Skip to main content
Agentic Online

Service group

Cybersecurity and Compliance

Security is a property of how a system is built, which is why we treat it as an engineering discipline rather than a review at the end. That includes the newer questions AI raises: what a model is allowed to see, what a tool is allowed to do, how prompt injection is contained, and how you evidence any of it to an auditor.

Services in this group

  • Cybersecurity solutions
  • Compliance and assurance
  • Secure-by-design engineering

The problem

What this service is for

If any of these describe your organisation, this is the right group to start with.

  • An audit, tender or client security questionnaire is coming and the evidence doesn't exist.
  • Access has accumulated over years and nobody can say who can reach what.
  • Secrets are held in configuration files, chat messages and people's memories.
  • An AI system is being considered but the security and privacy questions are unanswered.
  • Security findings arrive as a list of issues with no prioritisation or remediation plan.

What we do

Services included in this group

Cybersecurity solutions

Identity and access design, secrets management, network and application hardening, logging and monitoring for detection, and incident response preparation with defined roles and escalation paths.

Compliance and assurance

Mapping your controls to the obligations that apply — data protection, sector rules, contractual and procurement requirements — and producing the documented evidence an assessor will ask for.

Secure-by-design engineering

Threat modelling, secure architecture and code review, dependency and supply-chain checks in CI, and AI-specific controls: tool permission scoping, output validation, prompt-injection containment and data-handling boundaries.

Key deliverables

What you receive

Tangible artefacts, not a status report. Everything below is handed over and belongs to you.

  • Threat model for the system in scope, with prioritised, ranked findings
  • Identity, access and secrets management design and implementation plan
  • Security control mapping to applicable obligations, with evidence locations
  • AI-specific control set: data boundaries, tool scoping, output validation, injection containment
  • Automated security checks in CI: dependency scanning, secret detection, policy tests
  • Logging, monitoring and alerting design for detection and investigation
  • Incident response plan with roles, escalation and communication templates

Expected outcomes

What changes as a result

Described as what the deliverable makes possible. We do not guarantee business results, and any figure we quote will be one you can verify.

  • Findings arrive ranked by exploitability and impact, with a remediation sequence you can resource
  • Access can be evidenced from source rather than reconstructed from memory
  • Secrets live in a managed store with rotation, and stop appearing in repositories
  • AI features have explicit, documented boundaries on data access and permitted actions
  • Security questionnaires and audits draw on evidence that already exists

Technologies

What we build with

Chosen for fit rather than fashion. Where your organisation has a standardised technology set, we work within it or make a documented case for an exception.

  • OAuth 2.1, OpenID Connect, SAML
  • Managed secrets stores and key management services
  • Static analysis, dependency and container scanning
  • Web application firewalls and edge protection
  • SIEM and centralised log analysis
  • Content Security Policy and browser security headers
  • AI guardrail, evaluation and red-teaming tooling

Engagement options

How to start with this service

Most engagements begin with the smallest bounded commitment that answers the open question.

Discovery sprintTypically 1–2 weeks, fixed fee
A short, bounded piece of work that turns a broad ambition into a defined problem, a recommended approach and a costed plan. You keep the outputs whether or not we build the solution.
Fixed-scope deliveryDefined outcome, milestone-based
An agreed scope, acceptance criteria and milestone schedule. Change is handled through a written change process rather than absorbed silently.
Managed serviceOngoing, agreed response targets
Continuing operation, monitoring, patching and improvement of a system we or another supplier built, under response and resolution targets agreed in writing.

Talk to us about cybersecurity & compliance

Tell us the problem in your own words. If this is the wrong service for it, we will say so and point you at the right one — including at another supplier if that is the honest answer.

We reply to every enquiry within one business day.