ESHAY ADVISORY
Two Eshay Advisory consultants working through a risk assessment with a client

Home  /  Approach

Methodology

Good security starts
with good judgement.

The same four movements on every engagement, scaled to the environment — from a six-week assessment to a multi-year program.

01 / AUDIT

Establish the real picture

We don't start with controls. We start with your organisation. Assets, dependencies, people, regulations and business priorities all influence the right answer.

  • Asset and data flow mapping
  • Regulatory obligation register
  • Threat scenario modelling
  • Control effectiveness testing
02 / SECURE

Decide and remediate

Recommendations only matter if they can be implemented. Every recommendation is prioritised against your architecture, constraints, budget and business priorities.

  • Risk-ranked remediation plan
  • Cost and effort estimation
  • Architecture and control design
  • Implementation alongside your teams
03 / MONITOR

Keep it true over time

Posture decays quietly after a report is signed. We keep exposure, intelligence and control verification running.

  • External exposure monitoring
  • Contextual threat intelligence
  • Detection engineering
  • Periodic control re-verification
04 / BUILD

Close the remaining gap

Most of the time, the right answer already exists. Sometimes it needs to be adapted. Occasionally, it needs to be built. We do whichever best fits the organisation.

  • Tooling gap analysis
  • Product design and development
  • Security review of what we ship
  • Handover, documentation and exit path
Principles

How we work, stated plainly.

These are the commitments we would want from an advisor, so they are the ones we hold ourselves to.

01

Your constraints are the brief

Legacy, budget, headcount and politics are inputs to the design, not excuses we work around later.

02

No finding without a decision

A vulnerability list is not an outcome. Every finding we deliver carries an owner, a cost and a recommended decision.

03

Senior people, on the work

The person who scoped your engagement is on it. We do not sell a partner and staff a junior.

04

Written for two audiences

Every deliverable has an executive layer and a technical layer, and they say the same thing.

05

We say what we do not know

Scope limits, residual risk and assumptions are stated. Confidence you cannot audit is worthless.

06

Nothing that locks you in

Documentation, source access and an exit path on everything we build. Dependency is a risk we would flag ourselves.

Engagement models

Three ways to start.

You need an answer

Fixed-scope engagement

Four to twelve weeks. An audit, a penetration test or a targeted review with a defined deliverable and a fixed price.

You need ongoing judgement

Retained advisory

Ongoing senior support: CISO-as-a-service, board reporting, architecture governance and the escalation line when something breaks.

You need capability

Embedded engineering

Our engineers inside your teams to design and ship controls, with a defined handover so capability stays with you.

Good security starts with understanding your organisation.

Every organisation has different constraints. Different technologies. Different priorities. That's why we don't start with a framework. We start by understanding yours.