Six practices · Thirty-three services

What we do

The portfolio has a shape. Vetting and Technical Assurance establish what is true — independently, and against a defined standard. Governance decides what to do about it and builds the structure that keeps the decision holding.

CyberFinance applies both to regulated finance, where the same evidence has to satisfy a supervisor. Incident Response is what happens when the assessment came too late. Capability & Resourcing builds security capability inside the client organisation, so the work continues once an engagement closes.

The six practices

Independence

CYBERVETTER does not resell security products, does not manage client infrastructure and does not issue certifications. Each is revenue deliberately foregone, so that the advice stays clean.

It means a finding cannot be a sales lead, a recommended control cannot be a product we profit from, and an assessment cannot be softened to protect an operational relationship. You are buying judgement, and nothing sits behind it.

How independence is maintained

  • We do not resell security products.
  • We do not manage client infrastructure.
  • We do not issue certifications.