Services
Six domains. Take the ones you need.
Our services are modular. Most organisations do not need all six at once; they need one done properly, then the next. Whatever the scope, the same scale is applied, which is what makes a finding defensible when somebody asks how it was reached.
What we do
The six governance domains
These are the domains we assess and the areas we work in. They are the same six throughout: on this page, in the assessment, and in the profile your leadership team receives. Take one, a few, or all six.
-
01
IT strategy and accountability
Direction is either set deliberately, or it is set by whoever is loudest.
We establish who decides, who is accountable, and whether priorities follow your objectives rather than a supplier’s renewal cycle. You get decision rights recorded in one place, a strategy your leadership can approve, and a road map against which progress is visible.
-
02
Investment and delivery
Approved on a business case, then rarely measured against it.
We establish what is being spent, what it is delivering against the case that was made for it, how change is authorised and recorded, and where the portfolio has grown commitments nobody deliberately chose. You get investment criteria, a portfolio view and a change route that holds.
-
03
Operational resilience
The question is not whether something fails. It is what happens when it does.
We establish which services the organisation cannot operate without, how long it could run without them, and whether the arrangements for a critical system, site or supplier becoming unavailable have ever been tested rather than assumed. You get a continuity position based on evidence, with the gaps ranked by consequence.
-
04
Cybersecurity
Control coverage measured against the exposure you actually carry.
We assess the controls in place against your organisation’s real exposure rather than a generic checklist, and separate what is documented from what is working. You get a gap assessment, a ranked exposure register, and a remediation order that starts with consequence rather than convenience.
-
05
AI governance and literacy
Your people are already using it. The question is on what terms.
We establish where it is in use, on what information, under whose authority, and what has to be true before it influences a decision affecting a customer or an employee. You get an acceptable-use policy people can actually follow, a register of where it is used, a review route for anything high consequence, and a clear view of whether your people understand the rules.
-
06
Enterprise architecture
Systems accumulate faster than anyone maps them.
We set out how your systems, data and dependencies actually connect, where duplication and single points of failure sit, and what a realistic target state looks like. You get a current-state picture, a target state and a sequenced route between them.
Start here
The Preliminary Maturity Assessment
The usual way in. A scored, written picture of where you stand in the domains you choose, with a ranked plan for the next ninety days.
What you receive
- Governance profile with maturity ratings for the domains in scope
- One-page summary written for your leadership team
- Full assessment report, 10 to 12 pages
- Ranked exposure register, highest consequence first
- Prioritised 90-day action plan, with owners and effort estimates
- Sixty-minute findings presentation to your executive team
- Thirty-day follow-up call
Scope honesty
What we do not do
Not our work
- IT support, helpdesk or fixing equipment
- Selling or reselling hardware and software
- Building software or websites
- Installing or managing networks
- Supplier and third-party risk assessment
- Open-ended consulting with no defined end
Why that matters
We sell no technology and take no commission from anyone. Nothing sits behind the assessment, which is the point of commissioning it from outside rather than asking the supplier who installed the system.
It also means we will tell you when the answer is to do nothing, or to fix a process rather than buy a tool.
Next step
Take the first step
Most engagements start with a short discussion about what your organisation is trying to achieve and where technology is getting in the way. From there we agree a clear scope and a fixed price before any work begins.