Technology

Cybersecurity. Security is bought on trust and sold on proof.

The proof now has deadlines.

Security platforms, managed security providers, identity and cloud-security vendors and audit firms, selling to buyers who distrust claims and must report incidents within hours. We build positioning a technical buyer believes, evidence-led sites and trust centres, consoles analysts can work in, and AI copilots that are red-teamed before they ship.

The number we move
Evaluation-to-contract conversion
Where we work in cybersecurity
  • Security platforms & products
  • Managed security services
  • Identity & access
  • Cloud & application security
  • Security consulting & audit
Rules mapped
8 rules · 5 areas
Disciplines that lead
BrandProduct
Frameworks we build to
ISO/IEC 27001:2022 — Information security management systemsSOC 2 — Trust Services CriteriaNIST CSF 2.0 — Cybersecurity FrameworkCERT-In Directions 2022 — Cyber incident reporting directionsNIS2 — Network and Information Security Directive (EU) 2022/2555OWASP Top 10 for LLM Applications — LLM and generative AI security risksMITRE ATLAS — Adversarial Threat Landscape for AI SystemsOWASP ASVS — Application Security Verification Standard
A man at a keyboard looks up from a desk of monitors showing code, in black and white
CybersecuritySecurity is decided by the people watching the screens.

Where the rules biteMap of all forty-one industries

  • Claims Advertising & claims: Often shapes the work
  • Regulator Sector regulator: Shapes most of the work
  • Payments Payments: Sometimes shapes the work
  • Data Personal data: Often shapes the work
  • Security Security & incidents: Shapes most of the work
  • Access Accessibility: Sometimes shapes the work
  • AI AI governance: Often shapes the work

What is shifting

Proof has deadlines now, and the buyer reads the bill of materials.

Reporting clocks reached products, buyers ask for SBOMs, audits score exploitability and fear-led selling met a regulator. Each shift names what it demands, with a fact you can check.

Network cables and equipment in a server rack, lit green in the dark
Buyers now ask what is inside the box.
  1. Reporting clocks reached the product itself.

    It demandsProducts with vulnerability and incident reporting designed in, from detection to the regulator’s form.

    SignalSince 11 September 2026, makers of products with digital elements sold in the EU must send an early warning of actively exploited flaws within 24 hours, under the Cyber Resilience Act.

  2. Buyers ask for a bill of materials, not a brochure.

    It demandsSBOMs, AI bills of materials and evidence packs that a procurement team can check.

    SignalCERT-In’s guidelines of 9 July 2025 set minimum elements for software, crypto, AI and hardware bills of materials and urge buyers to make SBOMs standard.

  3. Audits are yearly and scored for exploitability.

    It demandsFindings that read by risk and likelihood, not by volume.

    SignalCERT-In’s audit policy guidelines of 25 July 2025 call for an audit at least once a year, with findings rated by CVSS severity and EPSS likelihood.

  4. Fear-led selling is now a consumer-protection risk.

    It demandsClaims and renewal screens that inform without threatening.

    SignalIn June 2026 the CCPA fined a security-software company whose renewal screen offered ‘Renew now’ or ‘Accept risk’, finding the choice was not neutral.

The rulebook

Your customers’ rulebook is now yours as well.

CERT-In’s directions and guidelines, NIS2, the Cyber Resilience Act, consumer-protection rules and the data law, read for a security vendor. Your counsel and auditors keep sign-off.

Frameworks we build to

  • ISO/IEC 27001:2022 — Information security management systems
  • SOC 2 — Trust Services Criteria
  • NIST CSF 2.0 — Cybersecurity Framework
  • CERT-In Directions 2022 — Cyber incident reporting directions
  • NIS2 — Network and Information Security Directive (EU) 2022/2555
  • OWASP Top 10 for LLM Applications — LLM and generative AI security risks
  • MITRE ATLAS — Adversarial Threat Landscape for AI Systems
  • OWASP ASVS — Application Security Verification Standard

Frameworks we design and build to — not a claim of certification.

Advertising & claims

Often shapes the work

  1. Central Consumer Protection Authority

    Consumer-protection rules on claims and dark patterns

    Misleading advertisements are barred under the Consumer Protection Act, and fear-based or manipulative choices are dark patterns; in June 2026 the CCPA penalised a security-software renewal screen that framed declining as accepting risk.

    We designEvery detection, coverage or ‘AI-powered’ claim is tied to evidence, and renewal copy states facts, not threats.

    Consumer Protection Act, 2019 · CCPA Dark Patterns Guidelines, 30 November 2023 · CCPA order of June 2026 Official text: Consumer-protection rules on claims and dark patterns

Sector regulator

Shapes most of the work

  1. Indian Computer Emergency Response Team

    CERT-In guidelines on SBOM, QBOM, CBOM, AIBOM and HBOM

    Minimum elements for software, quantum and crypto, AI and hardware bills of materials, which the public sector, essential services and software exporters are urged to make standard in procurement.

    We designBills of materials are generated in the build and shared with customers in a form they can read.

