; if you are taking a budget request to the board, you need the score and the plan.
No price appears on this page. Scope does: what we do, how we run it, who runs it and what is not included. The people who read your request are the ones who will look after you, and they come back with the proposal and with time to talk it through.
Where to invest first to take most of the risk off the table.
The name comes from something that repeats in almost every environment: a small fraction of the actions delivers most of the risk reduction. We survey how your security stands today, score each discipline and hand you the plan in the order worth executing. If you only need a quick read before deciding, there is the health check; if you are taking a budget request to the board, you need the score and the plan.
Evidence gathering
We collect what already exists: documents, configurations and logs. We start from what the company has, rather than from a blank form.
Interviews
We talk to IT, to security and to the business areas. Documents say what should happen; interviews say what does.
Maturity analysis
We compare the practice with what each discipline calls for and assign the score, with the criteria in the open.
Presentation
A meeting with the board, translating the technical finding into business risk and an investment decision.
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.