Where We Add Value
Six practice areas across audit, assessment, offensive security, advisory, and leadership.
ISMS / PIMS / AIMS: Gap Assessment, Implementation & Audit
Structured gap assessment and implementation for ISO 27001, ISO 27701, and ISO 42001. Control frameworks and evidence trails built for certification bodies — not template decks.
Banks, FinTechs, insurers, and IT service organisations in Nepal preparing for ISO/IEC 27001:2022 certification — or extending to ISO/IEC 27701 (privacy) or ISO/IEC 42001 (AI management). Also suited to teams with an existing ISMS that need a credible gap assessment before internal audit or certification body review.
How we work
- 1
Gap Assessment
Baseline your current controls against the applicable standard clauses and Annex A controls, with evidence review and stakeholder interviews.
- 2
Remediation Roadmap
Prioritised plan mapping gaps to owners, timelines, and resource needs — sequenced for certification readiness, not checkbox closure.
- 3
Implementation Support
Hands-on support building policies, procedures, risk treatment, and operational controls aligned to how your organisation actually works.
- 4
Internal Audit
Independent internal audit against the standard before the certification body arrives — findings you can fix, not surprises.
What you receive
- Gap assessment report with clause-level findings and maturity ratings
- Remediation roadmap with prioritised actions and ownership
- ISMS / PIMS / AIMS documentation pack (policies, procedures, SoA)
Information Security Audit — NRB & NIA Regulatory Compliance
Independent IS audits aligned to NRB and NIA supervisory requirements. SWIFT Customer Security Programme (CSP) assessment capability for institutions on the SWIFT network.
NRB-regulated commercial banks, development banks, finance companies, and microfinance institutions subject to Nepal Rastra Bank information systems audit requirements. NIA-regulated life and non-life insurers subject to Nepal Insurance Authority IT and information security supervisory expectations. SWIFT member institutions needing Customer Security Programme (CSP) gap analysis or attestation support ahead of annual reporting cycles.
How we work
- 1
Engagement & Scope
Align audit scope to your regulatory filing, prior audit findings, and NRB/NIA circular requirements — including SWIFT CSP controls where applicable.
- 2
Document Review
Review IS policies, risk assessments, access management records, change logs, incident registers, and vendor due diligence evidence.
- 3
Control Testing & Fieldwork
Test key controls through sampling, configuration review, and interviews with IT, security, and business process owners.
- 4
Findings Validation
Validate observations with your team before finalisation — factual, evidence-backed findings rated by risk and regulatory impact.
What you receive
- Information systems audit report aligned to NRB or NIA supervisory expectations
- Findings register with risk ratings and regulatory reference where applicable
- Management letter for board and senior leadership
Vulnerability Assessment & Penetration Testing
Systematic VAPT across web, API, mobile, and network targets. Prioritised findings with reproducible evidence and remediation guidance your engineering teams can act on.
Organisations that need to prove what is exploitable before an audit, regulator review, or production release — including banks and FinTechs, software product teams, and enterprises with internet-facing applications or APIs. Suitable when you need scoped testing of defined targets, not a full red team programme.
How we work
- 1
Scoping
Define in-scope assets, testing boundaries, rules of engagement, and success criteria with your technical and business owners.
- 2
Assessment
Vulnerability scanning and manual penetration testing across agreed targets — web, API, mobile, or network — using OWASP-aligned methods.
- 3
Findings
Document each finding with reproducible steps, evidence, severity rating, and practical remediation guidance for your engineering team.
- 4
Retest
Retest remediated findings and issue confirmation of closure — or document residual risk where fixes are deferred.
What you receive
- Technical penetration test report with step-by-step reproduction evidence
- Executive summary for leadership and audit stakeholders
- Findings register with severity ratings and remediation recommendations
Offensive Security & Red Team Engagements
Adversary simulation and red team exercises that test detection, response, and control effectiveness — a higher-tier engagement than scoped VAPT, aligned to realistic attack objectives.
Mature security programmes — typically banks, FinTechs, and critical infrastructure operators — that have already addressed baseline vulnerabilities and want to test whether detection, response, and governance hold under realistic attack pressure. Not a substitute for a first VAPT; this is the next tier when you need to know if your SOC, IR process, and controls work together.
How we work
- 1
Objectives & Threat Profiling
Define attack objectives, scope boundaries, and threat scenarios aligned to your risk profile and regulatory context.
- 2
Reconnaissance & Initial Access
Simulate adversary recon and entry using agreed TTPs — phishing, external exploitation, or assumed-breach scenarios as scoped.
