Draft · client work, figures, partner tiers, offices and people are placeholders until approved
Run · Capability

Security & risk

Security designed in from the first sprint, with evidence collected automatically for your next audit.

Analysts monitor alerts in a security operations centre
What we do

Security & risk services

01

Zero trust

Identity-based access for people, services and devices, including operational technology.

02

Operational resilience

Impact tolerances, severe-but-plausible scenarios and recovery drills.

03

Continuous compliance

Controls as code, mapped to ISO 27001, SOC 2, DORA or NIS2, with evidence on demand.

Ways to start

Three ways to engage Security & risk

How every engagement runs
  1. 3 weeks
    Resilience assessment
    Important business services mapped, tolerances set and the gaps ranked against your regulator's rules.
  2. 4–6 months
    Zero-trust rollout
    Identity-based access for a first population of users and devices, then a repeatable path for the rest.
  3. Ongoing
    Compliance as code
    Controls, tests and evidence maintained continuously instead of before each audit.
Selected work

Security & risk in practice

All case studies
Questions

What clients ask about Security & risk

Do you run a security operations centre?

We run detection and response for the systems we operate, and integrate with your SOC or MSSP for the rest.

Which frameworks do you map to?

ISO/IEC 27001, SOC 2, PCI DSS, DORA, NIS2 and local banking and health rules.

Can you work with operational technology?

Yes. We secure access to substations, plants and devices without installing agents on safety systems.

Know where you stand before the regulator asks.

A three-week resilience assessment maps your important services and ranks the gaps.

Book a resilience assessmenthello@speey.com