Playbooks.
Step-by-step guides drawn from the work — governance, evidence, and adoption, in the open.
The AI governance operating model
Decision rights, policy hierarchy, and operating cadence — the working parts of AI governance that survives scrutiny, mapped to ISO 42001 and the NIST AI RMF.
AI evidence and audit readiness
The evidence architecture to build before the auditor, regulator, or board asks — what to capture at design, deploy, and run, and how to rehearse the questions.
Leading AI-fluent teams
The four adoption failure modes, work design that builds fluency, and policy that enables adoption instead of killing it.
The data governance operating model
Ownership, classification, lineage, and cadence — the working parts of data governance that make analytics, AI, and privacy obligations defensible.
Finding and securing sensitive data
You cannot protect what you have not found. Discovery, classification, access right-sizing, and monitoring — the posture discipline for the data that matters most.
Data breach readiness
The NDB scheme gives you thirty days to assess and no time to prepare. The runbook, the evidence, and the rehearsal — built before the day they are needed.
Cyber awareness that changes behaviour
Completion rates measure compliance, not risk. Treating the human layer as a managed risk — measured behaviour, targeted intervention, and a culture where reporting is safe.
Securing identity end to end
Attackers log in more often than they break in. Closing the MFA coverage gaps, governing the identities that aren't people, and cutting off lateral movement.
Bringing your APIs under management
APIs are the connective tissue of the enterprise — and most estates cannot list theirs. The catalogue, the gateway, the lifecycle, and the AI traffic now flowing through all of it.
Securing AI systems
AI is software with new failure modes — poisoned models, injected prompts, leaking context, agents off the leash. The attack surface, and the disciplines that hold it.
Building security into software delivery
Vulnerabilities are cheapest at the keyboard. Scanning in the pipeline, prioritising by real risk, keeping developers in flow — and holding the line as AI writes more of the code.
Seeing the network you actually run
You defend what you can see — and most estates cannot see sideways. East-west traffic, encrypted flows, and the network as the ground truth detection stands on.
Want help running one of these?
Whether you are framing a board-level technology decision, scoping a platform build, or recovering a transformation that has stalled — we lead with senior judgement, not a sales pitch. The first conversation is always free.
Contact us