Persona A
The executive who owns the outcome
A board, a regulator, or a customer questionnaire is asking questions you cannot answer from tribal knowledge. You need a program with a named owner — not another tool trial.
SU-01 · Drawing — security program
Security, drawn before it is bolted on
Fractional vCISO, GRC on eramba, and hands-on engineering for SMBs, public bodies, and teams moving to cloud or agentic systems. Consultation is global. We design the controls with the architecture — then we stay to run them.
Scroll · SU-02SU-02 · Who this is for
If you already have a 200-person security org, you do not need us. If you are accountable for risk and still doing it from inboxes and a shared drive, you do.
Persona A
A board, a regulator, or a customer questionnaire is asking questions you cannot answer from tribal knowledge. You need a program with a named owner — not another tool trial.
Persona B
AWS or Azure is already in motion. Identity, logging, and network pathing were supposed to come “next sprint.” We put CloudSec and ZTNA on the same drawing as the workload.
Persona C
Agentic automation is useful until it has standing access, no audit trail, and no one who can explain it to a regulator. We treat agents as identities with a control plane.
SU-03 · Scope of work
Six primary practices. Named, bounded, and staffed by the same people who write the plan. We are not a 24/7 SOC-as-a-service — if that is what you need, we will say so and help you buy it cleanly.
Implement and operate GRC in eramba: risk, compliance, policies, assessments, incidents, and the workflows that keep ISO 27001 and similar programs alive. Flat-fee GRC instead of a module catalogue. We configure it so people use it.
Security leadership on a retainer: board reporting, policy, vendor pressure, incident counsel, and the unglamorous work of making owners actually own controls. A CISO function you can staff without a full-time seat.
Defensive build work informed by MITRE ATT&CK and SOC operating principles: detection design, identity, logging, and CloudSec on AWS and Azure. Engineering, not a black-box appliance.
Threat models, tool-use boundaries, secrets handling, evaluation, and governance for systems that act. If the agent can change production, it gets the same scrutiny as a privileged human.
Cloud cost with security constraints attached: idle attack surface is a bill and a risk. We line spend, tagging, and control coverage so finance and security argue from the same numbers.
Strategy, operating cadence, and hiring plans for teams that cannot yet name a security org chart. We write the program you can hand to the next internal lead without a cliff-edge.
SU-04 · Method
A consulting sequence, not a sensor rollout. You see the drawing before anyone buys a box.
01
Obligations, systems, identities, and the gaps between policy and production. Written, not workshop-theatre.
02
The program, the control set, and the tooling — eramba, Cloudflare ZTNA, cloud accounts — on one architecture.
03
Fractional leadership and engineering until your people can hold it. Exit is part of the design, not a surprise.
SU-05 · Engagement
No per-endpoint mystery price. We will not invent a number on this page that we cannot defend in a statement of work.
Advisory
Embedded
Build
SU-06 · Also in the kit
Authn/z, abuse cases, and contract testing for the interfaces your agents and partners actually call.
Zero-trust access on Cloudflare: replace the castle VPN with identity-aware paths.
Third-party risk that fits the real vendor list, not a 400-question PDF no one returns.
Use-case intake, data classes, and human-in-the-loop rules that survive an audit.
Implementation, not a binder. Statement of Applicability tied to eramba records.
A rhythm: discover, prioritize, patch or accept, prove it. No dashboard tourism.
Use-case design, playbooks, and retainer counsel. We do not fake a follow-the-sun SOC.
Recovery objectives that match the business, then the platform choice — not the reverse.
SU-07 · Plain answers
No. We design and run security programs: leadership, GRC, and engineering. If you need a staffed SOC, we help you specify it and hold the vendor to the SLA — we will not sell you one we do not operate.
Most GRC suites charge by module, user, or framework. eramba is open GRC software used for risk, compliance, policies, assessments, and related workflows, with a simple enterprise model. We implement it so the register matches how you actually work.
A scoping conversation this week. A written plan before tools. Implementation on a calendar you can show a board. We will not promise “protected in 48 hours” unless the work is that small.
Consultation is global. Delivery is remote-first. If a control or a regulator needs data to stay in a region, we say so in the design — including when eramba should be on-prem rather than SaaS.
No. Handover is a deliverable: system ownership, documentation, and a named internal successor. Vendor lock-in is a design smell. We treat it that way.
SU-08 · Contact
A short form. No nurture sequence. If chat is faster, use the bubble.