    CERT-In · Technical Guidelines, version 2.0, 9 July 2025 Official text: CERT-In guidelines on SBOM, QBOM, CBOM, AIBOM and HBOM

  2. European Union

    EU Cyber Resilience Act

    Makers of products with digital elements report actively exploited vulnerabilities and severe incidents — an early warning within 24 hours, a notification within 72 — from 11 September 2026; the security requirements apply from 11 December 2027.

    We designVulnerability handling, disclosure pages and the SBOM are designed as part of the product, not added for the audit.

    Regulation (EU) 2024/2847 · Article 14 from 11 September 2026 · Article 71 Official text: EU Cyber Resilience Act

Personal data

Often shapes the work

  1. Ministry of Electronics and IT

    DPDP Act, 2023 and DPDP Rules, 2025

    Logs and telemetry often hold personal data: processors work under contract, and fiduciaries report breaches to the Data Protection Board — with a detailed report within 72 hours — and to the people affected, from 13 May 2027.

    We designTelemetry is minimised and tagged, so a breach report can say whose data was touched.

    DPDP Act, 2023 · section 8 · DPDP Rules, 2025, rule 7 (from 13 May 2027) Official text: DPDP Act, 2023 and DPDP Rules, 2025

Security & incidents

Shapes most of the work

  1. Indian Computer Emergency Response Team

    CERT-In Directions, 2022

    Service providers, intermediaries, data centres, companies and government bodies report listed cyber incidents within six hours of noticing them and keep logs of all ICT systems for a rolling 180 days within India.

    We designDetection and case tools record the moment an incident was noticed, so the six-hour clock can be proved.

    CERT-In · Directions under section 70B(6) of the IT Act, 28 April 2022 Official text: CERT-In Directions, 2022

  2. Indian Computer Emergency Response Team

    CERT-In audit policy guidelines, 2025

    Cyber security audits by CERT-In-empanelled auditors at least once a year, more often where a sector regulator says so, with findings rated by CVSS severity and EPSS likelihood of exploitation.

    We designAudit reports and remediation trackers sort findings by exploitability and keep the evidence for the next audit.

    CERT-In · Comprehensive Cyber Security Audit Policy Guidelines, version 1.0, 25 July 2025 Official text: CERT-In audit policy guidelines, 2025

  3. European Union

    NIS2 Directive

    Essential and important entities, managed security service providers among them, give an early warning within 24 hours of a significant incident, a notification within 72 hours and a final report within a month; boards approve the measures.

    We designCustomer-facing reporting follows the 24-hour, 72-hour and one-month stages, with templates for each.

    Directive (EU) 2022/2555 · Articles 20 and 23 Official text: NIS2 Directive

AI governance

Often shapes the work

  1. OWASP GenAI Security Project

    OWASP Top 10 for LLM Applications

    Prompt injection (LLM01), sensitive information disclosure (LLM02), excessive agency (LLM06) and the other risks a security copilot faces when it reads untrusted logs and tickets.

    We designCopilots are red-teamed against the list before release, with tools limited to what each task needs.

    OWASP Top 10 for LLM Applications, 2025 edition Official text: OWASP Top 10 for LLM Applications

Compiled 3 October 2026. Our reading of typical programmes, not legal advice. Rules change; your counsel confirms how each one applies to you.

Challenges

What gets in the way in cybersecurity.

The problems that surface in nearly every cybersecurity programme: the ones customers feel, and the ones teams carry.

Your customers

  1. Proof before the meeting

    Technical buyers want architecture, test results and integrations on the site, not behind a form.

  2. A review that clears in days

    Questionnaires, SBOMs and certificates ready the day procurement asks for them.

  3. Alerts an analyst can act on

    Fewer, clearer alerts, with the evidence in one view.

A technician in a high-visibility vest works on equipment at an open server rack
Evidence is built in the rack, not in the brochure.

Your operation

  1. Claims that survive scrutiny

    Detection, coverage and ‘AI-powered’ claims checked against what the product actually does.

  2. Clocks inside and out

    Your own incidents, your customers’ and the products you ship all run on reporting deadlines.

  3. A copilot that cannot be turned

    AI features that read untrusted data must resist injection and stay within their permissions.

What we build

What we build for cybersecurity, discipline by discipline.

A typical programme here draws on each discipline in this mix. Every line names what it builds for the industry and links to the capability that does the work.

Leads Core Supports Share of a typical programme, by role · illustrative
  1. 01

    Brand Design

    Leads

    Positioning a technical buyer believes, with every claim tied to evidence.

  2. Analyst consoles, alert triage and incident views designed with the people who use them at three in the morning.

  3. Trust centres, evidence portals and reporting integrations, built and run securely.

  4. Research, threat reports and points of view that practitioners and assistants cite.

  5. 05

    AI Design

    Core

    Security copilots grounded in your own telemetry and runbooks, red-teamed and bound by permissions.

  6. 06

    Marketing Technology

    Supports

    Account journeys and lead routing for long evaluations with many reviewers.

Programmes

Check every claim first, then publish the evidence.

The way in ties each public claim to its evidence and maps what buyers ask for against what you can share. Lengths are typical, never promised.

The way in

Claims and evidence audit

We check every public claim against what the product and its tests show, and map the evidence buyers ask for against what you can share.

