Services

A niche consulting bench: advisory, engineering and managed defence

Our engineers come from the environments we secure — clinical networks, plant floors, colocation facilities, cloud platforms and AI teams. Every engagement ends with work your people can act on, not a PDF of scanner output.

Advisory & leadership

Senior judgement where the decisions are made — strategy, risk, compliance and vendor exposure.

Virtual CISO & Security Leadership

Senior security leadership on a fractional basis, from strategy and budget to regulator and customer liaison.

  • Programme strategy, roadmap and budget ownership
  • Framework selection and control baseline definition
  • Security policy and standards architecture
  • Board-ready risk reporting and committee attendance
  • Customer, auditor and regulator engagement support

Risk Analysis & Quantification

Asset-level, scenario-driven risk analysis that tells you what a failure would actually cost — and what to fund first.

  • Enterprise and asset-level risk assessment
  • Scenario and consequence modelling for critical systems
  • Quantified risk registers with treatment owners and dates
  • Control-gap analysis against NIST CSF 2.0 and ISO 27001
  • Regulator- and board-facing risk narrative

Governance, Risk & Compliance

One control set mapped across every framework you answer to, with the evidence collected as work happens rather than the week before an audit.

  • Unified control framework and multi-standard crosswalk
  • SOC 2, ISO 27001, HITRUST and HIPAA readiness
  • Policy, standard and procedure development
  • Audit evidence libraries and internal control testing
  • Security questionnaire and customer diligence support

Third-Party & Supply Chain Risk

Your vendors, model providers and integrators inherit your access. We assess them the way an attacker would choose one.

  • Vendor tiering and inherent-risk classification
  • Technical assessment of critical suppliers and integrators
  • Contractual security and AI-use requirements
  • Cloud, SaaS and model-provider dependency mapping
  • Continuous monitoring and reassessment cadence

Cybersecurity Compliance

Continuous readiness for the regulations and customer obligations you are held to, with evidence produced as part of normal operations.

  • Regulatory applicability and obligation mapping
  • HIPAA, GDPR and sector-specific compliance programmes
  • Control testing calendars and remediation tracking
  • Attestation and certification support end to end
  • Executive and regulator reporting packs

Security engineering

Controls designed, built and proven in your environment, not recommended and abandoned.

Cloud Security

Identity-first cloud architecture and posture management across AWS, Azure, GCP and Kubernetes.

  • Landing zone, tenancy and guardrail design
  • IAM, privilege and workload identity review
  • CSPM and CIEM implementation with real remediation ownership
  • Kubernetes and container runtime hardening
  • Infrastructure-as-code policy and drift control

Application Security

Secure engineering practice from design review to pipeline enforcement, not a scanner bolted onto a release.

  • Threat modelling and secure design review
  • SAST, DAST, SCA and secret scanning in CI/CD
  • API and web application security assessment
  • Software supply chain, SBOM and dependency governance
  • Developer-facing secure coding enablement

Security Engineering & Architecture

We design the controls, then build them with your teams — reference architecture, segmentation, identity and logging that hold up in production.

  • Reference security architecture and design reviews
  • Zero-trust and network segmentation engineering
  • Identity, privileged access and secrets management build-out
  • Logging, telemetry and detection pipeline engineering
  • Hardening baselines and configuration-as-code

Data Protection & Privacy Engineering

Find the regulated data, prove who can reach it, and keep it out of places it was never meant to travel.

  • Data discovery, classification and flow mapping
  • Encryption, key management and tokenisation design
  • DLP and egress control across cloud and AI tooling
  • HIPAA and GDPR privacy control implementation
  • Retention, minimisation and secure disposal

Domain specialisation

Deep practice in the environments where failure is physical, clinical or regulatory.

Secure AI & AI Security

Governance, threat modelling and adversarial testing for the models, agents and pipelines now making decisions inside your business.

  • AI/LLM threat modelling: prompt injection, tool abuse, data exfiltration
  • Adversarial evaluation of models, agents and retrieval pipelines
  • Guardrail, evaluation and monitoring architecture
  • AI governance mapped to the NIST AI RMF and ISO/IEC 42001
  • Training-data provenance, tenancy and model supply-chain review
Full AI security practice

OT & ICS Security

Protection for plant floors, utilities, building systems and clinical equipment where an outage is a physical event.

  • Passive asset discovery across OT and IIoT estates
  • Purdue-model segmentation and secure remote access design
  • IEC 62443 and NIST SP 800-82 gap assessment
  • Safety-aware vulnerability triage with engineering teams
  • OT incident response planning and tabletop exercises

Healthcare Security & Compliance

Programmes built for environments where downtime affects care and every regulator wants evidence.

  • Asset-level risk analysis across ePHI systems
  • HIPAA Security Rule, HITECH and GDPR readiness
  • HITRUST and SOC 2 preparation with evidence libraries
  • Connected medical device and clinical network review
  • Board and audit-committee risk reporting

Data Center Security

Physical, logical and infrastructure-layer defence for colocation, enterprise and edge facilities.

  • Physical access control and zoning assessment
  • Fabric segmentation, management-plane and out-of-band hardening
  • BMS, power and cooling system exposure review
  • Hypervisor, storage and backup isolation design
  • Resilience and site-failover validation

Detection, response & resilience

Threats seen early, answered by people who rehearsed it, with the business back on its feet fast.

Managed Detection & Response

Continuous monitoring, triage and containment across IT, cloud, OT and AI workloads, run by analysts who understand your environment.

  • 24/7 monitoring across endpoint, identity, cloud and OT telemetry
  • Analyst triage with containment actions, not just alerts
  • Threat hunting and intelligence-led detection tuning
  • Defined escalation paths into your teams and leadership
  • Monthly coverage, response-time and risk reporting

Detection & Response Engineering

Coverage measured against real attacker behaviour, with detections you own rather than a dashboard nobody trusts.

  • MITRE ATT&CK coverage assessment
  • Detection engineering and use-case development
  • SIEM and EDR tuning, triage playbooks and runbooks
  • SOC or MDR provider selection and oversight
  • Alert quality and response-time measurement

Incident Response & Resilience

A plan, a team and a rehearsal before the event, so decisions under pressure are not improvised.

  • Incident response plan development and retainer
  • Tabletop exercises across IT, OT and clinical stakeholders
  • Ransomware readiness and recovery sequencing
  • Backup immutability and restore testing
  • Post-incident review and control uplift

Frameworks and standards we work to

  • NIST CSF 2.0
  • NIST AI RMF
  • ISO/IEC 27001
  • ISO/IEC 42001
  • IEC 62443
  • HIPAA Security Rule
  • SOC 2
  • HITRUST CSF
  • GDPR
  • CIS Benchmarks
  • OWASP ASVS
  • OWASP Top 10 for LLMs

Not sure which service you need?

Most engagements start with an assessment, because it decides everything after it. Email info@blackharborsecurity.com and we will scope it with you.

Request a consultation