What We Do

Five service lines.
One delivery standard.

We don't run a pick-list of services — every engagement is staffed by senior practitioners who own the outcome end to end. Below is the full catalogue of what our Singapore practice delivers, from MAS TRM, PDPA and the Cyber Trust Mark through to ISO/IEC 42001 for AI management systems, for clients here and worldwide.

01

Compliance

GRC Consulting

Frameworks, audits, and certifications — done as a programme, not a tick-box exercise. Now including AI governance.

What's included

Frameworks & certification

  • ▸ISO 27001:2022 implementation & internal audit
  • ▸SOC 2 (Type I & II) readiness
  • ▸PCI-DSS v4.0 (QSA-ready packages)
  • ▸Statement of Applicability automation

Singapore regulatory

  • ▸MAS TRM, MAS Notice 644, Cyber Hygiene Notice
  • ▸Singapore PDPA — DPO, DPIA, breach playbooks
  • ▸Cyber Trust Mark & Cyber Essentials certification
  • ▸SS 712:2025 readiness

AI governance

  • ▸ISO/IEC 42001 AI management system implementation
  • ▸ISO/IEC 42001 readiness & gap assessment
02

Offensive Security

Vulnerability Assessment and Penetration Testing (VAPT)

Two disciplines, one service line: vulnerability assessment establishes the breadth of exposure, penetration testing proves the depth. Reports built for both engineers and auditors.

What's included

Vulnerability assessment (VA)

  • ▸External & internal vulnerability assessment
  • ▸Static application security testing (SAST)
  • ▸Cloud security audit (AWS, GCP, Azure)
  • ▸Cloud configuration review
  • ▸Network configuration review

Penetration testing (PT)

  • ▸Dynamic application security testing (DAST) — web & API, OWASP/ASVS
  • ▸Mobile application security testing (MAST) — iOS & Android
  • ▸External & internal network penetration testing
  • ▸AI security testing — model, prompt, and AI-application
  • ▸IoT & embedded device testing
  • ▸Red-team & purple-team engagements
03

Strategy

Strategic / Virtual CISO

Senior security leadership on demand — for boards, audit committees, and growing security functions.

What's included

Security leadership

  • ▸Virtual CISO (vCISO) retainer
  • ▸Security roadmap & maturity assessments
  • ▸Board & audit-committee reporting

Assurance & diligence

  • ▸M&A and IPO security due-diligence
  • ▸Vendor risk & third-party assurance
  • ▸Security technology selection
04

People

Security Training

Awareness for every employee, technical depth for engineers, and tabletop exercises for leadership.

What's included

Workforce

  • ▸Phishing simulations & awareness
  • ▸Compliance training (PDPA, MAS, ISO)

Engineering

  • ▸Secure coding (OWASP Top 10, ASVS)
  • ▸Cloud security training (AWS / GCP / Azure)

Leadership

  • ▸Tabletop & breach simulations
  • ▸CISO and board-level briefings
05

Industrial

OT / ICS Security

For manufacturers, utilities, and critical infrastructure — IT/OT convergence done safely.

What's included

Assessment

  • ▸OT asset discovery & risk assessment
  • ▸Vendor & integrator security review

Standards & design

  • ▸IEC 62443 alignment
  • ▸NIST CSF & SP 800-82 mapping
  • ▸Network segmentation design
  • ▸OT continuity & recovery planning

How We Engage

Three engagement shapes.

Project

Fixed-scope, fixed-fee. Best for audits, assessments, pen-tests, and certification readiness with a defined output.

Retainer

Monthly hours pool for vCISO, advisory, assurance reviews, and ad-hoc requests. Renewable, with a roll-over allowance.

Programme

Multi-quarter security build-outs — typically a vCISO embed plus delivery streams (GRC, technical, training).

Not sure where to start?

Send us a one-paragraph description of your environment. We'll come back with a recommended starting point — fast, no pitch.

Talk to a Practitioner →