- 3
Lateral Movement & Objective Execution
Pursue agreed goals such as privilege escalation, data access paths, or control bypass — within rules of engagement.
- 4
Detection & Response Review
Document what was detected, when, and by whom — and where monitoring, alerting, or IR processes did not surface activity.
What you receive
- Red team engagement report with attack narrative and timeline
- Objective achievement summary and evidence artefacts
- Detection and response gap analysis
Information Security & Cybersecurity Consultation
Project-based advisory on architecture, control design, and incident readiness. Defined scope and deliverables — distinct from an ongoing vCISO retainer.
Organisations facing a specific security decision or deadline — a new system launch, vendor selection, incident readiness gap, architecture review before audit, or a board briefing on a defined risk topic. Suited when you need senior practitioner input on a bounded problem, not an embedded security executive on retainer.
How we work
- 1
Problem Definition
Agree the decision to be made, stakeholders, constraints, and what "done" looks like for this engagement.
- 2
Current-State Review
Review relevant architecture, controls, documentation, and interviews with your technical and business owners.
- 3
Options & Recommendations
Present assessed options with trade-offs, risk implications, and a clear recommendation — not open-ended slide decks.
- 4
Deliverable Handover
Issue agreed outputs in a format your team can act on — memo, assessment report, or briefing materials.
What you receive
- Scoped advisory report or architecture assessment memo
- Risk assessment and treatment recommendations (where in scope)
- Vendor or technology security review summary
vCISO / vISO: Strategic Security Leadership
Fractional CISO and ISO leadership on retainer — governance, risk management, and board reporting without full-time headcount. Practitioner-led GRC for regulated environments.
Banks, insurers, FinTechs, and mid-size enterprises that need executive-level security governance — risk registers, policy frameworks, regulator and board reporting — without hiring a full-time CISO. Especially relevant for NRB-regulated institutions building or maturing an information security function under supervisory scrutiny.
How we work
- 1
Baseline & Risk Assessment
Establish current security posture, regulatory obligations, and top risks with leadership alignment on priorities.
- 2
Programme Design
Define the security roadmap, policy framework, metrics, and governance structure for the retainer period.
- 3
Operating Rhythm Embedding
Establish steering committee cadence, incident escalation paths, and remediation tracking integrated with your teams.
- 4
Ongoing Governance & Reporting
Monthly or quarterly reporting to leadership, audit committee, and regulators as required — with honest risk status, not green-washing.
What you receive
- Maintained risk register and treatment tracking
- Security programme roadmap with milestones
- Policy and standards suite — drafted or reviewed on an ongoing basis
Deployments & Managed Solutions
Ready-to-deploy platforms and managed tooling — keeping your systems secure, observable, and operational.
SIEM - Log & Security Monitoring
Monitor logs and detect security threats in real-time for enterprise-grade protection.
Uptime, Service & Website Monitoring
Ensure your critical services and websites are always available and performing optimally.
Network & System Performance Monitoring
Track network and system health to prevent bottlenecks and downtime.
Web Traffic Log Analyzer
Analyze user traffic and trends to optimize website performance and engagement.
Dashboards & Portals
Centralized dashboards to visualize key metrics and manage resources efficiently.
Internet Bandwidth Tracker
Monitor internet usage and bandwidth to optimize connectivity and performance.
Container Management
Simplify deployment and orchestration of containerized applications for scalability.
Reverse Proxy & SSL Management
Secure and accelerate your web applications with proper SSL and proxy setups.
Remote Desktop Tool
Access and manage desktops remotely for support and collaboration.
Version Control & CI/CD
Manage code versions and automate deployments for development efficiency.
Password Manager
Securely manage credentials and access for teams with ease and safety.
Team Collaboration & Chat
Seamless communication and collaboration across teams for faster decision-making.
Project & Task Management
Plan, track, and manage projects and tasks effectively to meet deadlines.
Note-Taking & To-Do Management
Capture ideas and manage tasks efficiently for better productivity.
PDF Management
Organize, edit, and secure your PDF documents efficiently.
Document Management System
Store, track, and manage all your business documents in one place.
Cloud Storage & Team Collaboration
Secure cloud storage with integrated team collaboration tools.
Learning Management System
Deliver training and track learning progress across your organization.
HR Management System
Streamline HR processes from recruitment to employee management.
SIEM - Log & Security Monitoring
Monitor logs and detect security threats in real-time for enterprise-grade protection.
Uptime, Service & Website Monitoring
Ensure your critical services and websites are always available and performing optimally.
Network & System Performance Monitoring
Track network and system health to prevent bottlenecks and downtime.
