How scope is set
Every domain below can be dialled up or down
During discovery, your Executive Cyber Leader maps which of the nine domains carry the most risk for your organisation right now, and builds the roadmap around those first.
- No domain is compulsory — scope is agreed before work begins.
- Priorities are revisited at each reporting cycle as risk changes.
- Certification-driven domains (ISO 27001, Cyber Essentials) can be fast-tracked.
The register
Nine domains, grouped into three areas of focus
Every engagement draws from the same nine domains — grouped here into the three areas an Executive Cyber Leader actually works across, so it's easier to see where your priorities sit.
Cyber Leadership
Setting direction and owning accountability
Governance & Compliance
- Policy & procedure suite
- ISO 27001 / Cyber Essentials readiness
- Regulatory alignment (GDPR, DORA)
Risk Management
- Risk register & treatment plans
- Asset & information classification
- Board-level risk reporting
Culture & Awareness
- Staff training programmes
- Phishing simulation
- Executive & board briefings
Cyber Transformation
Building and hardening the technical estate
Cloud & Technology
- Architecture & configuration review
- Vendor-neutral tooling advice
- Cloud security posture assessment
Business Continuity
- Continuity & disaster recovery plans
- Resilience testing
- Recovery time / point objectives
Incident Response
- IR plans & playbooks
- Tabletop exercises
- Breach communications planning
Cyber Assurance
Proving controls actually work
Data Protection
- Data flow & access mapping
- Information handling controls
- Data loss prevention strategy
Third-Party & Supply Chain
- Supplier due-diligence process
- Contractual security requirements
- Ongoing vendor risk monitoring
Audit & Assurance
- Independent policy assurance review
- Audit preparation & support
- Control effectiveness testing
How work gets delivered
Every domain is delivered one of three ways
Before any work starts, we agree which mode applies — so scope and cost are clear from the outset.
Review
We assess what you already have — documents, controls or processes — and give you a clear, independent opinion on where it stands.
Refresh
We take existing material and bring it up to current best practice, aligned to the framework and regulations relevant to you.
Build
Where nothing exists yet, we create it from scratch — shaped around how your organisation actually operates.