SU-01 · Drawing — security program

Security, drawn before it is bolted on

The program you’d staff if you had the people.

Fractional vCISO, GRC on eramba, and hands-on engineering for SMBs, public bodies, and teams moving to cloud or agentic systems. Consultation is global. We design the controls with the architecture — then we stay to run them.

Scroll · SU-02

SU-02 · Who this is for

Built for operators, not for a logo wall.

If you already have a 200-person security org, you do not need us. If you are accountable for risk and still doing it from inboxes and a shared drive, you do.

Persona A

The executive who owns the outcome

A board, a regulator, or a customer questionnaire is asking questions you cannot answer from tribal knowledge. You need a program with a named owner — not another tool trial.

Persona B

The IT lead mid-migration

AWS or Azure is already in motion. Identity, logging, and network pathing were supposed to come “next sprint.” We put CloudSec and ZTNA on the same drawing as the workload.

Persona C

The team wiring in agents

Agentic automation is useful until it has standing access, no audit trail, and no one who can explain it to a regulator. We treat agents as identities with a control plane.

SU-03 · Scope of work

What we actually do.

Six primary practices. Named, bounded, and staffed by the same people who write the plan. We are not a 24/7 SOC-as-a-service — if that is what you need, we will say so and help you buy it cleanly.

GRC on eramba

Implement and operate GRC in eramba: risk, compliance, policies, assessments, incidents, and the workflows that keep ISO 27001 and similar programs alive. Flat-fee GRC instead of a module catalogue. We configure it so people use it.

Fractional vCISO

Security leadership on a retainer: board reporting, policy, vendor pressure, incident counsel, and the unglamorous work of making owners actually own controls. A CISO function you can staff without a full-time seat.

Security engineering

Defensive build work informed by MITRE ATT&CK and SOC operating principles: detection design, identity, logging, and CloudSec on AWS and Azure. Engineering, not a black-box appliance.

Agentic AI security

Threat models, tool-use boundaries, secrets handling, evaluation, and governance for systems that act. If the agent can change production, it gets the same scrutiny as a privileged human.

FinOps

Cloud cost with security constraints attached: idle attack surface is a bill and a risk. We line spend, tagging, and control coverage so finance and security argue from the same numbers.

Security leadership

Strategy, operating cadence, and hiring plans for teams that cannot yet name a security org chart. We write the program you can hand to the next internal lead without a cliff-edge.

SU-04 · Method

Map. Design. Run.

A consulting sequence, not a sensor rollout. You see the drawing before anyone buys a box.

01

Map

Obligations, systems, identities, and the gaps between policy and production. Written, not workshop-theatre.

02

Design

The program, the control set, and the tooling — eramba, Cloudflare ZTNA, cloud accounts — on one architecture.

03

Run

Fractional leadership and engineering until your people can hold it. Exit is part of the design, not a surprise.

SU-05 · Engagement

Three ways to hire us. Scope first.

No per-endpoint mystery price. We will not invent a number on this page that we cannot defend in a statement of work.

Advisory

A written answer

  • ISO 27001 gap, tabletop, or architecture review
  • Typical elapsed time: days to a few weeks
  • Deliverable: findings, owners, and a sequenced plan

Embedded

A vCISO on the roster

  • Retainer leadership, board pack, vendor and audit interface
  • Cadence agreed in writing (not “we’ll be around”)
  • Named backup coverage when the lead is out

Build

Put it in production

  • eramba GRC, Cloudflare ZTNA/SASE, AWS/Azure hardening
  • Detection design and vulnerability operating rhythm
  • Handover runbooks so you are not stuck with us

SU-06 · Also in the kit

Adjacent work we will not hide in a footnote.

API security

Authn/z, abuse cases, and contract testing for the interfaces your agents and partners actually call.

ZTNA / SASE

Zero-trust access on Cloudflare: replace the castle VPN with identity-aware paths.

TPRM

Third-party risk that fits the real vendor list, not a 400-question PDF no one returns.

AI governance

Use-case intake, data classes, and human-in-the-loop rules that survive an audit.

ISO 27001

Implementation, not a binder. Statement of Applicability tied to eramba records.

Vulnerability ops

A rhythm: discover, prioritize, patch or accept, prove it. No dashboard tourism.

Detect & respond

Use-case design, playbooks, and retainer counsel. We do not fake a follow-the-sun SOC.

DRaaS counsel

Recovery objectives that match the business, then the platform choice — not the reverse.

SU-07 · Plain answers

Questions we would ask us.

Are you an MSSP or a 24/7 SOC?

No. We design and run security programs: leadership, GRC, and engineering. If you need a staffed SOC, we help you specify it and hold the vendor to the SLA — we will not sell you one we do not operate.

Why eramba?

Most GRC suites charge by module, user, or framework. eramba is open GRC software used for risk, compliance, policies, assessments, and related workflows, with a simple enterprise model. We implement it so the register matches how you actually work.

How fast can we start?

A scoping conversation this week. A written plan before tools. Implementation on a calendar you can show a board. We will not promise “protected in 48 hours” unless the work is that small.

Where do you work?

Consultation is global. Delivery is remote-first. If a control or a regulator needs data to stay in a region, we say so in the design — including when eramba should be on-prem rather than SaaS.

Will we be stuck with you?

No. Handover is a deliverable: system ownership, documentation, and a named internal successor. Vendor lock-in is a design smell. We treat it that way.

SU-08 · Contact

Tell us the constraint. We’ll tell you if we can help.

A short form. No nurture sequence. If chat is faster, use the bubble.

We use this to reply. Read the privacy note.