Detailed information for all 52 services across 3 domains — click any card to expand details.



AI strategy, governance, risk and ethics services to help you deploy artificial intelligence responsibly and effectively.
Assessment of AI governance maturity against NIST AI RMF, ISO 42001 and PCPD AI Guidance. Covers: AI inventory, risk classification, accountability structures, transparency mechanisms, human oversight and bias management.
AI governance maturity report with scored assessment, gap analysis, governance framework recommendations and board-ready executive summary.
Technical audit of AI/ML models: bias testing across protected characteristics, fairness metrics (equal opportunity, demographic parity), explainability analysis and robustness testing against adversarial inputs.
AI audit report with bias findings, fairness metrics dashboard, model card documentation and remediation recommendations.
Development of a comprehensive AI Employee Usage Policy covering: approved AI tools, prohibited use cases (sensitive data, IP, customer PII), data classification rules, review and approval processes and consequences for violations.
AI Usage Policy document (editable), quick-reference staff guide, department head briefing notes and implementation checklist.
AI-specific security testing following OWASP Top 10 for LLM Applications and MITRE ATLAS framework. Covers: prompt injection, jailbreaking, training data extraction, model theft, supply chain vulnerabilities and plugin security.
AI security assessment report with vulnerability findings, threat modelling output, attack scenarios and remediation guidance.
Development of AI vendor evaluation criteria: security requirements, data handling, model transparency, SLA review, exit strategy. Assessment of up to 3 shortlisted vendors against the criteria, with scoring and recommendations.
Vendor evaluation framework document, scored vendor comparison matrix, recommendations report and due diligence checklist.
Risk assessment of agentic AI deployments: autonomy boundaries, action approval chains, credential management, sandbox effectiveness, logging and audit trail completeness and rollback capability. Aligned to emerging regulatory guidance.
Agentic AI risk assessment report, threat model, control framework recommendations and board-ready risk summary.
Compliance assessment against key Gen AI regulatory frameworks: EU AI Act (provisional), China Gen AI Measures, PCPD AI Guidance and Singapore AI Verify. Covers training data governance, content labelling and transparency requirements.
Gen AI compliance report with regulatory mapping, gap analysis, compliance roadmap and staff Gen AI usage guidelines.
Development of a bespoke AI Ethics Framework covering: fairness, transparency, accountability, privacy, safety and human-centric values. Includes stakeholder workshops, principle definition, operational guidelines and governance structures.
AI Ethics Framework document, principle-to-practice mapping, ethics review board terms of reference and implementation roadmap.
Half-day or full-day AI governance training for board members and senior management. Covers: AI risk landscape, regulatory developments, governance frameworks (NIST AI RMF, ISO 42001), board oversight responsibilities and case studies.
Training slide deck (editable), participant workbook, case study materials, completion certificates and a management briefing report.
Development of an AI Procurement Framework: pre-procurement risk classification, mandatory due diligence checklist, contract clause library (data rights, model access, audit rights, termination) and post-procurement monitoring process.
AI Procurement Framework document, due diligence template, contract clause library and procurement workflow diagram.
Assess exposure to AI-specific incident scenarios and review current response capability against them. Develop a tailored AI Incident Response Plan aligned with your existing IR framework, covering roles, escalation, evidence handling and regulatory notification. Validate the plan with a facilitated online tabletop exercise.
AI Incident Response Plan document (editable), AI incident scenario register with severity classification, detection and escalation playbooks per scenario, online tabletop exercise (half-day) and after-action report.
Identify where AI adds most value for your business: efficiency, product or customer experience. Assess current AI usage, data readiness and staff capability to set a realistic baseline. Develop a phased adoption roadmap with quick wins in the first 90 days, governance touchpoints and success metrics. Deliverables are agreed at kick-off and vary with your starting point.
AI Adoption Strategy document with phased roadmap, AI opportunity map (quick wins vs strategic bets), data and tool readiness checklist, 90-day action plan with success metrics.
