TOWERVECTOR

06  Service

Security Consulting.

Medium and long term defense planning built from attacker behavior, focusing on assets that are actually targeted.

All services

01  Overview

What to fix first.

Security budgets tend to get spent in the order a framework lists its controls, which is rarely the order that reduces risk. This work establishes what to spend the next year on, and in what order, given what would actually be attacked in your organization.

Frameworks list what to consider. Which of it matters in your organization is a separate question.

02  Engagements

Assessment through to working controls.

Most engagements begin with an assessment of current state, because the sequencing of everything after it depends on what that finds.

Security Strategy and Roadmap

What to do, and in what order

A sequenced plan built from where your risk actually sits. The output is an ordered list with owners and approximate cost, short enough that someone will read it and act on it.

NIS2 Readiness and Gap Analysis

For organizations newly in scope

Establishing whether the regime applies to you, which of its obligations you already meet, and what the gap costs to close. For a mid-size company the answer is usually less alarming than the consultancy market suggests.

Framework Alignment

ISO/IEC 27001, NIST CSF, CIS Controls

Mapping what you do to the framework you have chosen, and identifying the controls that are documented but not operating. A framework is a checklist of things to have considered, and organizations that treat it as a description of a secure estate produce a lot of paper.

Controls Evaluation and Implementation

Making them real

Turning selected controls into working technical configuration, then verifying they hold. Verification is part of every engagement.

MITRE ATT&CK Alignment

Coverage against real technique

Mapping your detection and prevention coverage against the techniques an actual adversary would use against your sector, then finding where the gaps are concentrated. It turns "are we secure" into a question with an answer, and it pairs naturally with purple team work.

03  Process

How an engagement runs.

Fewer stages than our technical services and a longer horizon, because most of the elapsed time is spent on your side, implementing.

  1. 01

    Where you are, and what matters

    An honest assessment of current state, based on what is actually running, and of which assets, obligations, and outcomes actually drive the program. This usually takes a few days of conversations and a look at the environment.

  2. 02

    The gap, sequenced

    What is missing, with rough cost and effort attached, ordered by risk reduced per unit of effort. Recommendations without cost estimates are why so many security roadmaps stall at the first budget conversation.

  3. 03

    Implementation support

    Working alongside your team or your provider to put the controls in. How involved we are is your choice: some clients want the plan and nothing else, others want us present until it is done.

  4. 04

    Verification

    Testing the controls that were implemented. This is the step most consulting engagements do not include.

04  Deliverable

What you receive.

  • Current state assessment based on what is actually running
  • Prioritized roadmap with owners and effort against each item
  • Gap analysis against the framework or obligation that applies to you
  • Control specifications precise enough for an engineer to implement
  • A short briefing for the board, written for people who do not work in IT security
  • Verification that implemented controls hold up when tested

05  Questions

Common questions.

Can you certify us to ISO 27001?

We can get you ready for that audit and tell you whether you would pass, but the certificate has to come from an accredited body.

How is this different from hiring an auditor?

An auditor establishes whether you meet a standard on a given day. There are controls that pass an audit and stop nothing, and there is work that materially reduces risk and appears nowhere in a framework.

Do you do the implementation, or only advise?

Either. Some clients want a plan they will execute themselves. Others want us involved until the controls are running.

How long does a readiness program take?

The assessment is weeks. Closing the gaps is months, and how many depends almost entirely on your engineering capacity.

Is this an ongoing engagement or a project?

Both models work. Ongoing advisory suits organizations that need a security perspective in the room regularly but do not yet need a full-time hire.

06  Contact

Tell us what you need.

TowerVector will assist you in taking your security strategy to the next level. Please feel free to contact us: