01 End-to-end PKI transformation
The National Public Key Infrastructure (PKI), providing trust services (digital signatures, authentication and timestamping) for government and regulated industries, required comprehensive modernisation. The system…
Selected work across assurance, security and digital trust.
The National Public Key Infrastructure (PKI), providing trust services (digital signatures, authentication and timestamping) for government and regulated industries, required comprehensive modernisation. The system…
A national-scale security operations mandate required a production SOC protecting critical infrastructure across multiple sectors — with no high-availability monitoring platform, no structured detection and response…
During the 2024 national electoral process, critical digital infrastructure faced sustained high-pressure threat activity — large-scale DDoS, social-engineering campaigns and real-time attacks against availability and…
National incident reporting and investigation lacked a single structured platform — cases tracked inconsistently, forensic artefacts collected ad hoc and hand-offs between monitoring, hunting and response teams without…
A regulated electronic communications operator required accredited quality, information-security and business-continuity management systems — a condition of continued operation under essential-entity and licence…
A regulated electronic communications operator required an owned on-premises security operations capability — a condition of continued operation under essential-entity and licence supervisory requirements. The…
A network operator with national IP resources needed threat visibility beyond single-IP indicators — infrastructure abuse, C2 hosting and campaign activity visible only at Autonomous System (AS) level. Existing…
A regulated B2B organisation lacked a single source of truth for information assets, services and dependencies — configuration items, clusters, physical equipment and locations were not linked in a deterministic model…
A regulated technology holding required independent external attack-surface assurance across its group — spanning consumer, enterprise and wholesale verticals — under essential-entity supervisory obligations and…
Ahead of the European Political Community Summit 2023, event-facing digital infrastructure — public platforms, communication channels and supporting services — required independent validation of security posture before…