Deep security expertise, we understand attackers and how defend against them
Risk-based objective evaluation of your controls, procedures and goals
Develop actionable insight and plans to guide your business
Governance
Our Governance services run the full spectrum from security governance to compliance and are designed to help organisations review and evaluate the maturity, effectiveness and efficiency of their existing security programs. We use industry standard maturity frameworks to measure you programs against best practices and identify gaps and areas for improvement.
Business Value
Assess the maturity of your current security program and identify areas for improvements
- Understand your organisations risk exposure
- Develop a roadmap for project investments and organisational change initatives
- Collect information to create benchmarks against other organisations
- Validating that your security investments have improved your security posture
Our Approach
Organisations need to measure their level of readiness with respect to security risks. You cannot improve what you do not measure. Our maturity assessments are based on Carnegie Mellon University’s CMMI framework for process improvement in combination with appropriate security frameworks.
The assessment begins with objective workshops to understand business objectives, risk exposure, risk tolerance and other factors.
We follow up this with a series of facilitated group sessions to identify additional areas of exposure and capture the current maturity level.
At the conclusion, we provide a written report that includes an executive summary, showing the high level analysis and findings, industry benchmarking, maturity mapping to the Capability Maturity Model, and prioritised action plan to adjust your program to the desired maturity level.
Deliverables
Our Governance Services
Our Cybersecurity Program Maturity Assessment is designed to help organisations review and evaluate the maturity, effectiveness and efficiency of their existing security program. Based on the Carnegie Mellon University’s CMMI framework for process improvement and leveraging the ISO 27001 security model, we can provide a baseline security assessment that helps your organisation identify gaps and areas for improvement.
This assessment will help you by:
- Assessing the maturity of your current security program and identify areas for improvement
- Understand your organisations risk exposure
- Develop a roadmap for project investments and organisations change initiatives
- Collect information to create benchmarks against other organisations
- Validating that your security investments have improved security posture
Organisations are progressively moving their core infrastructure operations, and business critical applications into the cloud. We review your operations across the dimensions of business alignment, organisational change management, workload analysis and infrastructure readiness. The Cloud Readiness Assessment was created to evaluate an enterprise’s potential to function in the cloud and to provide direction on ways to mitigate risks and improve agility.
This assessment will help you by:
- Refining your vision for the cloud
- Identify gaps or areas of concern that would impact your cloud adoption
- ROI / TCO to determine economic feasibility of moving to cloud
- Migration Roadmap
We help organisations review and evaluate their existing incident management programs as well as to provide guidance and best practice on the development of their incident response strategy. Organisations need incident management programs that are closely aligned with the threat profile of the business and the changing threat landscape.
This assessment will help you by:
- Assess your current IR strategy/program and develop a roadmap to mature it
- Identify gaps, manage risk and allocate resources to better protect your organisation
- Design and align your IR strategy with business goals and the changing security landscape
- Implement best practices and consistent execution of your incident response strategy
We conduct an assessment of your current third-party risk program to identify gaps through on-site and remote interviews with key personnel and a documentation review.
At the conclusion of the assessment you will:
- Understand the maturity of your program
- Have recommendations to improve your existing program