Governance frameworks, risk assessments and compliance services to keep your organisation secure and accountable.
Board-level strategic advisory on an on-demand basis. Covers: technology strategy alignment, cyber risk appetite definition, digital transformation governance, regulatory horizon scanning and technology investment prioritisation.
Board briefing pack per session, action items log, risk dashboard update and follow-up advisory note.
On-demand management consulting across technology, security and privacy domains. Typical engagements: strategy development, operating model design, transformation roadmap, vendor negotiations advisory and organisational design.
Agreed deliverables per engagement – typically a strategy document, roadmap or assessment report with executive summary.
End-to-end vendor selection support: requirements definition, RFP document creation, vendor shortlisting, proposal evaluation against weighted criteria, demo/presentation scoring and final recommendation report.
Requirements specification, RFP document, vendor evaluation matrix with scores and final recommendation report with rationale.
Creation of professional RFP/tender documents for technology, security or privacy services. Covers: scope definition, technical requirements, evaluation criteria, pricing structure, service levels and contractual terms.
Complete RFP/tender document (Word/PDF), evaluation criteria matrix and proposer Q&A template.
Independent post-implementation review of technology, security or privacy projects. Covers: delivery against scope, budget and timeline; benefits realisation; user adoption; lessons learned; and recommendations for future projects.
Post-implementation review report, benefits realisation assessment, lessons-learned register and improvement recommendations.
Review of IT spend: software licensing, cloud consumption, SaaS subscriptions, hardware maintenance and managed services. Benchmarking against industry peers and identification of consolidation, renegotiation and optimisation opportunities.
IT cost optimisation report with saving opportunities ranked by impact and effort, total cost of ownership models and an implementation roadmap.
Review of system architecture covering: scalability, resilience, security, data architecture, integration patterns, technology stack fitness and alignment with business goals. Produces a modernisation roadmap.
Architecture assessment report with current-state and target-state diagrams, risk register, modernisation roadmap and executive summary.
Establish risk appetite in industry-specific terms, aligned to regulatory expectations and board accountability. Facilitate board-level workshops to define risk tolerance statements across technology, cyber and AI risk. Assess current posture against the agreed appetite and produce a gap view with escalation triggers.
Industry risk appetite statement (board-approved wording), risk tolerance matrix for technology, cyber and AI domains, board workshop facilitation (one session) and minutes, posture vs appetite gap report with escalation triggers.
End-to-end Business Impact Analysis: process identification, impact assessment (financial, operational, regulatory, reputational), recovery time objectives (RTO) and recovery point objectives (RPO) definition and criticality ranking.
BIA report with process criticality matrix, RTO/RPO recommendations per process, dependency map and executive summary.
Development of a comprehensive Business Continuity Plan covering: crisis management structure, communication protocols, recovery procedures for critical processes, alternate site arrangements and resource requirements. Aligned to ISO 22301.
BCP document, crisis communication templates, team contact cards and a BCP maintenance schedule.
Development of a Crisis Communication Plan: stakeholder mapping, communication channels, message templates for different scenarios (data breach, service outage, regulatory action), spokesperson designation and media handling guidelines.
Crisis Communication Plan document, message template library, stakeholder contact matrix and spokesperson briefing guide.
Comprehensive security risk assessment following ISO 27005 methodology: asset identification, threat and vulnerability assessment, risk analysis (likelihood × impact), risk treatment recommendations and residual risk acceptance.
SRAA report with asset register, threat catalogue, risk register with risk ratings, risk treatment plan and executive summary.
Assessment of ransomware preparedness across the NIST CSF functions: Identify (asset inventory, risk assessment), Protect (backups, access control, awareness), Detect (monitoring, alerting), Respond (IR plan, containment), Recover (restoration, communications).
Ransomware preparedness report with maturity scores per NIST function, gap analysis, prioritised improvement roadmap and board-ready summary.
Assessment against PCI DSS v4.0 requirements: scoping validation, gap analysis across all 12 requirements, compensating control evaluation and remediation planning. Covers both merchant and service provider requirements.
