NodeOps Security Infrastructure · Assurance
Secondary activity

Security strategy, above the implementation layer.

The same clients who need our technical work usually need something further up: a defensible risk position, policies that hold up under scrutiny, and a continuity plan somebody has actually tested. We advise on how to structure a security framework - not just how to configure it.

Four connected layers: governance, policy, continuity and technical controls.
Secondary activity

Risk management

You cannot protect everything equally, and trying to is how budgets get spent on the wrong controls. Risk management is the work of deciding, deliberately, what you are going to defend and what you are willing to accept.

What we look at

  • Inventory of systems, data and the processes that depend on them
  • Threat scenarios grounded in your sector and your actual exposure
  • Impact assessment in business terms: revenue, contractual, regulatory, reputational
  • Likelihood assessment based on existing controls, not wishful thinking
  • Third-party and supplier risk, including your critical SaaS dependencies
  • Existing insurance and contractual obligations

What you get

  • A risk register with a named owner for every entry
  • Treatment decisions recorded: mitigate, transfer, avoid or accept
  • Prioritised remediation roadmap tied to budget and effort
  • Board-ready summary of your top risks in plain language
  • A review cadence so the register does not go stale in a quarter
RISK REGISTERBUSINESS IMPACTSUPPLIER RISKISO/IEC 27005TREATMENT PLANNING
Secondary activity

Corporate security policies

Most policy sets fail for the same reason: they were downloaded, lightly edited, and describe a company nobody works at. We write policies against how your business actually operates, so people can follow them.

What we look at

  • Information security policy and the supporting standards beneath it
  • Acceptable use, remote and hybrid working, and bring-your-own-device
  • Access control, joiner-mover-leaver and privileged access
  • Data classification, handling and retention
  • Incident response and breach notification responsibilities
  • Supplier and third-party security requirements
  • Change management and secure development expectations

What you get

  • A coherent policy set, cross-referenced rather than contradictory
  • Written in language your staff will actually read
  • Clear ownership and an approval and review cycle
  • Supporting awareness material for rollout
  • Mapping from each policy to the controls that implement it
POLICY SETACCEPTABLE USEACCESS CONTROLDATA RETENTIONINCIDENT RESPONSEGDPR TOMs
Secondary activity

Business continuity planning

The question is never whether something will fail. It is how long you can operate while it is down, how much data you can afford to lose, and whether anyone has ever tested the answer.

What we look at

  • Business impact analysis: which processes actually stop the company
  • Recovery time and recovery point objectives agreed with the business
  • Dependency mapping, including the suppliers you cannot operate without
  • Disaster recovery design against those objectives
  • Crisis communication: who decides, who speaks, who gets told
  • Gaps between the plan on paper and the infrastructure in reality

What you get

  • A continuity plan tied to measured RTO and RPO targets
  • Recovery runbooks specific enough to follow under pressure
  • Call trees and decision authority, documented before you need them
  • Tabletop exercise facilitation with your team
  • A recovery test report - including what did not work
BIARTO / RPODR RUNBOOKSTABLETOP EXERCISESRESTORE TESTING
Secondary activity

Security framework alignment

Enterprise customers and regulators increasingly ask you to prove your security, not describe it. We map what you already do onto a recognised framework, then close the gaps in a sensible order.

What we look at

  • Gap analysis against ISO/IEC 27001, the CIS Controls or NIS2 obligations
  • Which requirements genuinely apply to a company of your size and sector
  • Existing controls that already satisfy requirements without anyone realising
  • Evidence you are currently producing but not retaining
  • Realistic sequencing, so the cheap wins come first

What you get

  • A control-by-control gap analysis with current status
  • Remediation roadmap phased across quarters, costed by effort
  • An evidence structure an external auditor will recognise
  • Statement of applicability groundwork
  • Support during customer security questionnaires and due diligence
ISO/IEC 27001CIS CONTROLSNIS2GAP ANALYSISAUDIT EVIDENCE

A note on certification. We prepare organisations for certification and support them through audits, but we are not an accredited certification body and we do not issue certificates. It would also be a conflict of interest for the people who designed your controls to certify them - so when you are ready for the formal audit, we will help you choose an independent certification body rather than pitch for the work ourselves.

Strategy is cheaper than an incident.

Whether you need a risk register from scratch or a second opinion on the one you have, start with a conversation. No obligation, and no sales sequence afterwards.