Services Framework Engagement Model Who We Serve FAQ Contact

Home / Framework

The framework

Structured against five pillars, not a stack of best-practice guesses

Every CSISC engagement is organised against the same register your board will eventually see: Identify, Protect, Detect, Respond, Recover — the structure behind the NIST Cybersecurity Framework, adapted to plain business language.

Illustration of the five pillars mapped as connected nodes

Why it matters

A common language between your vCISO and your board

The five pillars give every finding a home. Instead of a pile of disconnected recommendations, your board sees one register that only ever grows more complete.

Advisory aligned to
NIST CSF ISO/IEC 27001 NCSC Cyber Essentials GDPR / UK DPA DORA SOC 2
§1 / 5

Identify

Map assets, data flows and third-party dependencies to understand what actually needs protecting, and what threatens it.
§2 / 5

Protect

Design and prioritise the policies, controls and architecture decisions that reduce risk to an agreed appetite.
§3 / 5

Detect

Assess monitoring coverage and close the visibility gaps that let incidents go unnoticed.
§4 / 5

Respond

Build and rehearse incident response plans so the first hours of a real incident aren't spent improvising.
§5 / 5

Recover

Plan for continuity and resilience, and turn every incident — real or simulated — into a documented improvement.

Why a fixed framework

Consistency your board can follow, engagement after engagement

Ad hoc consulting produces ad hoc reporting. Because every finding, recommendation and status update is mapped to one of the five pillars, your board sees a consistent register over time — not a new format every quarter. It also makes it straightforward to demonstrate progress against ISO 27001, Cyber Essentials or the NIST CSF directly, since the underlying structure is the same.

See how the framework applies to your organisation