रक्षा

Raksha · protection

Engagements, not tasks.

Scoped work against a live environment: identity, devices, cloud posture, audit evidence, platform builds. Phased, documented, and priced against your estate after a scope call. There is no rate card here on purpose.

Security & Compliance

Locking down an estate, and proving it stayed locked down.

Zero Trust Access Rollout

Device-bound, context-aware access across identity, endpoints and SaaS.

  • Phased rollout plan with a written guide per phase
  • Device enrolment and posture signal collection
  • Access levels built and tested per persona
  • Enforcement across core and SAML applications
8 to 12 weeks, phasedScoped & quoted

SOC 2 Readiness Programme

Evidence, controls and engineering practice in place before the audit window.

  • Gap assessment against the Trust Services Criteria
  • Branch protection and dependency scanning baseline
  • Secret scanning and vulnerability management in CI
  • Evidence collection organised for the auditor
10 to 16 weeks to readinessScoped & quoted

ISO 27001 & Framework Mapping

One control set mapped across every framework you are asked about.

  • Statement of Applicability and risk register
  • Policy set written to be followed, not filed
  • Cross-mapping to SOC 2, NIST CSF and CIS
  • Internal audit programme and schedule
12 to 20 weeksScoped & quoted

Workspace Security Hardening

Baseline your tenant against published benchmarks, then close the gaps.

  • Automated conformance scan against published baselines
  • Findings prioritised by exploitability
  • Admin role, sharing and exfiltration review
  • Remediation applied and re-scanned to prove closure
3 to 6 weeksScoped & quoted

Security Review & Gap Assessment

Where you actually stand, in language your board can read.

  • Review across identity, endpoint, cloud and application
  • Findings ranked by exploitability and business impact
  • Plain-language summary for non-technical stakeholders
  • Remediation plan sequenced by dependency
2 to 4 weeksScoped & quoted

Vendor & Third-Party Risk

Answer the questionnaires you receive, ask better ones of your suppliers.

  • Inbound questionnaire and TPRM response preparation
  • Supplier assessment against a consistent rubric
  • Contract and access review from a security angle
  • A reusable answer library
2 to 6 weeksScoped & quoted

Incident Response Readiness

Know what you will do before the day you have to do it.

  • Incident response plan and severity model
  • Runbooks for the scenarios most likely to hit you
  • Tabletop exercise with the actual responders
  • Contact tree, escalation and comms templates
4 to 8 weeksScoped & quoted

Fractional Security Lead

Senior security ownership without a full-time hire.

  • Security roadmap owned and reported against
  • Customer security reviews and audits fronted
  • Engineering guidance on design decisions
  • Board and stakeholder reporting
Ongoing retainer, monthlyScoped & quoted
How an engagement starts. A thirty minute scope call, then a written scope with phases, deliverables and a fixed price for phase one. Work is delivered in phases, each leaving behind a written guide, so your team can run it again without us. Client names are withheld by default.