Survive the disruption you didn’t plan for.
Cyberattack, outage, supplier failure — disruption is a question of when. We build continuity and cyber risk programmes on ISO 22301 and NIST CSF 2 so the answer is rehearsed rather than improvised.

ISO 22301 — business continuity
The international standard for business continuity management. We work through business impact analysis, recovery objectives, continuity plans and the exercises that prove those plans hold — so recovery time is a measured number, not an estimate.
NIST CSF 2 — cyber risk
A framework for identifying, prioritising and addressing cyber risk across six functions: Govern, Identify, Protect, Detect, Respond and Recover. We assess your current profile, agree a target profile, and sequence the work between them by risk reduction per unit of effort.
What we deliver
- Gap assessment — current state against ISO 22301 or NIST CSF 2, with findings ranked by exposure
- Programme build — continuity plans, incident response runbooks and the controls behind them
- Cloud assurance — extending the same control set across cloud environments rather than exempting them
- Exercise and review — tabletop and live tests, because an untested plan is an assumption