Capability

What the practice is qualified to assess

An engagement is led by a senior consultant who carries out the assessment personally and signs the report. What matters to a client deciding whether to instruct us is the qualification behind that signature, so this page states the capability of the practice: what it covers, the certifications held, and the professional role profiles it spans.

Certifications are held by the individuals who do the assessment rather than by the letterhead. They are listed here in the aggregate, as capability available to an engagement, and they are verified at the point of assignment against the scope of the work.

The six practices and what each covers

Vetting
Independent assurance over systems, suppliers and people.
Governance, Risk & Compliance
Security that survives contact with an auditor and a regulator.
Technical Assurance & Offensive Security
Find it before someone else does, then fix the reason it was there.
Incident Response & Digital Forensics
When it has already happened, and the next hour decides how bad it gets.
CyberFinance
Digital operational resilience and financial crime defence for regulated finance.
Capability & Resourcing
Build security capability inside your organisation, or bring in ours.

Certifications held across the team

Held across the practice as a whole. No certification on this list is attributed to a named individual.

Certifications held

  • CISSP
  • CISM
  • CISA
  • CRISC
  • CGEIT
  • TOGAF 9
  • ISO/IEC 27001 Lead Auditor
  • CEH
  • CHFI
  • CSSLP
  • CompTIA CASP+

ECSF role profiles covered

Mapped to the European Cybersecurity Skills Framework published by ENISA, so a client can see the professional profiles an engagement can draw on and compare them with the profiles their own programme requires.

  • Chief Information Security Officer (CISO)
  • Cybersecurity Architect
  • Cybersecurity Auditor
  • Cybersecurity Risk Manager
  • Cybersecurity Implementer
  • Cyber Legal, Policy and Compliance Officer
  • Penetration Tester
  • Cyber Incident Responder
  • Digital Forensics Investigator
  • Cyber Threat Intelligence Specialist
  • Cybersecurity Educator

Working languages

Engagements are conducted in English and Romanian, on site or remotely, and reports are written to be read by boards, auditors and supervisory authorities in the jurisdiction that will ask for them.

Ask who would lead the work

Tell us what has to be assessed and we will set out the capability the engagement would be led with.

Contact