Threat model first
We build an attacker-centric model of the system under review using STRIDE and MITRE ATT&CK, grounded in the tradecraft Guardian Labs observes in your sector this quarter — not in a generic threat catalogue.
Security consulting
Guardian's consulting practice produces costed, sequenced, technically specific programmes — maturity assessments, architecture reviews, zero-trust roadmaps and cloud migration security. Every deliverable is yours outright, in editable source.
445 consultants and architects · benchmarked against 6,800 organisations
Four core offers
These four engagements cover the questions boards ask most often. Each is delivered against the published Guardian Delivery Method with a written acceptance test agreed at kick-off.
Where you actually stand across twelve domains, benchmarked against your sector, with a costed path to where you need to be.
4–6 weeksA threat-model-led review of your current design, its control coverage and the failure modes nobody has written down.
3–8 weeksA three-horizon programme across identity, devices, network and data, sequenced by dependency and priced per phase.
6–10 weeksLanding-zone design, guardrail policy and a control set that lets teams ship without opening the estate up on the way.
4–12 weeksOffer 01
A structured evaluation of twelve control domains against NIST CSF 2.0 and ISO 27001, calibrated by evidence rather than by self-assessment questionnaire. We read your configuration, sample your telemetry and interview the people doing the work.
Sample output — current maturity vs. 24-month target
Offer 02
Architecture reviews go wrong when they become a checklist audit. Ours start from a threat model — who would attack this, what would they want, and what would they have to get through — and then test whether the design actually stops that.
We build an attacker-centric model of the system under review using STRIDE and MITRE ATT&CK, grounded in the tradecraft Guardian Labs observes in your sector this quarter — not in a generic threat catalogue.
Every technique in the model is mapped to the control that should stop it, the telemetry that should catch it, and the response that should contain it. Gaps fall out of the mapping rather than out of opinion.
What happens when the identity provider is unavailable, the certificate expires, the break-glass account is used, or the segmentation policy fails open? Reviews that skip this miss the incidents that actually occur.
Directory topology, federation and trust relationships, privileged access model, tier-0 containment, service and workload identity, joiner-mover-leaver reality versus policy, and the recovery plan for a compromised identity provider. This is the most requested scope and consistently the highest-yield.
East-west controls, data-centre and campus segmentation, remote access, the boundary between IT and OT, third-party connectivity, and whether your segmentation survives the compromise of a single management plane. Includes a reachability analysis from an assumed-breach position.
Account and subscription topology, guardrail policy, network egress design, key management, workload identity federation, CI/CD trust boundaries and the blast radius of a compromised pipeline credential. Delivered against AWS, Azure and Google Cloud reference architectures.
Design review for a specific product or platform: authentication and session model, tenant isolation for multi-tenant SaaS, secret handling, supply-chain integrity, and the security assumptions embedded in the deployment model that nobody has written down.
Purdue-model conformance, safety-instrumented system separation, remote vendor access, historian and jump-host design, and a review of what genuinely cannot be patched. Conducted by consultants with plant-floor safety certification. See our OT solution.
Offer 03
Zero trust fails as a purchase and works as a sequence. Guardian builds a three-horizon programme across identity, devices, network and data, ordered by dependency, so that each phase delivers standalone value even if the next one slips.
Each horizon carries a licence, implementation and run-cost estimate, plus the internal headcount it assumes. Finance can approve Horizon 1 without committing to Horizon 3.
Every activity is tagged to NIST SP 800-207, CISA's Zero Trust Maturity Model and the control clauses your auditors already track, so the roadmap doubles as compliance evidence.
Roadmaps assume reorganisations, budget cuts and a failed vendor selection. Each phase is designed to hold its value if the following phase is deferred by two quarters.
Offer 04
Migration is the one moment when you can set the security model cheaply. Guardian embeds with your cloud platform team to design the landing zone, the guardrails and the detection coverage before the first production workload lands.
Account, subscription and project topology mapped to your legal entities and data residency obligations. Separation of production from non-production enforced at the organisation level rather than by naming convention, so a compromised developer credential cannot reach a production data store.
