Industries

Regulated, audited, and accountable to somebody.

We work best where security is not optional, where a regulator, a prime contractor, an insurer or your largest customer is going to check. Context matters: the same control means different things in a hospital and a factory.

Healthcare & Life Sciences

HIPAA and HITRUST, connected medical devices, clinical system uptime, and business associate risk across a sprawling vendor base.

HIPAA Security RuleHITRUST CSFFDA premarket cybersecurity42 CFR Part 2

Financial Services

Examiner-ready programs, third-party concentration risk, and controls that hold up under regulatory scrutiny rather than just internal review.

GLBA SafeguardsNYDFS Part 500FFIEC CATPCI DSS 4.0

Technology & SaaS

Enterprise buyers auditing your product. Multi-tenant isolation, SOC 2 and ISO 27001, and a security story that shortens the sales cycle.

SOC 2 Type IIISO 27001OWASP ASVSCustomer security review

Government & Defense

CMMC Level 1 and 2, CUI enclave design, and the evidence discipline that survives a real assessment rather than a self-attestation.

CMMC 2.0NIST SP 800-171FedRAMP readinessDFARS 7012

Manufacturing & Industrial

IT/OT boundary security, ransomware resilience where downtime is measured in shifts, and supply chain requirements flowing down from primes.

IEC 62443NIST CSF 2.0CMMC flow-downOT segmentation

Professional & Legal Services

Client confidentiality obligations, outside counsel guidelines, and the security requirements your largest clients now impose contractually.

ISO 27001Client OCG complianceSOC 2Data residency

Energy & Utilities

Critical infrastructure resilience, regulator expectations, and OT environments that were never designed to be connected.

NERC CIPTSA directivesIEC 62443NIST CSF 2.0

Education

Student data protection, research security obligations, and a decentralised IT reality that makes central policy hard to enforce.

FERPAGLBA SafeguardsNIST SP 800-171Research security

Retail & eCommerce

Payment security, fraud and account takeover, and a martech stack quietly moving customer data to places nobody approved.

PCI DSS 4.0CCPA / CPRAGDPRFraud controls

Nonprofit & NGO

Grant and donor data obligations, funder security requirements, and meaningful risk reduction on a budget that has no slack.

Donor data protectionGrant requirementsNIST CSF 2.0Cyber insurance
Not on the list?

The pattern travels further than the vertical does.

If your organization holds data somebody else cares about, depends on systems that cannot go down, or has to prove its controls to a third party, the work looks broadly similar. Tell us the specifics and we will tell you honestly whether we are the right firm.

Start with a straight conversation

Thirty minutes, no deck, no pitch. Tell us what prompted the call and we will tell you what we would do about it, including when the answer is that you do not need us yet.