Where We Add Value

Six practice areas across audit, assessment, offensive security, advisory, and leadership.

Service 01

ISMS / PIMS / AIMS: Gap Assessment, Implementation & Audit

Structured gap assessment and implementation for ISO 27001, ISO 27701, and ISO 42001. Control frameworks and evidence trails built for certification bodies — not template decks.

Banks, FinTechs, insurers, and IT service organisations in Nepal preparing for ISO/IEC 27001:2022 certification — or extending to ISO/IEC 27701 (privacy) or ISO/IEC 42001 (AI management). Also suited to teams with an existing ISMS that need a credible gap assessment before internal audit or certification body review.

#iso-27001#iso-27701#iso-42001#gap-assessment
Plan your certification roadmap
01

How we work

  1. 1

    Gap Assessment

    Baseline your current controls against the applicable standard clauses and Annex A controls, with evidence review and stakeholder interviews.

  2. 2

    Remediation Roadmap

    Prioritised plan mapping gaps to owners, timelines, and resource needs — sequenced for certification readiness, not checkbox closure.

  3. 3

    Implementation Support

    Hands-on support building policies, procedures, risk treatment, and operational controls aligned to how your organisation actually works.

  4. 4

    Internal Audit

    Independent internal audit against the standard before the certification body arrives — findings you can fix, not surprises.

What you receive

  • Gap assessment report with clause-level findings and maturity ratings
  • Remediation roadmap with prioritised actions and ownership
  • ISMS / PIMS / AIMS documentation pack (policies, procedures, SoA)
Service 02

Information Security Audit — NRB & NIA Regulatory Compliance

Independent IS audits aligned to NRB and NIA supervisory requirements. SWIFT Customer Security Programme (CSP) assessment capability for institutions on the SWIFT network.

NRB-regulated commercial banks, development banks, finance companies, and microfinance institutions subject to Nepal Rastra Bank information systems audit requirements. NIA-regulated life and non-life insurers subject to Nepal Insurance Authority IT and information security supervisory expectations. SWIFT member institutions needing Customer Security Programme (CSP) gap analysis or attestation support ahead of annual reporting cycles.

#nrb#nia#swift-csp#regulatory-audit
Scope a regulatory audit
02

How we work

  1. 1

    Engagement & Scope

    Align audit scope to your regulatory filing, prior audit findings, and NRB/NIA circular requirements — including SWIFT CSP controls where applicable.

  2. 2

    Document Review

    Review IS policies, risk assessments, access management records, change logs, incident registers, and vendor due diligence evidence.

  3. 3

    Control Testing & Fieldwork

    Test key controls through sampling, configuration review, and interviews with IT, security, and business process owners.

  4. 4

    Findings Validation

    Validate observations with your team before finalisation — factual, evidence-backed findings rated by risk and regulatory impact.

What you receive

  • Information systems audit report aligned to NRB or NIA supervisory expectations
  • Findings register with risk ratings and regulatory reference where applicable
  • Management letter for board and senior leadership
Service 03

Vulnerability Assessment & Penetration Testing

Systematic VAPT across web, API, mobile, and network targets. Prioritised findings with reproducible evidence and remediation guidance your engineering teams can act on.

Organisations that need to prove what is exploitable before an audit, regulator review, or production release — including banks and FinTechs, software product teams, and enterprises with internet-facing applications or APIs. Suitable when you need scoped testing of defined targets, not a full red team programme.

#vapt#web-application#api-security#network-testing
Request a VAPT scope
03

How we work

  1. 1

    Scoping

    Define in-scope assets, testing boundaries, rules of engagement, and success criteria with your technical and business owners.

  2. 2

    Assessment

    Vulnerability scanning and manual penetration testing across agreed targets — web, API, mobile, or network — using OWASP-aligned methods.

  3. 3

    Findings

    Document each finding with reproducible steps, evidence, severity rating, and practical remediation guidance for your engineering team.

  4. 4

    Retest

    Retest remediated findings and issue confirmation of closure — or document residual risk where fixes are deferred.

What you receive

  • Technical penetration test report with step-by-step reproduction evidence
  • Executive summary for leadership and audit stakeholders
  • Findings register with severity ratings and remediation recommendations
Service 04

Offensive Security & Red Team Engagements

Adversary simulation and red team exercises that test detection, response, and control effectiveness — a higher-tier engagement than scoped VAPT, aligned to realistic attack objectives.

Mature security programmes — typically banks, FinTechs, and critical infrastructure operators — that have already addressed baseline vulnerabilities and want to test whether detection, response, and governance hold under realistic attack pressure. Not a substitute for a first VAPT; this is the next tier when you need to know if your SOC, IR process, and controls work together.

#red-team#adversary-simulation#purple-team#ttp-emulation
Discuss a red team scope
04

How we work

  1. 1

    Objectives & Threat Profiling

    Define attack objectives, scope boundaries, and threat scenarios aligned to your risk profile and regulatory context.

