Skip to content

Consulting

We leave behind a capability, not a dependency

Four engagement shapes, all of them hands-on-keyboard alongside your team. We do not produce assessments that recommend hiring us again.

Book a scoping call

Detection programme build

10–14 weeks

You have a SIEM, some rules, and no repeatable way to produce more. We build the pipeline, the review process and the first fifty tested detections alongside your engineers.

What you get

  • Rules repository with lint, test and deploy stages running in your CI
  • 50 validated detections mapped to your threat model
  • Detection review standard and PR template your team owns
  • Rule health dashboard with decay alerting
  • Two engineers trained to run it without us

Purple team validation

3–5 weeks

A full pass over what you believe you detect versus what you actually detect, run as a collaborative exercise rather than a report handed over at the end.

What you get

  • Detonation of 60–100 techniques scoped to your threat model
  • Per-technique result: detected, logged-not-alerted, or invisible
  • Root cause for every miss - telemetry, rule, or routing
  • Prioritised remediation backlog with effort estimates
  • Re-test of every fix before we leave

SIEM migration

8–16 weeks

Moving platforms is the best opportunity you will get to delete bad detections. Most migrations waste it by porting everything.

What you get

  • Inventory and triage of the existing rule estate
  • Rules rebuilt as Sigma so the next migration is cheap
  • Parallel-run comparison, old platform versus new
  • Documented decisions on every rule not carried across
  • Cutover plan with rollback

Detection engineering retainer

Ongoing, 4–8 days a month

For teams that have the pipeline but not the headcount. We write and tune detections against your backlog and stay accountable for their precision.

What you get

  • Agreed detection backlog, reviewed monthly
  • New rules delivered tested and shadow-deployed
  • Tuning of existing rules below the precision floor
  • On-call escalation for detection failures during incidents

Cloud detection build

6-10 weeks

Most cloud detection is three rules copied from a vendor blog and a lot of hope. Control-plane telemetry behaves nothing like endpoint telemetry and needs its own detection model.

What you get

  • Audit-log coverage review across accounts, subscriptions or projects
  • Identity-first detections: role assumption, key creation, consent grants
  • Data-plane rules for storage, secrets and compute where logging allows it
  • Cost model for the logging you actually need versus what is enabled today
  • Terraform or Bicep for every logging change we ask you to make

Detection engineering enablement

4 weeks, part time

For teams that want to build the capability rather than buy the output. Structured around your own backlog, so what gets built during the programme is work you were going to need anyway.

What you get

  • Workshops on rule design, tuning economics and validation practice
  • Pair-writing sessions against your real backlog, not lab exercises
  • A detection review standard your team wrote and therefore enforces
  • Runbook template linked from every rule your team ships
  • A written assessment of where the team is strong and where it is not

Post-incident detection sprint

2-3 weeks

You just finished an incident. The window where the organisation will fund detection work is open and short. We turn the incident timeline into rules before attention moves on.

What you get

  • Every technique in the incident timeline mapped to detect, partial or blind
  • Rules written for the blind spots, tested against the incident artefacts
  • Replay of the original intrusion against the new detections
  • Telemetry gaps written up with the cost of closing each one
  • A short board-readable summary of what would now be caught, and what would not

How we work

Four things we will not negotiate on

These are the terms that make the work stick. If they do not suit your procurement process, we are probably the wrong firm.

01

We price the engagement, not the hours

Scope is agreed up front and so is the number. If the work takes longer than we estimated, that is our problem to absorb, not a variation to invoice.

02

Your telemetry stays yours

We work inside your tenancy, on your infrastructure. Nothing is copied to our systems, and there is no phase of the engagement where your logs leave your estate.

03

We work in your repository

Every rule we write lands as a pull request in your Git, reviewed by your engineers. Nothing is delivered as a PDF appendix that has to be retyped.

04

Detonation or it did not happen

A detection is not delivered until an atomic test has proved it fires in your environment and reached a queue a human reads. That is the acceptance criterion, in writing.

05

We delete more than we add

Most estates carry hundreds of rules at single-digit precision. Removing them raises real coverage. Expect us to argue for deletions, with fire-count evidence.

06

The goal is our own redundancy

Every engagement ends with a handover session and a runbook. If you still need us at month twelve for the things we built in month one, we did it wrong.

Start with a scoping call

Forty-five minutes, no charge. Bring your current rule count, your SIEM, and the last incident where a detection should have fired and did not. That last one tells us more than the other two combined.

Book the call