Package
Sprint · Fixed fee
Typical length
2–3 weeks
It sets
Days to clear a customer’s security review, as a baseline
  • Brand audit & diagnostic
  • Product experience audit

What it hands over

  • A claims register with the evidence for each claim, or a rewrite
  • A trust-centre outline: what to publish and what to gate
  • An evaluation journey with the drop-off points marked
Start here
  1. 02Project · 8–12 weeks

    Trust centre and evidence portal

    Security posture, sub-processors, SBOMs and reports published in one place, with gated documents released under NDA.

    MovesDays to clear a customer’s security review

    Services: Website · Compliance readiness

    Enquire about Trust centre and evidence portal
  2. 03Milestone · 4–9 months

    Analyst console redesign

    Alert, investigation and reporting views redesigned around the analyst’s path, with the reporting clock beside the evidence.

    MovesAnalyst time per alert in the product

    Services: Product discovery · End-to-end UX & UI design · Design system build

    Enquire about Analyst console redesign
  3. 04Project · 8–12 weeks

    Security copilot with red-team evaluations

    A copilot grounded in your telemetry and runbooks, tested against prompt injection and excessive agency before it reaches a customer.

    MovesCopilot answer accuracy on the evaluation set

    Services: Custom AI agent or copilot · Brand fidelity evaluation · Penetration test (VAPT)

    Enquire about Security copilot with red-team evaluations

How success is measured

The number we moveEvaluation-to-contract conversion

  • Evaluation-to-contract conversion
  • Days to clear a customer’s security review
  • Analyst time per alert in the product
  • Copilot answer accuracy on the evaluation set

AI, under the rules

Copilots read hostile data, so they are tested like it.

Each use case treats logs and tickets as untrusted input, has an evaluation set and a log, and a person approves every action and every notification.

Use case 01

Alert summary copilot

Measured byAnalyst time per alert

Tested forOWASP LLM01 · Prompt injection

agent / alert-summary-copilot Guarded
  1. TaskSummarises an alert with its timeline, related events and affected assets from your own telemetry.
  2. GuardrailTreats log content as untrusted data, cites every event it uses and has no tool that can act on a system.
  3. HumanThe analyst decides whether it is an incident.
  4. LogPrompt, events cited and the analyst’s decision.

Ships only with its evaluation set, its guardrail and an owner

Use case 02

Incident notification drafter

Measured byNotifications sent within their deadline

Tested forOWASP LLM09 · Misinformation

agent / incident-notification-drafter Guarded
  1. TaskDrafts the CERT-In and customer notifications from the case record, with the clock for each.
  2. GuardrailUses only facts recorded in the case and flags gaps instead of filling them.
  3. HumanThe incident lead approves every notification before it is sent.
  4. LogDraft, edits and approval time against the clock.

Ships only with its evaluation set, its guardrail and an owner

Use case 03

Questionnaire assistant

Measured byDays to return a questionnaire

Tested forOWASP LLM02 · Sensitive information disclosure

agent / questionnaire-assistant Guarded
  1. TaskAnswers customer security questionnaires from approved policies, test reports and the SBOM.
  2. GuardrailApproved answers only; anything new or sensitive goes to the security lead.
  3. HumanThe security lead signs off each submission.
  4. LogEach answer tied to the document version it came from.

Ships only with its evaluation set, its guardrail and an owner

Work and insights

Published work follows client approval.

We publish cybersecurity projects only once a client signs off the write-up. Meanwhile, here is the reading that applies.

A typical programme · composite

A managed security provider rebuilt its site around a public trust centre and a sample incident report, and gave its analysts one console view per incident with the reporting clock beside the evidence.

Anonymised and illustrative: the shape a programme takes, never a named client.

Questions

What founders, product and security leads ask us first.

Something else on your mind? Ask us directly

Q.01Will you change our product claims?

Only where the evidence does not support them. We keep a register that ties each claim to a test result, a report or a documented capability, and rewrite the claims that cannot be shown.

Q.02Do you work with managed security providers as well as product companies?

Yes. Managed services carry their own reporting duties — to CERT-In in India and, for EU customers, under NIS2 — and we design the customer-facing reporting and evidence around them.

Q.03Can our copilot be safe to put in front of customers?

It can be tested, bounded and logged: evaluated on your analysts’ questions, red-teamed against the OWASP Top 10 for LLM Applications and MITRE ATLAS techniques, and limited to read-only tools unless a person approves an action.

Q.04Can you certify us to ISO/IEC 27001 or SOC 2?

No. Certificates come from accredited certification bodies and SOC 2 reports from independent auditors. We build the systems, pages and evidence that make those audits easier to pass.

Let’s build what happens next.

Tell us what you’re building. We’ll answer straight.

Book a discovery call

Three ways to start

  1. 01About 2 minutes

    A quick question

    You get A reply from a lead, not a sales queue

  2. 02About 8 minutesMost useful

    A project brief

    You get Options and a first scope after one call

  3. 03About 15 minutes

    A formal RFQ or RFP

    You get Receipt confirmed and a named bid lead

Every engagement starts with a written scope and a quote agreed before work begins. How each package is priced