Run · Capability
Security & risk
Security designed in from the first sprint, with evidence collected automatically for your next audit.

What we do
Security & risk services
01
Zero trust
Identity-based access for people, services and devices, including operational technology.
02
Operational resilience
Impact tolerances, severe-but-plausible scenarios and recovery drills.
03
Continuous compliance
Controls as code, mapped to ISO 27001, SOC 2, DORA or NIS2, with evidence on demand.
Ways to start
Three ways to engage Security & risk
- 3 weeksResilience assessmentImportant business services mapped, tolerances set and the gaps ranked against your regulator's rules.
- 4–6 monthsZero-trust rolloutIdentity-based access for a first population of users and devices, then a repeatable path for the rest.
- OngoingCompliance as codeControls, tests and evidence maintained continuously instead of before each audit.
Selected work
Security & risk in practice
Questions
What clients ask about Security & risk
Do you run a security operations centre?
We run detection and response for the systems we operate, and integrate with your SOC or MSSP for the rest.
Which frameworks do you map to?
ISO/IEC 27001, SOC 2, PCI DSS, DORA, NIS2 and local banking and health rules.
Can you work with operational technology?
Yes. We secure access to substations, plants and devices without installing agents on safety systems.
Industries we serve with Security & risk
Open roles in this practice
Know where you stand before the regulator asks.
A three-week resilience assessment maps your important services and ranks the gaps.
Book a resilience assessmenthello@speey.com
