Skip to main content

Services

Cybersecurity Governance & Vulnerability Management

We help organisations govern cybersecurity and manage vulnerabilities as an ongoing programme, with clear ownership and reporting to leadership.

What this covers

  • Cybersecurity governance and policy framework
  • Security risk assessment
  • Design of the vulnerability management process
  • Scoping and commissioning of scans and penetration tests, and follow-up of findings
  • Incident response planning
  • Standards for access control and secure configuration
  • Security measures and reporting to leadership
  • Supplier security assurance

How we work on this

The same five steps apply to every service, applied here to this work.

  1. Assess

    Understand your systems, data and the threats and obligations that apply.

  2. Identify

    Identify weaknesses in governance, process and technical exposure.

  3. Design

    Design policy, ownership and a workable vulnerability handling process.

  4. Implement

    Support your teams in running the process and acting on findings.

  5. Monitor & Improve

    Report on progress and adjust priorities as your exposure changes.

Who it's for

Discuss your cybersecurity governance requirements

Tell us what you are working towards and we will advise on where to start.