The Grid Model
Four moves, in order, every time.
Security programmes stall when they start in the middle — a tool bought before the estate was mapped, a policy written before anyone checked whether the control holds. We work in sequence, and each stage produces something you can inspect.
Map
You cannot defend a network you have never drawn.
Stage 1 of 4We start with two weeks of discovery: every asset, identity, cloud account, third-party connection and data flow. Not a questionnaire you fill in — telemetry we collect ourselves. Most engagements surface a meaningful number of systems the client did not know were still running.
What you get
Asset and identity inventory, data-flow map, ranked risk register
Harden
Fix the cheap things first, loudly.
Stage 2 of 4We sequence remediation by exploitability against effort, so the first month removes the attack paths that a real intruder would actually use. Nothing goes on a roadmap without an owner and a date, and we do the work rather than handing you a list.
What you get
Hardened baselines, closed exposures, documented exception register
Watch
Continuous monitoring, tuned to your environment.
Stage 3 of 4Telemetry flows into one correlated view and detections are written against how your business actually behaves. A finance tool that logs in from three countries is normal for you and suspicious for someone else — the rules should know the difference.
What you get
24×7 SOC coverage, tuned detection library, live dashboards
Respond
Rehearsed, pre-authorised, and written down.
Stage 4 of 4Containment actions are agreed before they are needed, so the response is measured in minutes. Every incident ends with a root-cause report and a change to the detection library, which is what stops the second occurrence.
What you get
Response runbook, tabletop exercises, post-incident reports
Principles
How we work, stated plainly enough to hold us to
These are the commitments we would want from a security partner, so they are the ones we make.
We do the work
Plenty of firms sell you a report. We would rather be measured on what actually got fixed, so remediation is inside the engagement rather than quoted separately afterwards.
Tool-agnostic by default
We have no resale quota to hit. If the licence you already pay for can do the job, we will configure it properly and tell you which of the others to cancel.
One pod, not a ticket queue
The engineers who onboard you stay with you. They learn your environment, and that knowledge is the difference between a fifteen-minute triage and a two-hour one.
Plain language
Reports go to boards and to engineers, so we write them for both. If a finding cannot be explained without a vendor acronym, it is not yet understood.
Evidence over assertion
Every claim we make about your posture is backed by something you can inspect. Dashboards are yours, not a screenshot we email monthly.
Honest about limits
If a control will not survive contact with how your teams work, we will say so at design time rather than write it into a policy nobody follows.
Commitments
The numbers we sign up to
These go in the contract. If we miss them, you have something to point at.
- 15 min
- Critical alert triageA named analyst — not an autoresponder — acknowledges every P1 within fifteen minutes, around the clock.
- 24×7×365
- Live SOC coverageFollow-the-sun rotation across two operations centres. No overnight queue that gets read at 9am.
- < 30 days
- Time to full coverageFrom signed order to complete telemetry, tuned detections and a documented response runbook.
- 1 pod
- One team, start to finishThe engineers who onboard you are the engineers who defend you. No handover to a stranger in month two.
Next step
Find out what an attacker would find first.
Twelve questions, four minutes, and a scored read of where your defences actually stand — or skip it and talk to an engineer directly.