TOWERVECTOR

06  Service

Security Consulting.

Medium and long term defense planning built from attacker behavior, focusing on assets that are actually targeted.

All services

01  Overview

Overview.

What to spend the next year's security budget on, and in what order, given what would actually be attacked in your organization.

Frameworks are a reasonable place to start and a poor place to finish. They tell you what to consider; they cannot tell you which of it matters here.

02  Engagements

Assessment through to working control.

Most engagements begin with an assessment of current state, because the sequencing of everything after it depends on what that finds.

Security Strategy and Roadmap

What to do, and in what order

A sequenced plan built from where your risk actually sits rather than from a maturity model's idea of a complete program. The output is an ordered list with owners and approximate cost, short enough that someone will read it and act on it.

NIS2 Readiness and Gap Analysis

For organizations newly in scope

Establishing whether the directive applies to you, which of its obligations you already meet, and what the gap costs to close. Portugal's transposition is the reference point rather than the directive alone, and the answer for a mid-size company is usually less alarming than the consultancy market suggests.

Framework Alignment

ISO/IEC 27001, NIST CSF, CIS Controls

Mapping what you do to the framework you have chosen, and identifying the controls that are documented but not operating. Frameworks are useful as a checklist of things to have considered; they are not a description of a secure organization, and treating them as one produces a lot of paper.

Controls Evaluation and Implementation

Making them real

Turning selected controls into working technical configuration, then verifying they hold. This is where our testing work matters: we can attack a control we recommended, which is a materially different position from advising on paper and never seeing whether it survives.

MITRE ATT&CK Alignment

Coverage against real technique

Mapping your detection and prevention coverage against the techniques an actual adversary would use against your sector, then finding where the gaps are concentrated. It turns "are we secure" into a question with an answer, and it pairs naturally with purple team work.

03  Process

How an engagement runs.

Longer horizon than our technical services, and more dependent on your organization than on us.

  1. 01

    Where you are

    An honest assessment of current state, based on what is running rather than what the policies say. This usually takes a few days of conversations and a look at the environment, not a hundred-question spreadsheet sent in advance.

  2. 02

    What matters to you

    Which assets, obligations, and outcomes actually drive the program. A regulated manufacturer, a SaaS company answering customer questionnaires, and a firm preparing for acquisition need different things, and a generic roadmap serves none of them.

  3. 03

    The gap

    What is missing, with rough cost and effort attached. Recommendations without cost estimates are not decisions, they are wishes, and they are why so many security roadmaps stall at the first budget conversation.

  4. 04

    Sequencing

    Ordering the work by risk reduced per unit of effort, not by framework section number. The first three things on the list should visibly reduce exposure; if they do not, the program loses its sponsor.

  5. 05

    Implementation support

    Working alongside your team or your provider to put the controls in. How involved we are is your choice: some clients want the plan and nothing else, others want us present until it is done.

  6. 06

    Verification

    Testing the controls that were implemented. This is the step most consulting engagements do not include, and it is the one that distinguishes a control that works from a control that is documented.

04  Deliverable

What you receive.

  • Current state assessment based on what is running, not what is documented
  • Prioritized roadmap with owners and effort against each item
  • Gap analysis against the framework or obligation that applies to you
  • Control specifications precise enough for an engineer to implement
  • A short briefing for the board, written for people who do not work in IT security
  • Verification that implemented controls hold up when tested

05  Questions

Common questions.

Can you certify us to ISO 27001?

We can get you ready for that audit and tell you whether you would pass, but the certificate has to come from an accredited body.

How is this different from hiring an auditor?

An auditor establishes whether you meet a standard on a given day. There are controls that pass an audit and stop nothing, and there is work that materially reduces risk and appears nowhere in a framework.

Do you do the implementation, or only advise?

Either. Some clients want a plan they will execute themselves. Others want us involved until the controls are running.

How long does a readiness program take?

The assessment is weeks. Closing the gaps is months, and how many depends almost entirely on your engineering capacity rather than on the security work.

Is this an ongoing engagement or a project?

Both models work. Ongoing advisory suits organizations that need a security perspective in the room regularly but do not yet need a full-time hire.

06  Contact

Tell us what you need.

TowerVector will assist you in taking your security strategy to the next level. Please feel free to contact us: