What we do
We offer various security consultancy services in whatever format works for you. Need a part time Virtual CISO to help manage your security? We can do that. If you have a specific project where you need more hands on work for a period of time, we can also assist there.
Our goal is to give you our security expertise in whatever format works for you, because we believe that everyone should be secure. Arkferos is about Security for all
Virtual CISO Services
If you need the expertise of a seasoned security leader, but not full time, a Virtual CISO on retainer is a great way to regular security advice for your business. A Virtual CISO can work for a set amount of time per month to assist to advise the business in security matters, assist with security reporting, risk management, compliance, and general security management
Security Posture & Risk Assessments (Strategy Building)
Do you know how much security do you really need? We can assess you security posture on industry standards like ISO 27001, CIS top 18, and NIST. We can also assess your risk with our homegrown “FAIR Lite” Risk Framework
Strategy Building
Based on security posture assessments, we can establish a roadmap from where you are, to where you should be in terms of security maturity. This will help you to focus fire on your most important security issues now and in the future.
Fixed Term & Project Based Consultancy
We can assist you with any number of fixed term projects, to help you deliver on a particular scope of security work. This can be the Security Architecture (the design & integration of security systems), Writing (policies, processes and standards), audits, crisis planning, or whatever you think you need. We can even set up Verkada physical security systems!
Services
- Policy Writing & Advice
- Process Design
- Cyber Strategy Building
- Security Programme Creation
- Security Function Design
- Crisis Planning & Management
- Information Security Management System design
- Enterprise Security Architecture
- Cyber Key Performance Indicator creation & reporting
- Security Assurance, Assessment & Threat Modelling
- Organisational Security Posture Assessment
- Risk Assessments
- Risk Appetite Workshops
- Risk Framework Development & Implementation
- Audit Preperation & Representation
- Technical Writing (Design & Architecture)
- Technical & Non-technical Proofs of Concepts and Implementations (Design & Build)
Technology
Please note this list is not exhaustive, and when it comes to a specific technology, skills with one vendor/software platform one are often transferrable to another. Please ask for any further information
GRC Tools
- Archer
- OneTrust
Infrastructure
- Google Cloud Platform
- VMware
- VirtualBox
- Docker
- Terraform
- Nginx
- Apache
- HaProxy
- WordPress
- Ubuntu
- CentOS
- Windows
- Checkmarks
SAST & PenTesting & DevSecOps
- Checkmarx
- Immuniweb Discovery
- Immuniweb OnDemand
- Gitlab
IAM, Encryption and PAM
- Active Directory
- Google Cloud IAM and IAP
- ADFS
- SAML & Oauth2
- OneLogin
- Hashicorp Vault
- CyberArk
- Google Cloud KMS
Endpoint Managment
- Automox
- Wazuh
- ClamAV
- Defender
- ESET
- Qualys
Security Incident Response, Operations / Monitoring
- Wazuh
- Elasticseach, Logstash, Kibana
- TheHive (Case Management)
- Cortex (Incident Response)
Generative AI
- Private GPT
- Ollama
- OpenWebUI
- AnythingLLM
- N8N (This is a general no-code automation platform)
Network Technology
- Websense / Forcepoint DLP
- Websense / Forcepoint Internet Gateway
- Zscaler
- Juniper
- Foundry
- Fortinet
Physical Security
- Verkada
How we do things
We craft hollistic security strategies and architectures, based on your organisation’s appetite for risk and your resources.
We think about security hollistically. To us this means that we’ll take a risk based approach to creating security strategies for your organisation: balancing your desired security posture, the minimum viable security needed for your organisation and the resources you have.
We care about realistic, effective security strategies, that focus on your biggest organisational security issues. We also try to help you plan for the future, so that you can feel more secure today and tomorrow.
A Risk Based Approach
One of the most important components of a security strategy is an organization’s appetite for risk. An organisation has many priorities and demands to keep up with. At the same time, resources are always limited, and security is not free. You need to make decisions about when and how to divert resources into security, to make sure you’re safeguarding what’s most important and not wasting precious resources on what’s not.
Many business don’t have a appetite for risk that’s already formulated, but not to worry, this is something we can help out with!
Minimum Viable Security
The context of every organisation changes the threats it faces, and the vulnerabilities it has. What all organisations have in common is that there is a minimum amount of security that is needed in order to mitigate the most common threats, and meet their contractual and regulatory requirements. We call this Minimum Viable Security, and it differs for every business. The minimum viable security for a small manufacturing business is different then a large one, or than a business that sells customer facing software.
We will help you to determine what this is for you, based on industry data, our experience, and best practice security standards like CIS top 18, NCSC Cyber Essentials, or ISO 27001
Your Desired Security Posture
Most conscientious organisation have a gap between where they are, and where they want to be. This is a fundamentally good thing, and important to a good security strategy, as it allows to create stability, through a long term vision. We can help you to set a target for how mature you want your security function to be and create a roadmap for the future of your organisation, and to ensure that you’re always on top, spending time doing what’s important to your organisation, rather than fighting fires (unless of course, that’s what your organisation does).