  2. 2

    Reconnaissance & Initial Access

    Simulate adversary recon and entry using agreed TTPs — phishing, external exploitation, or assumed-breach scenarios as scoped.

  3. 3

    Lateral Movement & Objective Execution

    Pursue agreed goals such as privilege escalation, data access paths, or control bypass — within rules of engagement.

  4. 4

    Detection & Response Review

    Document what was detected, when, and by whom — and where monitoring, alerting, or IR processes did not surface activity.

What you receive

  • Red team engagement report with attack narrative and timeline
  • Objective achievement summary and evidence artefacts
  • Detection and response gap analysis
Service 05

Information Security & Cybersecurity Consultation

Project-based advisory on architecture, control design, and incident readiness. Defined scope and deliverables — distinct from an ongoing vCISO retainer.

Organisations facing a specific security decision or deadline — a new system launch, vendor selection, incident readiness gap, architecture review before audit, or a board briefing on a defined risk topic. Suited when you need senior practitioner input on a bounded problem, not an embedded security executive on retainer.

#advisory#architecture-review#risk-assessment#project-based
Describe your project scope
05

How we work

  1. 1

    Problem Definition

    Agree the decision to be made, stakeholders, constraints, and what "done" looks like for this engagement.

  2. 2

    Current-State Review

    Review relevant architecture, controls, documentation, and interviews with your technical and business owners.

  3. 3

    Options & Recommendations

    Present assessed options with trade-offs, risk implications, and a clear recommendation — not open-ended slide decks.

  4. 4

    Deliverable Handover

    Issue agreed outputs in a format your team can act on — memo, assessment report, or briefing materials.

What you receive

  • Scoped advisory report or architecture assessment memo
  • Risk assessment and treatment recommendations (where in scope)
  • Vendor or technology security review summary
Service 06

vCISO / vISO: Strategic Security Leadership

Fractional CISO and ISO leadership on retainer — governance, risk management, and board reporting without full-time headcount. Practitioner-led GRC for regulated environments.

Banks, insurers, FinTechs, and mid-size enterprises that need executive-level security governance — risk registers, policy frameworks, regulator and board reporting — without hiring a full-time CISO. Especially relevant for NRB-regulated institutions building or maturing an information security function under supervisory scrutiny.

#vciso#viso#governance#grc
Book a strategy conversation
06

How we work

  1. 1

    Baseline & Risk Assessment

    Establish current security posture, regulatory obligations, and top risks with leadership alignment on priorities.

  2. 2

    Programme Design

    Define the security roadmap, policy framework, metrics, and governance structure for the retainer period.

  3. 3

    Operating Rhythm Embedding

    Establish steering committee cadence, incident escalation paths, and remediation tracking integrated with your teams.

  4. 4

    Ongoing Governance & Reporting

    Monthly or quarterly reporting to leadership, audit committee, and regulators as required — with honest risk status, not green-washing.

What you receive

  • Maintained risk register and treatment tracking
  • Security programme roadmap with milestones
  • Policy and standards suite — drafted or reviewed on an ongoing basis
Managed Infrastructure

Deployments & Managed Solutions

Ready-to-deploy platforms and managed tooling — keeping your systems secure, observable, and operational.

Explore deployments →

SIEM - Log & Security Monitoring

Monitor logs and detect security threats in real-time for enterprise-grade protection.

Uptime, Service & Website Monitoring

Ensure your critical services and websites are always available and performing optimally.

Network & System Performance Monitoring

Track network and system health to prevent bottlenecks and downtime.

Web Traffic Log Analyzer

Analyze user traffic and trends to optimize website performance and engagement.

Dashboards & Portals

Centralized dashboards to visualize key metrics and manage resources efficiently.

Internet Bandwidth Tracker

Monitor internet usage and bandwidth to optimize connectivity and performance.

Container Management

Simplify deployment and orchestration of containerized applications for scalability.

Reverse Proxy & SSL Management

Secure and accelerate your web applications with proper SSL and proxy setups.

Remote Desktop Tool

Access and manage desktops remotely for support and collaboration.

Version Control & CI/CD

Manage code versions and automate deployments for development efficiency.

Password Manager

Securely manage credentials and access for teams with ease and safety.

Team Collaboration & Chat

Seamless communication and collaboration across teams for faster decision-making.

Project & Task Management

Plan, track, and manage projects and tasks effectively to meet deadlines.

Note-Taking & To-Do Management

Capture ideas and manage tasks efficiently for better productivity.

PDF Management

Organize, edit, and secure your PDF documents efficiently.

Document Management System

Store, track, and manage all your business documents in one place.

Cloud Storage & Team Collaboration

Secure cloud storage with integrated team collaboration tools.

Learning Management System

Deliver training and track learning progress across your organization.

HR Management System

Streamline HR processes from recruitment to employee management.