Web Traffic Log Analyzer
Analyze user traffic and trends to optimize website performance and engagement.
Dashboards & Portals
Centralized dashboards to visualize key metrics and manage resources efficiently.
Internet Bandwidth Tracker
Monitor internet usage and bandwidth to optimize connectivity and performance.
Container Management
Simplify deployment and orchestration of containerized applications for scalability.
Reverse Proxy & SSL Management
Secure and accelerate your web applications with proper SSL and proxy setups.
Remote Desktop Tool
Access and manage desktops remotely for support and collaboration.
Version Control & CI/CD
Manage code versions and automate deployments for development efficiency.
Password Manager
Securely manage credentials and access for teams with ease and safety.
Team Collaboration & Chat
Seamless communication and collaboration across teams for faster decision-making.
Project & Task Management
Plan, track, and manage projects and tasks effectively to meet deadlines.
Note-Taking & To-Do Management
Capture ideas and manage tasks efficiently for better productivity.
PDF Management
Organize, edit, and secure your PDF documents efficiently.
Document Management System
Store, track, and manage all your business documents in one place.
Cloud Storage & Team Collaboration
Secure cloud storage with integrated team collaboration tools.
Learning Management System
Deliver training and track learning progress across your organization.
HR Management System
Streamline HR processes from recruitment to employee management.
SIEM - Log & Security Monitoring
Monitor logs and detect security threats in real-time for enterprise-grade protection.
Uptime, Service & Website Monitoring
Ensure your critical services and websites are always available and performing optimally.
Network & System Performance Monitoring
Track network and system health to prevent bottlenecks and downtime.
Web Traffic Log Analyzer
Analyze user traffic and trends to optimize website performance and engagement.
Dashboards & Portals
Centralized dashboards to visualize key metrics and manage resources efficiently.
Internet Bandwidth Tracker
Monitor internet usage and bandwidth to optimize connectivity and performance.
Container Management
Simplify deployment and orchestration of containerized applications for scalability.
Reverse Proxy & SSL Management
Secure and accelerate your web applications with proper SSL and proxy setups.
Remote Desktop Tool
Access and manage desktops remotely for support and collaboration.
Version Control & CI/CD
Manage code versions and automate deployments for development efficiency.
Password Manager
Securely manage credentials and access for teams with ease and safety.
Team Collaboration & Chat
Seamless communication and collaboration across teams for faster decision-making.
Project & Task Management
Plan, track, and manage projects and tasks effectively to meet deadlines.
Note-Taking & To-Do Management
Capture ideas and manage tasks efficiently for better productivity.
PDF Management
Organize, edit, and secure your PDF documents efficiently.
Document Management System
Store, track, and manage all your business documents in one place.
Cloud Storage & Team Collaboration
Secure cloud storage with integrated team collaboration tools.
Learning Management System
Deliver training and track learning progress across your organization.
HR Management System
Streamline HR processes from recruitment to employee management.
SIEM - Log & Security Monitoring
Monitor logs and detect security threats in real-time for enterprise-grade protection.
Uptime, Service & Website Monitoring
Ensure your critical services and websites are always available and performing optimally.
Network & System Performance Monitoring
Track network and system health to prevent bottlenecks and downtime.
Web Traffic Log Analyzer
Analyze user traffic and trends to optimize website performance and engagement.
Dashboards & Portals
Centralized dashboards to visualize key metrics and manage resources efficiently.
Internet Bandwidth Tracker
Monitor internet usage and bandwidth to optimize connectivity and performance.
Container Management
Simplify deployment and orchestration of containerized applications for scalability.
Reverse Proxy & SSL Management
Secure and accelerate your web applications with proper SSL and proxy setups.
Remote Desktop Tool
Access and manage desktops remotely for support and collaboration.
Version Control & CI/CD
Manage code versions and automate deployments for development efficiency.
Password Manager
Securely manage credentials and access for teams with ease and safety.
Team Collaboration & Chat
Seamless communication and collaboration across teams for faster decision-making.
Project & Task Management
Plan, track, and manage projects and tasks effectively to meet deadlines.
Note-Taking & To-Do Management
Capture ideas and manage tasks efficiently for better productivity.
PDF Management
Organize, edit, and secure your PDF documents efficiently.
Document Management System
Store, track, and manage all your business documents in one place.
Cloud Storage & Team Collaboration
Secure cloud storage with integrated team collaboration tools.
Learning Management System
Deliver training and track learning progress across your organization.
HR Management System
Streamline HR processes from recruitment to employee management.
Need something custom?
Discuss your threat profile →