Cybersecurity Consulting

Some security decisions cannot wait for the next audit: an architecture that has to be signed off this week, a supplier to assess before signing, a large client’s questionnaire nobody knows how to answer. That is what consulting is for: independent technical judgement, when it is needed.

How it differs from the rest

Audit
Looking back
Checks what is already built and tells you what fails.
Consulting
Looking forward
Steps in before you build or sign, while correcting is still cheap.
CISO as a Service
Sustaining over time
A permanent security function, with a schedule and continuing accountability.

Where we help

Architecture review before deployment: segmentation, identity, encryption and single points of failure. Fixing a design costs a fraction of fixing a deployment.
Supplier and third-party risk assessment, at the level of rigour NIS2 and DORA now demand.
Vendor assessment questionnaires from large clients: we answer them with you and tell you what needs fixing before you reply.
Second opinion on a technical proposal or a tooling purchase. We do not resell licences, so we have no stake in the outcome.
Secure design of new products and services, building security in from the start instead of bolting it on at the end.
One-off risk assessment for a specific decision, with judgement and without standing up an entire management system.
Technical due diligence support for an acquisition.

How we work

1
Framing
What decision has to be taken, by when and who signs it. Consulting that does not end in a decision is an expensive conversation.
2
Analysis
Technical and documentary review of whatever exists: designs, contracts, proposals, configurations.
3
Recommendation
In writing, with the options, their risks and our reasoned position. With a view, not a menu for you to choose from alone.
4
Support
We attend the meeting where the decision is defended, if that helps.
5
Verification
When what was agreed gets implemented, we check it came out as designed.

Formats

By project: a scoped engagement with fixed deliverable and deadline.
Hours package: flexible consumption for recurring questions across the year.
Monthly retainer: if what you need is continuity, CISO as a Service probably fits better.
Who does the work. The same team that audits, not an account manager. Governance, risk and compliance: CISSP, CISM, ISO 27001 Lead Auditor, ENS and Risk Analysis (CCN), certified DPO, CCSP and CDPP (ISMS Forum) and PMP (PMI). On the technical side: OSCP, CRTO II and eWPTX, ranked in the top 1% of the CCN-CERT Atenea platform. We have run compliance projects for crypto exchanges, universities and public administrations.

Questions we get asked

Do you sell the solutions you recommend?
No. We do not resell licences or hardware and we have no commission arrangements with vendors. That is what makes our recommendation worth something.
Do you take small engagements?
Yes. Often the engagement is reviewing a design or giving a second opinion on a proposal, and it resolves in a few hours. The hours package exists for exactly that.
Do you work with our IT provider?
Yes, and it is usually the most effective arrangement. We bring the security judgement; they know your environment and deliver. We are not there to replace anyone.
Do you sign non-disclosure agreements?
Always, and before you show us anything.
Have a decision on the table?
Half an hour to put it to us. If it resolves in that half hour, then it is resolved.

Book 30 min with an auditor

Phone: +34 686 250 244 (Mon-Fri, 9:00 to 18:00 CET)  ·  Email: info@jaymonsecurity.com
We reply within 2 working hours.
ENES