SIEM - Log & Security Monitoring

Monitor logs and detect security threats in real-time for enterprise-grade protection.

Uptime, Service & Website Monitoring

Ensure your critical services and websites are always available and performing optimally.

Network & System Performance Monitoring

Track network and system health to prevent bottlenecks and downtime.

Web Traffic Log Analyzer

Analyze user traffic and trends to optimize website performance and engagement.

Dashboards & Portals

Centralized dashboards to visualize key metrics and manage resources efficiently.

Internet Bandwidth Tracker

Monitor internet usage and bandwidth to optimize connectivity and performance.

Container Management

Simplify deployment and orchestration of containerized applications for scalability.

Reverse Proxy & SSL Management

Secure and accelerate your web applications with proper SSL and proxy setups.

Remote Desktop Tool

Access and manage desktops remotely for support and collaboration.

Version Control & CI/CD

Manage code versions and automate deployments for development efficiency.

Password Manager

Securely manage credentials and access for teams with ease and safety.

Team Collaboration & Chat

Seamless communication and collaboration across teams for faster decision-making.

Project & Task Management

Plan, track, and manage projects and tasks effectively to meet deadlines.

Note-Taking & To-Do Management

Capture ideas and manage tasks efficiently for better productivity.

PDF Management

Organize, edit, and secure your PDF documents efficiently.

Document Management System

Store, track, and manage all your business documents in one place.

Cloud Storage & Team Collaboration

Secure cloud storage with integrated team collaboration tools.

Learning Management System

Deliver training and track learning progress across your organization.

HR Management System

Streamline HR processes from recruitment to employee management.

SIEM - Log & Security Monitoring

Monitor logs and detect security threats in real-time for enterprise-grade protection.

Uptime, Service & Website Monitoring

Ensure your critical services and websites are always available and performing optimally.

Network & System Performance Monitoring

Track network and system health to prevent bottlenecks and downtime.

Web Traffic Log Analyzer

Analyze user traffic and trends to optimize website performance and engagement.

Dashboards & Portals

Centralized dashboards to visualize key metrics and manage resources efficiently.

Internet Bandwidth Tracker

Monitor internet usage and bandwidth to optimize connectivity and performance.

Container Management

Simplify deployment and orchestration of containerized applications for scalability.

Reverse Proxy & SSL Management

Secure and accelerate your web applications with proper SSL and proxy setups.

Remote Desktop Tool

Access and manage desktops remotely for support and collaboration.

Version Control & CI/CD

Manage code versions and automate deployments for development efficiency.

Password Manager

Securely manage credentials and access for teams with ease and safety.

Team Collaboration & Chat

Seamless communication and collaboration across teams for faster decision-making.

Project & Task Management

Plan, track, and manage projects and tasks effectively to meet deadlines.

Note-Taking & To-Do Management

Capture ideas and manage tasks efficiently for better productivity.

PDF Management

Organize, edit, and secure your PDF documents efficiently.

Document Management System

Store, track, and manage all your business documents in one place.

Cloud Storage & Team Collaboration

Secure cloud storage with integrated team collaboration tools.

Learning Management System

Deliver training and track learning progress across your organization.

HR Management System

Streamline HR processes from recruitment to employee management.

SIEM - Log & Security Monitoring

Monitor logs and detect security threats in real-time for enterprise-grade protection.

Uptime, Service & Website Monitoring

Ensure your critical services and websites are always available and performing optimally.

Network & System Performance Monitoring

Track network and system health to prevent bottlenecks and downtime.

Web Traffic Log Analyzer

Analyze user traffic and trends to optimize website performance and engagement.

Dashboards & Portals

Centralized dashboards to visualize key metrics and manage resources efficiently.

Internet Bandwidth Tracker

Monitor internet usage and bandwidth to optimize connectivity and performance.

Container Management

Simplify deployment and orchestration of containerized applications for scalability.

Reverse Proxy & SSL Management

Secure and accelerate your web applications with proper SSL and proxy setups.

Remote Desktop Tool

Access and manage desktops remotely for support and collaboration.

Version Control & CI/CD

Manage code versions and automate deployments for development efficiency.

Password Manager

Securely manage credentials and access for teams with ease and safety.

Team Collaboration & Chat

Seamless communication and collaboration across teams for faster decision-making.

Project & Task Management

Plan, track, and manage projects and tasks effectively to meet deadlines.

Note-Taking & To-Do Management

Capture ideas and manage tasks efficiently for better productivity.

PDF Management

Organize, edit, and secure your PDF documents efficiently.

Document Management System

Store, track, and manage all your business documents in one place.

Cloud Storage & Team Collaboration

Secure cloud storage with integrated team collaboration tools.

Learning Management System

Deliver training and track learning progress across your organization.

HR Management System

Streamline HR processes from recruitment to employee management.

Need something custom?

Discuss your threat profile →