रक्षा
Raksha · protection
Engagements, not tasks.
Scoped work against a live environment: identity, devices, cloud posture, audit evidence, platform builds. Phased, documented, and priced against your estate after a scope call. There is no rate card here on purpose.
Security & Compliance
Locking down an estate, and proving it stayed locked down.
Zero Trust Access Rollout
Device-bound, context-aware access across identity, endpoints and SaaS.
- Phased rollout plan with a written guide per phase
- Device enrolment and posture signal collection
- Access levels built and tested per persona
- Enforcement across core and SAML applications
SOC 2 Readiness Programme
Evidence, controls and engineering practice in place before the audit window.
- Gap assessment against the Trust Services Criteria
- Branch protection and dependency scanning baseline
- Secret scanning and vulnerability management in CI
- Evidence collection organised for the auditor
ISO 27001 & Framework Mapping
One control set mapped across every framework you are asked about.
- Statement of Applicability and risk register
- Policy set written to be followed, not filed
- Cross-mapping to SOC 2, NIST CSF and CIS
- Internal audit programme and schedule
Workspace Security Hardening
Baseline your tenant against published benchmarks, then close the gaps.
- Automated conformance scan against published baselines
- Findings prioritised by exploitability
- Admin role, sharing and exfiltration review
- Remediation applied and re-scanned to prove closure
Security Review & Gap Assessment
Where you actually stand, in language your board can read.
- Review across identity, endpoint, cloud and application
- Findings ranked by exploitability and business impact
- Plain-language summary for non-technical stakeholders
- Remediation plan sequenced by dependency
Vendor & Third-Party Risk
Answer the questionnaires you receive, ask better ones of your suppliers.
- Inbound questionnaire and TPRM response preparation
- Supplier assessment against a consistent rubric
- Contract and access review from a security angle
- A reusable answer library
Incident Response Readiness
Know what you will do before the day you have to do it.
- Incident response plan and severity model
- Runbooks for the scenarios most likely to hit you
- Tabletop exercise with the actual responders
- Contact tree, escalation and comms templates
Fractional Security Lead
Senior security ownership without a full-time hire.
- Security roadmap owned and reported against
- Customer security reviews and audits fronted
- Engineering guidance on design decisions
- Board and stakeholder reporting
Platform & Infrastructure
The machines, pipelines and monitoring underneath everything else.
CI/CD & Deployment Engineering
Pipelines that are fast, fail for real reasons, and nobody fears.
- Pipeline design, or rescue of an unmaintainable one
- Build time reduction with measurements to prove it
- Deployment, reverse proxy, DNS and certificates
- Rollback that has actually been tested
Monitoring & Alerting
Find out from a dashboard, not from a customer.
- Metrics, logs and uptime checks in one place
- Alerts tuned so they are worth waking up for
- Dashboards someone will actually read
- On-call rotation and escalation setup
Backup & Disaster Recovery
Backups you have restored from, not backups you hope work.
- Backup coverage audit across every system
- Restore tested end to end and timed
- Recovery objectives agreed and documented
- Runbook for the day it is needed
Identity & SSO Migration
One login, everywhere, without a fortnight of lockouts.
- Application inventory and integration plan
- SSO and provisioning rollout, app by app
- Group and role model that survives growth
- Offboarding that actually removes access
Product Engineering
Building the thing, and building it so somebody else can run it.
Multi-Tenant Platform Build
A platform built to be operated by someone other than its author.
- Multi-tenant architecture with isolation and RBAC
- Operator control panel: provisioning, trials, tiers
- Customisation layered so upgrades stay possible
- Deployment, database tuning and pooling
Internal Tooling & Automation
Kill the spreadsheet that three people maintain by hand.
- The manual process mapped before anything is built
- Tool built against how the work is really done
- Integrations with the systems you already run
- Handover documentation as a deliverable
Data & Reporting
Turning what you already collect into decisions.
Process & Enablement
Writing down how it works, then making it work better.