Cybersecurity and resilience
Reducing exposure, detecting compromise, and keeping essential functions running through an incident.
The issue
The problem as it presents itself.
The security of a critical organisation is not measured by the number of tools it has deployed, but by its ability to keep operating while an incident is under way. That requires knowing its assets, knowing which functions must survive first, and having rehearsed the response before it is needed.
Intended outcome
What the organisation gets.
An organisation that knows its critical assets, detects anomalies, contains an incident without stopping the service, and can restore within a defined time.
Before committing
Four preliminary questions.
An organisation that cannot answer these questions does not yet have a programme: it has an intention. Formulating them costs less than discovering them mid-delivery.
- 01Which functions must keep running if everything else stops, and for how long?
- 02Has your recovery plan been executed under real conditions, or only written and approved?
- 03How long passes between a compromise and its detection by your own means?
- 04Who decides to take a service offline during an incident, and has that person been designated in writing?
Our role
What we take on.
- Inventory of assets and ranking of essential functions.
- Risk analysis expressed against missions, not against technical vulnerabilities alone.
- Configuration hardening and reduction of the exposed surface.
- Detection, incident response and crisis exercises.
- Continuity and recovery planning, tested rather than merely written.
Security
Principles applied.
- Security built into the life cycle, from design through to decommissioning.
- Segmentation, least privilege, and separation of administrative access.
- Traceability of access and of privileged actions.
- Vulnerability and patch management against committed timescales.
Deployment
Available modes.
- On site, in an isolated environment where required.
- Under joint supervision with the client’s own teams.
- By full transfer to a centre operated by the client.
The mode depends on the organisation’s own sovereignty, continuity and classification requirements. It is settled before design, not after.
Service level during an incident
Levels, from top to bottom:nominal servicereduced service, essential functions maintainedservice interrupted
- Prepared organisation
- Unprepared organisation
- Before
- Critical assets are inventoried and the response has been rehearsed.
- Detection
- The anomaly is seen by monitoring, not reported by the user.
- Containment
- The affected perimeter is isolated; essential functions hold.
- Recovery
- Restoration follows a tested procedure, within a defined time.
Transfer of skills
End of engagement.
Skills development of internal teams in detection and response, moving progressively from supported operation to full autonomy.
Related domains.
Consultations · Pre-qualifications · Partnerships
Continue the conversation.
Detailed material — methodology, references, capability statement — is provided within a controlled framework, at the request of an identified organisation.