SecOps & DevSecOps

Security that survives contact with delivery.

Controls that slow every release get worked around within a month. We build security into the pipeline instead of bolting it on afterwards — so the evidence your auditor and your customers ask for falls out of normal delivery rather than a panicked spreadsheet exercise.

Capabilities

What we cover

  • Pipeline security Dependency, container and static analysis wired into CI with thresholds a team can actually live with, so findings are triaged continuously rather than dumped in a quarterly report.
  • Secrets management Getting credentials out of repositories, scripts and shared documents into managed storage, with rotation someone can realistically perform and a plan for the ones already leaked.
  • Identity and least privilege Single sign-on, multi-factor authentication, scoped service accounts and access reviews — removing the standing admin rights that turn a small mistake into a large incident.
  • Vulnerability and patch management Knowing what you run, which versions, and how quickly fixes land — with a patch cadence that is measured rather than assumed.
  • Logging, monitoring and detection Centralised, tamper-resistant logs with alerting on the events that indicate compromise, and retention that still holds the evidence when you need to reconstruct what happened.
  • Supply chain and build integrity Pinned dependencies, provenance for what you ship, signed artefacts and locked-down build agents, so an upstream compromise does not become yours.
  • Compliance evidence Cyber Essentials and Cyber Essentials Plus, ISO 27001, SOC 2 and GDPR — mapped to controls that genuinely exist, with the automated evidence to demonstrate them.
  • Incident readiness A response plan that names people, defines severities and has been rehearsed, plus backups proven restorable against a ransomware scenario rather than assumed.

Engagements

How this usually starts

  • Certification push. Cyber Essentials, ISO 27001 or SOC 2 on a deadline, where the controls need to be real and the evidence needs to be produced without stopping delivery.
  • Client security review. A large customer has sent a security questionnaire your current setup cannot honestly answer, and the contract depends on it.
  • Pipeline hardening. Scanning, secrets and access control built into an existing CI/CD setup, tuned so the team does not immediately route around it.
  • Posture assessment. An honest review of where you are exposed, ranked by likelihood and blast radius rather than by scanner severity score.

Choosing a standard

Cyber Essentials, ISO 27001 or SOC 2?

These are not competing options so much as different weights. Most UK businesses should hold the first before considering the others.

Scheme What it covers Typical effort
Cyber Essentials Five technical controls: firewalls, secure configuration, user access, malware protection, patching. Self-assessed, then verified. Weeks. Certification fees are in the low hundreds for a small organisation.
Cyber Essentials Plus The same controls, confirmed by hands-on technical audit and vulnerability testing rather than a questionnaire. Weeks, once the basics genuinely pass. Assessment runs to a few thousand.
ISO 27001 A whole information security management system — policy, risk assessment, governance and continual improvement, not just technical controls. Months, and an order of magnitude more cost and internal time.
SOC 2 An auditor’s report on controls over a period. Common when selling to US customers. Months, plus an observation window before the report means anything.

Fees are indicative and set by the certification bodies, not by us — check current pricing with IASME or your chosen assessor. What we quote for is the engineering work needed to pass, which is usually the larger and more variable number.

Common questions

Questions we are usually asked first

A client has sent us a security questionnaire. What now?

Answer it honestly, including the gaps. Overstating controls in writing turns a procurement problem into a contractual one, and the follow-up questions usually expose it anyway.

In practice most questionnaires probe the same ground: access control, patching, backup and recovery, logging, encryption, supplier management and incident response. Getting those genuinely in order answers most of them permanently, rather than once.

Which certification should we start with?

Cyber Essentials, in almost every case. It is inexpensive, it takes weeks rather than months, it is a hard requirement for many UK public sector contracts, and the five controls it covers prevent a large share of real-world incidents.

ISO 27001 is worth pursuing when a customer contract demands it or you need a management system rather than a technical baseline. It is a much larger commitment and rarely the right first step.

Why did we fail Cyber Essentials Plus?

The recurring causes are unsupported operating systems or browsers still in use, missing patches beyond the required window, administrative accounts used for day-to-day work, multi-factor authentication not enforced on cloud services, and devices nobody realised were in scope — personal laptops and unmanaged mobiles especially.

Scope is the other frequent surprise. It covers everything that touches organisational data, not just the machines you issued.

Is DevSecOps just running a scanner in CI?

That is the part everyone starts with and the part that most often gets switched off. A scanner producing hundreds of unranked findings gets ignored within two sprints.

What makes it stick is deciding in advance which classes of finding block a release, routing the rest into normal backlog triage, and keeping the pipeline fast enough that nobody wants to bypass it.

Do we need a penetration test?

Eventually, and sometimes contractually. But a pen test against an estate with unpatched services and shared admin credentials mostly produces an expensive report telling you what you already suspect.

Fix the baseline first. A test is far more valuable once the obvious findings are gone and it can probe genuine weaknesses.

We have backups. Are we covered for ransomware?

Only if a copy is genuinely out of reach of a compromised administrator — offline, immutable, or in a separate account with separate credentials. Backups reachable with the same privileges as production get encrypted alongside it.

The other half is timing: you need to know how long a full restore takes, because you will have measured it. See our SRE work for recovery rehearsal.

Can you work with our existing security team?

Yes. We are often brought in for the engineering half — implementing the controls, wiring up the pipeline, producing the evidence — alongside an internal team or vCISO owning policy and risk.

Boring controls prevent most real incidents

The breaches that affect businesses like yours are rarely exotic. They are unpatched internet-facing services, credentials in a repository, standing admin access, no logging, and a backup nobody had restored. We fix those first, because doing so removes more risk than any tool you could buy this year.