Security consulting

A plan your CFO will fund and your architects will accept

Guardian's consulting practice produces costed, sequenced, technically specific programmes — maturity assessments, architecture reviews, zero-trust roadmaps and cloud migration security. Every deliverable is yours outright, in editable source.

445 consultants and architects · benchmarked against 6,800 organisations

1,260 Consulting engagements delivered in the last 24 months
6,800 Organisations in the benchmark dataset
1.4 Median maturity levels gained within 18 months
96% Engagements delivered on or ahead of the agreed date
0 Subcontracted practitioners — Guardian staff only

Offer 01

Security maturity assessment

A structured evaluation of twelve control domains against NIST CSF 2.0 and ISO 27001, calibrated by evidence rather than by self-assessment questionnaire. We read your configuration, sample your telemetry and interview the people doing the work.

  • Evidence-based scoring. Every domain score is supported by an artefact — a policy, a configuration export, a log sample or a demonstrated control.
  • Peer benchmarking. Compared against organisations of similar sector, size and regulatory footprint from a dataset of 6,800.
  • A target, not an aspiration. Target maturity is set per domain against your risk appetite. Level 5 everywhere is neither achievable nor sensible.
  • Costed remediation. Each gap carries an effort band, a headcount implication and a dependency note, so the output is a budget line.
We will tell you where you are over-invested Roughly a third of assessments identify a domain where spend exceeds the risk it retires. Reallocating that budget is usually the fastest available improvement.

Sample output — current maturity vs. 24-month target

Today 24-month target 1 2 3 4 5 Identity & access Endpoint & workload Network segmentation Data governance Detection engineering Incident readiness Cloud posture Third-party risk 1.5 3.5 Scale: 1 initial · 2 repeatable · 3 defined · 4 managed · 5 optimising. Illustrative client output.

Offer 02

Security architecture review

Architecture reviews go wrong when they become a checklist audit. Ours start from a threat model — who would attack this, what would they want, and what would they have to get through — and then test whether the design actually stops that.

Threat model first

We build an attacker-centric model of the system under review using STRIDE and MITRE ATT&CK, grounded in the tradecraft Guardian Labs observes in your sector this quarter — not in a generic threat catalogue.

Control coverage mapping

Every technique in the model is mapped to the control that should stop it, the telemetry that should catch it, and the response that should contain it. Gaps fall out of the mapping rather than out of opinion.

Failure-mode analysis

What happens when the identity provider is unavailable, the certificate expires, the break-glass account is used, or the segmentation policy fails open? Reviews that skip this miss the incidents that actually occur.

Typical review scopes

Enterprise identity architecture

Directory topology, federation and trust relationships, privileged access model, tier-0 containment, service and workload identity, joiner-mover-leaver reality versus policy, and the recovery plan for a compromised identity provider. This is the most requested scope and consistently the highest-yield.

Network and segmentation design

East-west controls, data-centre and campus segmentation, remote access, the boundary between IT and OT, third-party connectivity, and whether your segmentation survives the compromise of a single management plane. Includes a reachability analysis from an assumed-breach position.

Cloud landing zone and platform

Account and subscription topology, guardrail policy, network egress design, key management, workload identity federation, CI/CD trust boundaries and the blast radius of a compromised pipeline credential. Delivered against AWS, Azure and Google Cloud reference architectures.

Application and product security

Design review for a specific product or platform: authentication and session model, tenant isolation for multi-tenant SaaS, secret handling, supply-chain integrity, and the security assumptions embedded in the deployment model that nobody has written down.

OT and industrial control environments

Purdue-model conformance, safety-instrumented system separation, remote vendor access, historian and jump-host design, and a review of what genuinely cannot be patched. Conducted by consultants with plant-floor safety certification. See our OT solution.

What you receive

  • Current-state architecture diagrams in editable source
  • Threat model with technique-level coverage matrix
  • Risk-ranked findings with an owner and effort estimate
  • Target-state design with a migration sequence
Written for two audiences Every report ships with a four-page executive summary and a full technical annex, so the same document works in a steering committee and in an engineering review.

Offer 03

Zero-trust roadmap

Zero trust fails as a purchase and works as a sequence. Guardian builds a three-horizon programme across identity, devices, network and data, ordered by dependency, so that each phase delivers standalone value even if the next one slips.

zero-trust programme › three horizons
Horizon 1 Horizon 2 Horizon 3 0–6 months 6–18 months 18–36 months Identity Devices Network Data & workloads the new perimeter trust the endpoint? stop lateral movement the actual objective Phishing-resistant MFA for all administrators; MFA everywhere else; break-glass documented. EDR on 100% of managed endpoints; compliance state published to the IdP. Retire the flat VPN; broker access per application with identity-aware proxying. Locate and classify crown-jewel data; log every access to it. Risk-based conditional access; privileged access management for every tier-0 identity. Managed-device requirement for sensitive applications; unmanaged routed to VDI. Macro-segmentation of the data centre; explicit policy at every IT-to-OT boundary. DLP in enforcement mode; workload identity in CI/CD. Continuous session evaluation; passwordless as the default authentication path. Hardware-backed device attestation gating every privileged session. Micro-segmentation with identity-aware policy applied at the workload. Customer-held keys; policy that travels with the data itself. Sequence is dependency-ordered: identity work in Horizon 1 is what makes Horizon 2 segmentation enforceable.

Priced per phase

Each horizon carries a licence, implementation and run-cost estimate, plus the internal headcount it assumes. Finance can approve Horizon 1 without committing to Horizon 3.

Mapped to your frameworks

Every activity is tagged to NIST SP 800-207, CISA's Zero Trust Maturity Model and the control clauses your auditors already track, so the roadmap doubles as compliance evidence.

