Regulatory readiness
NIS Regulations 2018 and the Cyber Security and Resilience Bill, the NCSC Cyber Assessment Framework and GovAssure, the CAF-aligned DSPT, NIS2 and DORA for organisations serving EU entities.
Services
The four engineering services run as one loop, so the people who threat-modelled a system are the ones who attack it and the ones who fix it. The consultancy practice applies the same standard of evidence to regulation, assurance and the safe adoption of AI tooling.
1 · Design
Before architecture, we name what the system protects, who wants it and where trust changes hands. The threat model is a working document with a control register: for every claimed control, the code line that enforces it and the test that goes red when it is removed. Controls that turn out to be intentions rather than code are listed as such, because an assessor will find them anyway.
From ExPriori: a threat model with 13 trust boundaries, 3 attack trees, a control register of claim, enforcing line and revert-sensitive test, and a documented list of the blind spots it does not cover.
2 · Develop
We build in Rust, test-first, with every requirement carried in a traceability register and every governance rule turned into a gate that continuous integration runs. The default posture is fail-closed: a command that cannot do the work refuses it by name rather than printing a success message, and a listener that would reach beyond a private network refuses to start unless the operator says otherwise.
From ExPriori: an 11-crate Rust workspace of more than 440,000 lines, more than 4,500 tests, more than 600 traced requirements, a signed Windows installer and a browser console served from the binary itself.
3 · Pentest
Testing is scoped from the threat model, not from a tool's default profile. Every engagement runs under written rules of engagement with a standing authorisation, an evidence standard, a severity scale and a disclosure policy. Findings go into an exploit catalogue with a position, a rung on the escalation ladder and a citation to the line of code, and each is reproduced on a rig before it is reported. A finding that cannot be reproduced is a lead, and is labelled one.
From ExPriori: a programme whose re-derived catalogue found that the dominant defect class was not a broken control but an unreachable one, in four independent subsystems. The check that finds that class now runs in CI.
4 · Remediate
A finding is closed when the class is fixed, not the instance. Each remediation ships with a regression test that fails if the fix is undone, an updated entry in the compliance map for every control the change touches, and a note in the risk register recording what was found, what was done and what still stands. Where the honest answer is that a risk is accepted, the acceptance is recorded with a reason and a review date.
From ExPriori: dealer-plane modules that led one catalogue were closed by compilation, with a probe crate that requires each removed symbol to be absent from the default build. That is the strongest form of gate we know how to build.
5 · Consultancy
The consultancy practice draws on the founder's experience inside UK government cyber-security regulation and on the compliance engineering done for ExPriori. It is practical work: gap analyses that name the missing evidence, not the missing paragraph.
NIS Regulations 2018 and the Cyber Security and Resilience Bill, the NCSC Cyber Assessment Framework and GovAssure, the CAF-aligned DSPT, NIS2 and DORA for organisations serving EU entities.
Cyber Essentials and Cyber Essentials Plus readiness, ISO/IEC 27001 alignment, the Software Security Code of Practice, DCB0129 clinical safety and DTAC for health technology, UK GDPR and DPIAs.
Software bills of materials, dependency policy and licence posture; and a governed way to adopt AI coding assistants, with secure-coding rules, verification passes and measured cost.
Engagement shapes
Assessment
A threat model, a penetration test, a regulatory gap analysis or a code review with a written scope, a start date and a deliverable you can hand to your board or your assessor.
Build
Design, development, testing and remediation of a system or a component, delivered against milestones with the evidence trail growing alongside the code.
Retained
A standing arrangement for organisations that want a security engineer and a regulation specialist on call: design reviews, assessor preparation, incident support, second opinions.