PCI DSS readiness report with requirement-by-requirement findings, gap analysis, remediation plan with priorities and SAQ determination guidance.
Cyber resilience, data protection and privacy services to defend against modern threats.
A structured assessment covering 12 security domains: access control, network security, endpoint protection, patch management, backup, incident response, third-party risk, physical security and more. Includes automated scans and manual review by a certified practitioner.
Executive summary report with risk ratings (High/Medium/Low), a prioritised remediation roadmap and a one-page dashboard for board presentation.
Automated vulnerability scanning of internal and external network assets, web applications and cloud configurations. Manual validation of findings to eliminate false positives. Includes CVSS scoring and exploitability analysis.
Detailed vulnerability report with CVSS scores, affected assets inventory, remediation steps ranked by criticality and an executive summary.
Manual penetration testing following OWASP Testing Guide v4. Covers injection flaws, broken authentication, sensitive data exposure, XXE, broken access control, security misconfiguration, XSS, insecure deserialisation and more. Performed by CREST-certified or OSCP-certified testers.
Full penetration test report with proof-of-concept exploits, risk impact analysis, remediation guidance per finding and a stakeholder presentation deck.
Review of existing security policies against ISO 27001 / NIST standards or creation of new policies from templates tailored to your business. Covers: Acceptable Use, Access Control, Password, Incident Response, Data Classification and more.
Gap analysis of existing policies, updated or newly drafted policy documents in editable format, implementation checklist and staff communication templates.
End-to-end review of your security architecture: network segmentation, identity and access management architecture, data flow diagrams, cloud security controls, logging and monitoring architecture. Aligned to TOGAF and SABSA frameworks.
Architecture assessment report with risk-annotated diagrams, a prioritised remediation roadmap and executive summary.
Vendor risk assessment framework implementation: classification criteria, risk tiering, due diligence questionnaires, ongoing monitoring process. Review of up to 10 critical vendors. Includes contract clause templates for security requirements.
Vendor risk management framework document, vendor risk register, sample completed assessments for up to 3 vendors and a board-ready summary.
Assessment of cloud environment (AWS/Azure/GCP) against CIS Benchmarks and cloud provider Well-Architected Frameworks. Covers IAM, network security, encryption, logging, backup and cost optimisation. Includes automated scanning where applicable.
Cloud security posture report with misconfiguration findings, compliance mapping, remediation playbook and architecture improvement recommendations.
Design and execution of a phishing simulation campaign: 3 staged emails over 2 weeks with increasing sophistication. Includes landing page capture, click-rate metrics and a post-campaign awareness training session for all staff.
Campaign results report with click rates by department, benchmark comparison, lesson-learned summary and training completion certificates.
Review of backup strategy, retention policies, off-site storage, recovery time objectives (RTO) and recovery point objectives (RPO). Includes restore testing of a sample dataset to verify recoverability.
Backup maturity assessment report, gap analysis against 3-2-1 backup best practices, RTO/RPO recommendations and a tested restore procedure document.
Review of endpoint protection configuration across Windows, macOS and mobile devices. Covers: EDR/XDR deployment, patch management, device encryption, USB control, application whitelisting and MDM policies.
Endpoint security assessment report, configuration hardening guide and a prioritised remediation plan.
Assessment of email security controls: SPF, DKIM, DMARC configuration review, email gateway configuration, anti-spam and anti-malware effectiveness and BEC protection maturity.
Email security report with DMARC compliance score, configuration gaps, impersonation risk rating and step-by-step remediation guide.
Development or review of an Incident Response Plan aligned to NIST SP 800-61. Includes a half-day tabletop exercise (TTX) simulating a ransomware scenario with key stakeholders. Debrief and after-action report.
Updated IR Plan document, TTX scenario pack, after-action report with findings and recommendations and an improvement roadmap.
Customised security awareness training session (half-day or full-day) covering: phishing, password hygiene, social engineering, clean desk policy, remote work security and incident reporting. Includes interactive quizzes and scenarios.
