What We Do

Six service lines.
One delivery standard.

We don't run a pick-list of services — every engagement is staffed by senior practitioners who own the outcome end to end. Below is the full catalogue of what our Singapore practice delivers across Asia Pacific.

01

Compliance

GRC Consulting

Frameworks, audits, and certifications — done as a programme, not a tick-box exercise.

What's included

  • ISO 27001:2022 implementation & internal audit
  • SOC 2 (Type I & II) readiness
  • PCI-DSS v4.0 (QSA-ready packages)
  • MAS TRM, MAS Notice 644, Cyber Hygiene Notice
  • Singapore PDPA — DPO, DPIA, breach playbooks
  • Statement of Applicability automation
02

Offensive Security

VAPT — Penetration Testing

Red, grey, and white-box testing across the stack. Reports built for both engineers and auditors.

What's included

  • Web application & API testing (OWASP, ASVS)
  • Mobile app testing (iOS / Android)
  • External & internal network pen-tests
  • Cloud configuration review (AWS, GCP, Azure)
  • IoT and embedded device testing
  • Red-team & purple-team engagements
03

Strategy

Strategic / Virtual CISO

Senior security leadership on demand — for boards, audit committees, and growing security functions.

What's included

  • Virtual CISO (vCISO) retainer
  • Security roadmap & maturity assessments
  • Board & audit-committee reporting
  • M&A and IPO security due-diligence
  • Vendor risk & third-party assurance
  • Security technology selection
04

People

Security Training

Awareness for every employee, technical depth for engineers, and tabletop exercises for leadership.

What's included

  • Phishing simulations & awareness
  • Secure coding (OWASP Top 10, ASVS)
  • Cloud security training (AWS / GCP / Azure)
  • Tabletop & breach simulations
  • Compliance training (PDPA, MAS, ISO)
  • CISO and board-level briefings
05

24/7

Incident Response

24/7 retainer for ransomware, data breaches, fraud, and APAC-region cross-border incidents.

What's included

  • IR retainer (24/7 on-call)
  • Ransomware response & negotiation support
  • Digital forensics (host, cloud, mobile)
  • Breach notification & regulator liaison
  • Threat hunting & compromise assessment
  • Post-incident control hardening
06

Industrial

OT / ICS Security

For manufacturers, utilities, and critical infrastructure — IT/OT convergence done safely.

What's included

  • OT asset discovery & risk assessment
  • IEC 62443 alignment
  • NIST CSF & SP 800-82 mapping
  • Network segmentation design
  • OT-aware incident response plans
  • Vendor & integrator security review

How We Engage

Three engagement shapes.

Project

Fixed-scope, fixed-fee. Best for audits, assessments, pen-tests, and certification readiness with a defined output.

Retainer

Monthly hours pool for vCISO, IR readiness, advisory, and ad-hoc requests. Renewable, with a roll-over allowance.

Programme

Multi-quarter security build-outs — typically a vCISO embed plus delivery streams (GRC, technical, training).

Not sure where to start?

Send us a one-paragraph description of your environment. We'll come back with a recommended starting point — fast, no pitch.

Talk to a Practitioner →