Written to survive change

Roadmaps assume reorganisations, budget cuts and a failed vendor selection. Each phase is designed to hold its value if the following phase is deferred by two quarters.

Offer 04

Cloud migration security

Migration is the one moment when you can set the security model cheaply. Guardian embeds with your cloud platform team to design the landing zone, the guardrails and the detection coverage before the first production workload lands.

4–12 wktypical engagement
3hyperscalers supported
-64%median posture findings at go-live
Guardrails, not gates Controls that block delivery get disabled within a quarter. We design preventative policy that fails safe and detective policy that never blocks, so platform teams keep their velocity and security keeps its coverage.
See the cloud security platform
  1. Landing-zone and tenancy design

    Account, subscription and project topology mapped to your legal entities and data residency obligations. Separation of production from non-production enforced at the organisation level rather than by naming convention, so a compromised developer credential cannot reach a production data store.

  2. Guardrail policy as code

    Preventative controls expressed as service control policies, Azure Policy or organisation policy constraints, delivered in your infrastructure-as-code repository with tests. Typical baseline blocks public object storage, unencrypted volumes, unrestricted security groups and key material in plaintext.

  3. Identity and workload federation

    Human access through your identity provider with short-lived credentials only. Machine access through workload identity federation, eliminating long-lived static keys from CI/CD — the single most common root cause in cloud breaches Guardian responds to.

  4. Detection and telemetry coverage

    Control-plane and data-plane logging enabled by default at the organisation level so it cannot be turned off in a single account. Sentinel cloud detections deployed and validated against a simulated attack chain before production traffic arrives.

  5. Migration wave review

    Each migration wave gets a lightweight security review against the agreed pattern library, so recurring designs are approved once rather than re-litigated per application. Exceptions carry an owner and an expiry date.

  6. Handover and run model

    A documented operating model naming who owns guardrail changes, who reviews exceptions and how drift is detected. Delivered with a 30-day post-go-live support window and a scheduled 90-day posture reassessment.

Deliverables

Exactly what lands on your desk

Everything below is produced in editable source and assigned to you outright. Guardian retains no exclusivity over content written for your environment, and nothing is delivered as a locked PDF you cannot maintain.

Standard deliverable set by engagement type. Additional artefacts can be added to any statement of work.
Deliverable Engagement Format Typical size
Executive summary All engagements DOCX and PDF 4–6 pages
Maturity scorecard and benchmark Maturity assessment XLSX with scoring model 12 domains, 148 criteria
Evidence register Maturity assessment, compliance XLSX with artefact links 150–400 rows
Threat model Architecture review Editable diagram source and DOCX 30–80 techniques
Current and target architecture diagrams Architecture review, zero trust, cloud draw.io, Visio or Mermaid source 6–20 diagrams
Risk-ranked findings register All engagements XLSX and Jira or ServiceNow import 25–120 findings
Costed remediation plan All engagements XLSX with effort and dependency model Phased over 6–36 months
Three-horizon roadmap Zero trust DOCX, PPTX and editable timeline source 3 horizons, 4 lanes
Guardrail policy repository Cloud migration security Terraform, SCP and OPA source with tests 40–90 policies
Detection content pack Architecture review, cloud migration Sigma and Sentinel rule source 15–60 rules
Board presentation All engagements, on request PPTX, presented live by the engagement lead 10–15 slides
90-day reassessment All engagements DOCX delta report 6–10 pages

Scroll the table sideways to see formats and sizes.

Deliverables are reviewed with you in a working session before they are finalised, so factual errors are corrected while the team is still engaged. See the delivery method in full.

Who does the work

Practitioners who have held the pager

Guardian's consulting practice is deliberately staffed with people who have operated security programmes rather than only advised on them. The median consultant has eleven years of experience and has been on the receiving end of at least one major incident. It changes what they recommend.

  • 445 consultants, architects and compliance specialists
  • CISSP, CISM, CCSP, SABSA and ISO 27001 Lead Auditor
  • Cleared personnel pools for US, UK, NATO, AU and CA work
  • Named engagement lead who presents the findings personally

The roadmap was the first security document I have been able to hand to the CFO without translating it. Three horizons, a number against each, and an honest note about what we would not get in year one.

Tomas Bergström
CISO, Nordic insurance group

They told us we were over-invested in one area and moved the budget somewhere it mattered. No vendor had ever told us to spend less on anything.

Rachel Cho
VP Technology Risk, global logistics operator

How an engagement runs

From first call to signed acceptance

Week 0

Scoping call with the practitioner

Thirty to sixty minutes with the consultant who would lead the work, not a sales engineer. The output is either a proposal with a fixed price and a written scope, or an honest statement that a different service fits better.

Week 1

Frame

Objectives, success criteria, out-of-scope items, access requirements and the acceptance test are agreed in writing. Constraints — regulatory, works council, clearance — are captured here and enforced through scoped access for the rest of the engagement.

Weeks 2–5

Discover and analyse

Evidence collection, interviews, configuration review and hands-on inspection, with a weekly written status covering progress, blockers on your side and anything found that cannot wait for the report.

Week 4 or 5

Mid-point findings readout

Draft findings presented while there is still time to correct a misunderstanding or supply missing evidence. Roughly one finding in eight is revised or withdrawn at this session, which is exactly why it exists.

Weeks 6–7

Deliver

Final report, deliverable set and a working session with the owners of each recommendation to agree sequencing. A board presentation is delivered live where requested.

Day 90

Reassessment

A delta report measuring what actually moved. It is included in the original price precisely so that the engagement is judged on change rather than on documents produced.

Start with the question, not the engagement

Tell us what decision you are trying to make. If an assessment is the wrong instrument, we will say so and point you at the service that is not.