Services

Five ways to work together — as a one-off assessment, an embedded build, or ongoing advisory.

Every engagement is scoped directly with David, not a sales team.

01

Cloud Security & Architecture

Design and harden environments across AWS, Azure, and GCP. Zero Trust architecture, IAM and Microsoft Entra ID configuration, and secure-by-design cloud migrations — built to hold up under audit, not just under a demo.

02

DevSecOps & CI/CD Security

Security folded into the pipeline itself: Terraform-driven infrastructure-as-code, GitHub Actions security gates, dependency and vulnerability scanning with Snyk, and secrets management done properly — so security stops being the thing that blocks a release.

03

Security Operations & SIEM Engineering

SIEM design and tuning across Splunk, Datadog, and Microsoft Sentinel, endpoint protection with CrowdStrike Falcon, and detection engineering that's built around your actual threat model — not a vendor's default ruleset.

04

Compliance & Governance

ISO 27001 and SOC 2 readiness, audit preparation, and continuous compliance monitoring with tools like Drata — framed as an engineering problem with a paper trail, not a paperwork problem with a deadline.

05

Fractional Security Leadership

For organisations that need senior security judgement at the table — architecture reviews, board-level risk reporting, vendor evaluation — without the cost or commitment of a full-time CISO hire.

Engagement Models

How the work is structured.

Fixed-scope assessment

A bounded piece of work (e.g. a cloud security review or SOC 2 readiness gap analysis) with a clear deliverable and timeline.

Project-based build

Hands-on implementation work (e.g. a CI/CD security overhaul or SIEM migration) scoped to a defined outcome.

Retained advisory

Ongoing access on a day-rate or monthly-retainer basis for organisations that want continuity rather than a one-off engagement.

Not sure which model fits? Let's talk it through.