Plan

    Security strategy and architecture

    A target security architecture, a map of what your existing controls actually cover, and a sequence you can fund. It ends with a plan the board approves and the engineers recognise — not a list of products to buy.

    Duration

    4–6 weeks

    Built on

    ISO/IEC 27001:2022 · NIST CSF · CIS Controls

    Indicative price

    €8,500–19,000 per engagement

    Who this is for

    • CISO

      Needs to stop buying tactically and start building towards something.

    • CIO or CTO

      Is about to commit to a platform and wants the security design settled first.

    • CFO

      Sees the security line growing and cannot tell what it buys.

    • Board or audit committee

      Wants assurance that spending is deliberate.

    A list of tools is not an architecture

    Security estates accrete. An incident adds a product. An audit finding adds another. A vendor renewal that was easier to sign than to argue about adds a third. After a few years you have twenty or thirty tools, two of which do the same thing, three that nobody has looked at since the person who bought them left, and a licence bill nobody can defend line by line.

    The gaps, meanwhile, are rarely where the spending is. Coverage is dense around the things that were newsworthy when the budget was set, and thin around identity, logging and the supply chain — which is where the incidents actually start.

    So the useful question is not what to buy next. It is what the estate should look like when it is finished, what you already own that gets you there, and what order to do it in. That last part matters more than people expect: identity and logging are prerequisites, and doing them late makes everything built on top of them cost more and work worse.

    Identity is the real perimeter now, and most architectures still treat it as a supporting service. If an attacker's route into your environment is a valid credential — which it usually is — then privilege design, conditional access and session control are not identity hygiene. They are the architecture.

    We produce a target architecture, a control coverage map that shows what is genuinely protected and what only looks protected, a rationalisation list of what to retire, and a sequenced plan with the dependencies made explicit. You can fund it in stages and each stage stands on its own.

    How we do it

    1. 01

      Current state

      1–2 weeks

      Every security control and tool in the estate, what it actually covers, what it costs to run and what it overlaps with. We include the things nobody mentions — the free tier someone enabled, the agent still installed on half the fleet.

    2. 02

      Risk and threat input

      3–5 days

      The architecture has to defend against something specific. We take your risk assessment if you have one, and the realistic threat picture for your sector if you do not, and use it to weight the design.

    3. 03

      Target architecture

      1–2 weeks

      The end state: identity model, network and segmentation position, endpoint and workload protection, data protection and key management, logging and detection, and the boundaries between them. Designed for the organisation you are, not for a reference diagram.

    4. 04

      Control coverage and rationalisation

      1 week

      What you own mapped against the target. What covers a gap, what duplicates something else, what should be retired and what the retirement saves.

    5. 05

      Sequencing and funding case

      1 week

      The order, with dependencies stated, split into fundable stages. Each stage has a cost, an owner and a defensible reason for its position in the queue.

    6. 06

      Board presentation

      half a day

      Presented to the people who approve it, in their language, with the trade-offs visible rather than buried.

    Named artefacts

    What you receive

    • Control inventory — every tool, what it covers, what it costs to run
    • Control coverage map against the target architecture
    • Target security architecture, documented by domain
    • Identity and privilege model
    • Logging and detection design, including what must be retained and for how long
    • Rationalisation list, with the annual saving from each retirement
    • Sequenced roadmap with dependencies and fundable stages
    • Funding case and board pack

    What we need from you

    • A complete list of security tooling and its annual cost, including the renewals nobody reviews.
    • Architecture documentation and network diagrams, however out of date.
    • Time from the people who run identity, network and endpoint — they know where the design and the reality diverge.
    • Clarity on what is genuinely immovable. Every estate has constraints, and a design that ignores them is a document rather than a plan.

    What changes

    1. 01You know what your controls actually cover, rather than what the vendors claim.
    2. 02Spending is sequenced by dependency instead of by whoever asked most recently.
    3. 03Duplicated tooling is identified with a number attached to retiring it.
    4. 04The board approves a plan rather than a request.
    5. 05Each stage delivers something on its own, so a pause does not strand you mid-design.

    What it costs

    €8,500–19,000 per engagement

    All prices exclude VAT.

    Questions

    Will you recommend products?

    Where a capability is missing and you have nothing that covers it, yes, and we will say what we would choose and why. But most engagements find more value in retiring and consolidating than in buying, and we would rather your budget went on the sequence than on another agent.

    We already have a NIST CSF assessment. Is this the same thing?

    No. A framework assessment tells you your maturity against a model. This tells you what the estate should look like, what you already own that gets you there, and in what order — with costs. The assessment is a useful input to it.

    How long before it is out of date?

    The target architecture should hold for two to three years; the sequence needs reviewing quarterly, because priorities and threats move. That review is what the IT roadmap and quarterly review service exists to run.

    Leave with your top three risks documented

    Thirty minutes with a senior practitioner. No slideware, no sales engineer.