What we do

Capabilities that turn cyber risk into confidence.

Five connected capabilities, delivered by senior security experts, from boardroom strategy to hands-on testing. Use one, or combine them into a programme that fits your organisation.

01

Cyber Strategy

Set direction and lead with confidence.

Security strategy and fractional CISO leadership that connect cyber investment to business priorities.

What we deliver

  • Virtual CISO
    Senior security leadership on a fractional basis: accountable, available and embedded in your team, without the cost of a full-time hire.
  • Security strategy & roadmap
    A prioritised plan that links security investment to your business objectives and risk appetite.
  • Security operating model
    Clear roles, responsibilities and governance, so security is owned across the organisation, not just by IT.
  • Board & committee reporting
    Metrics and briefings that give non-technical leaders a clear view of risk and progress.

02

Cyber Risk

Understand your exposure, and act on it.

Risk assessment, treatment and oversight that give leaders a clear, defensible view of cyber risk across the organisation and its supply chain.

What we deliver

  • Cyber risk assessment
    Identify and prioritise the threats, vulnerabilities and business impacts that matter most, using recognised methodologies.
  • Risk register & treatment plans
    A living register with clear owners, actions and timescales your leadership team can track.
  • Third-party & supply chain risk
    Assess and monitor the suppliers that handle your data and systems.
  • Cyber insurance readiness
    Prepare for insurer questionnaires and underwriting reviews, and understand the cover your risk profile needs.
  • Policy & governance
    A proportionate, usable set of policies, standards and procedures.

03

Cyber Assurance

Prove it to auditors, regulators and customers.

Independent audit and certification readiness against the standards your contracts and regulators require.

What we deliver

  • Certification readiness
    Prepare for the certifications your customers and contracts require, with gaps found and closed before the auditor arrives.
  • Internal & independent audit
    An objective view of how well your controls work in practice, not just on paper.
  • Regulatory & sector compliance
    Meet the expectations of regulators, government frameworks and sector schemes with confidence.
  • Continuous assurance
    Ongoing checks that keep you audit-ready between assessments.

04

Cyber Resilience

Test your defences before someone else does.

Testing and preparedness that show how you would hold up under attack, and how quickly you would recover.

What we deliver

  • Penetration testing
    Infrastructure, web application and cloud testing, with clear, prioritised findings.
  • Vulnerability assessment
    Regular scanning and review to keep known weaknesses under control.
  • Incident response planning
    Playbooks, roles and escalation paths, ready before you need them.
  • Tabletop & crisis exercises
    Realistic scenarios that let leaders and teams rehearse a live incident.

05

Secure by Design

Build security in, not bolt it on.

Architecture and design assurance so new services and cloud platforms go live with controls that work.

What we deliver

  • Security architecture review
    Independent review of designs for new and changing systems, with practical recommendations.
  • Cloud security review
    Configuration and architecture review across AWS, Azure and Google Cloud.
  • Threat modelling
    Identify how a system could be attacked, and design the right controls early.
  • Secure by Design support
    Help for public sector delivery teams meeting the UK Government Secure by Design principles.

Not sure where to start?

Tell us what you’re facing and we’ll point you in the right direction, even if that isn’t us.

Buying through G-Cloud?

Our services are available on G-Cloud 15.

Public sector organisations can engage NRD Partners quickly and confidently through the Crown Commercial Service framework.