Training slide deck (editable), attendance records, quiz results summary, training completion certificates and a management report.
Monthly retainer including: virtual CISO attendance at management meetings, security strategy development, policy oversight, vendor security reviews, incident response advisory and board reporting. Minimum 3-month commitment.
Monthly security dashboard report, board presentation deck, policy updates as needed and ad-hoc advisory (up to 10 hours/month).
Security assessment of iOS and Android applications following OWASP Mobile Top 10. Includes static analysis, dynamic runtime testing, API security testing, local storage review and SSL/TLS validation.
Mobile security assessment report with vulnerability findings, risk ratings, proof-of-concept where applicable and remediation guidance per platform.
Comprehensive assessment against all 6 Data Protection Principles (DPPs) of the PDPO: purpose and collection, accuracy and retention, use, security, transparency and access/correction. Includes document review, staff interviews and gap analysis.
PDPO compliance report with DPP-by-DPP findings, risk ratings, gap analysis and a prioritised remediation plan with timelines.
End-to-end DPIA following PCPD guidelines: data flow mapping, necessity and proportionality assessment, risk identification and mitigation, stakeholder consultation and documentation of residual risks.
Complete DPIA report with data flow diagrams, risk assessment matrix, mitigation measures and sign-off recommendations.
Discovery and documentation of personal data flows across the organisation: what data is collected, where it is stored, who has access, how it is shared and when it is deleted. Includes stakeholder workshops and system reviews.
Data inventory register, data flow diagrams (Visio/PDF), Record of Processing Activities (ROPA) template and gap analysis against PDPO DPP1.
Drafting or review of external Privacy Policy, Personal Information Collection Statement (PICS) and internal data handling procedures. Tailored to your actual data processing activities and aligned with PDPO requirements.
Bespoke Privacy Policy and PICS documents (bilingual EN/TC), implementation guide and staff briefing notes.
Review of cross-border personal data flows: identification of all data transfers (including cloud storage, SaaS tools, group company sharing), assessment of legal basis for transfer, adequacy review and recommended safeguards (SCCs, BCRs, contractual clauses).
Cross-border data transfer register, risk assessment per transfer, legal basis documentation and recommended safeguard measures.
Development of a Data Breach Response Plan covering: detection, containment, investigation, notification (PCPD, data subjects, media) and remediation. Includes a half-day tabletop exercise simulating a personal data breach scenario.
Data Breach Response Plan document, TTX scenario pack, after-action report, PCPD notification template and staff communication templates.
Assessment against PCPD AI guidance: transparency, accountability, data minimisation, bias mitigation, human oversight and data subject rights in AI decision-making. Covers both in-house and third-party AI systems.
AI compliance gap report mapped to PCPD guidance, risk register, policy recommendations and staff AI usage guidelines.
Drafting an Employee AI Usage Policy covering: approved tools, prohibited uses, data classification rules, confidentiality obligations and disciplinary measures. Includes a 2-hour training session for all staff.
Employee AI Usage Policy document, training slide deck, attendance record and a management compliance checklist.
Assessment of biometric data processing: fingerprint, facial recognition, voiceprint. Covers: legal basis for collection, consent mechanisms, retention periods, security safeguards and compliance with PDPO and international standards.
Biometric data assessment report, consent form templates, retention and deletion policy and gap analysis against regulatory requirements.
Monthly retainer including: virtual DPO representation, PCPD liaison, privacy impact assessment oversight, data breach advisory, staff training coordination and quarterly compliance reporting. Minimum 3-month commitment.
Monthly privacy dashboard, quarterly compliance report, PCPD correspondence handling and ad-hoc privacy advisory (up to 10 hours/month).
Assessment against PIPL requirements: legal basis for processing, consent mechanisms, data localisation, cross-border transfer assessment, data subject rights, DPO appointment and impact assessments for sensitive data.
PIPL compliance report, gap analysis with remediation roadmap, data localisation assessment and cross-border transfer documentation.