Preventative controls expressed as service control policies, Azure Policy or organisation policy constraints, delivered in your infrastructure-as-code repository with tests. Typical baseline blocks public object storage, unencrypted volumes, unrestricted security groups and key material in plaintext.
Human access through your identity provider with short-lived credentials only. Machine access through workload identity federation, eliminating long-lived static keys from CI/CD — the single most common root cause in cloud breaches Guardian responds to.
Control-plane and data-plane logging enabled by default at the organisation level so it cannot be turned off in a single account. Sentinel cloud detections deployed and validated against a simulated attack chain before production traffic arrives.
Each migration wave gets a lightweight security review against the agreed pattern library, so recurring designs are approved once rather than re-litigated per application. Exceptions carry an owner and an expiry date.
A documented operating model naming who owns guardrail changes, who reviews exceptions and how drift is detected. Delivered with a 30-day post-go-live support window and a scheduled 90-day posture reassessment.
Deliverables
Everything below is produced in editable source and assigned to you outright. Guardian retains no exclusivity over content written for your environment, and nothing is delivered as a locked PDF you cannot maintain.
| Deliverable | Engagement | Format | Typical size |
|---|---|---|---|
| Executive summary | All engagements | DOCX and PDF | 4–6 pages |
| Maturity scorecard and benchmark | Maturity assessment | XLSX with scoring model | 12 domains, 148 criteria |
| Evidence register | Maturity assessment, compliance | XLSX with artefact links | 150–400 rows |
| Threat model | Architecture review | Editable diagram source and DOCX | 30–80 techniques |
| Current and target architecture diagrams | Architecture review, zero trust, cloud | draw.io, Visio or Mermaid source | 6–20 diagrams |
| Risk-ranked findings register | All engagements | XLSX and Jira or ServiceNow import | 25–120 findings |
| Costed remediation plan | All engagements | XLSX with effort and dependency model | Phased over 6–36 months |
| Three-horizon roadmap | Zero trust | DOCX, PPTX and editable timeline source | 3 horizons, 4 lanes |
| Guardrail policy repository | Cloud migration security | Terraform, SCP and OPA source with tests | 40–90 policies |
| Detection content pack | Architecture review, cloud migration | Sigma and Sentinel rule source | 15–60 rules |
| Board presentation | All engagements, on request | PPTX, presented live by the engagement lead | 10–15 slides |
| 90-day reassessment | All engagements | DOCX delta report | 6–10 pages |
Scroll the table sideways to see formats and sizes.
Deliverables are reviewed with you in a working session before they are finalised, so factual errors are corrected while the team is still engaged. See the delivery method in full.
Who does the work
Guardian's consulting practice is deliberately staffed with people who have operated security programmes rather than only advised on them. The median consultant has eleven years of experience and has been on the receiving end of at least one major incident. It changes what they recommend.
The roadmap was the first security document I have been able to hand to the CFO without translating it. Three horizons, a number against each, and an honest note about what we would not get in year one.
They told us we were over-invested in one area and moved the budget somewhere it mattered. No vendor had ever told us to spend less on anything.
How an engagement runs
Thirty to sixty minutes with the consultant who would lead the work, not a sales engineer. The output is either a proposal with a fixed price and a written scope, or an honest statement that a different service fits better.
Objectives, success criteria, out-of-scope items, access requirements and the acceptance test are agreed in writing. Constraints — regulatory, works council, clearance — are captured here and enforced through scoped access for the rest of the engagement.
Evidence collection, interviews, configuration review and hands-on inspection, with a weekly written status covering progress, blockers on your side and anything found that cannot wait for the report.
Draft findings presented while there is still time to correct a misunderstanding or supply missing evidence. Roughly one finding in eight is revised or withdrawn at this session, which is exactly why it exists.
Final report, deliverable set and a working session with the owners of each recommendation to agree sequencing. A board presentation is delivered live where requested.
A delta report measuring what actually moved. It is included in the original price precisely so that the engagement is judged on change rather than on documents produced.
Tell us what decision you are trying to make. If an assessment is the wrong instrument, we will say so and point you at the service that is not.