Domain 03 of four

Cybersecurity Governance, Risk and Resilience

Helping leadership teams establish effective oversight of cybersecurity, technology risk, business continuity and organisational resilience. The focus is governance and management accountability rather than technical security operations.

Start with the Cyber Governance and Resilience Preliminary Assessment

Why it matters

The problem this addresses

Security spending tends to follow whatever was most recently in the news, or whatever the last supplier presented. That produces strong controls in some places and nothing at all in others, with no way to tell which is which.

The question worth answering is not whether you have security tools. It is whether anyone owns the risk, whether leadership can see what matters, and whether the organisation would keep running.

Scope

The assessment may examine

  • Leadership accountability for cybersecurity
  • Cyber risk identification and reporting
  • Information security policies and responsibilities
  • Third-party and technology supplier dependencies
  • Incident governance and escalation arrangements
  • Business continuity and disaster recovery preparedness
  • Cybersecurity performance reporting
  • Priority control and governance weaknesses
Key standards
Framework alignment is a statement of method, not a certification claim.
ISO/IEC 27001
Information security management, controls and the statement of applicability.
NIST Cybersecurity Framework
Identify, Protect, Detect, Respond and Recover.
ISO 22301
Business continuity management, including impact analysis and exercises.
COBIT 2019
For accountability, decision rights and executive reporting.

Assessment

Included in the Assessment

  • Cyber governance maturity summary
  • Priority cyber and resilience risks
  • Key accountability and control gaps
  • Immediate risk-treatment recommendations
  • Executive findings presentation
  • Practical 90-day improvement roadmap
Price
Quoted on request. Each Preliminary Assessment is a paid, fixed-scope advisory engagement, confirmed before commencement based on the agreed scope, the number of stakeholders and the depth of evidence required.
Not an audit
Preliminary Assessments are advisory reviews. They are not certification audits, penetration tests, statutory audits, or formal legal and regulatory compliance opinions.

What this does not include

We do not sell, resell or install security products, and we do not carry out penetration testing or security operations. This is deliberate. An assessment of your governance is worth more when the organisation carrying it out has nothing to sell you at the end of it.

Implementation

Available as an Implementation Engagement

An assessment that ends at a report has done half the job. Building what it recommends is a separate engagement, scoped and quoted against what you need, and never bundled into the assessment.

Further advisory services

  • Cybersecurity governance frameworks
  • Cybersecurity maturity assessments
  • Information security policies and standards
  • Cyber risk management frameworks
  • Leadership and executive cybersecurity briefings
  • Cybersecurity performance dashboards
  • Third-party risk governance
  • Business continuity governance
  • Disaster recovery governance and assurance
  • Cyber incident governance
  • Cybersecurity improvement roadmaps
How it is priced
Quoted on request. Fixed scope and fixed fee, agreed in writing before work begins. We do not work on an open-ended basis.
Independence
Assessment and implementation are separately scoped engagements, quoted and agreed in writing before either begins. Keeping them separate is deliberate. It is what allows the assessment to stay independent, and it means you are never presented with findings that happen to recommend more of our own work. Where we have implemented something, any later re-assessment of that work says so plainly.

Intended outcomes

  • Clear ownership of cybersecurity risk
  • Improved visibility of material threats
  • Stronger executive oversight
  • Better prioritisation of security investment
  • Improved preparedness for disruption
  • Greater confidence in supplier and operational resilience

Where does this sit for you today?

If you are not sure whether this is the right starting point, the Quick Diagnosis takes about two minutes and gives you a position on the page. Nothing is sent anywhere.