← All expertise

Our areas of expertise

Cybersecurity

We support you across the entire cybersecurity lifecycle, from governance to incident response, building security around your risks and embedding it into day-to-day operations.

Discuss your needs

How we help

01 · Govern

Governance, risk & compliance

We define a security framework that fits your challenges and obligations.

  • Security policy Information systems security policy (ISSP)
  • Risk analysis & management Identifying and treating cyber risks
  • Compliance ISO 27001, PCI DSS, SWIFT CSP, personal data protection
  • BCP / DRP Business continuity and disaster recovery plans
02 · Assess

Audits & penetration testing

We find your weaknesses before attackers exploit them.

  • Organisational & technical audit Security maturity, practices and controls
  • CIS configuration audit System review against the CIS Benchmarks
  • Web & API penetration testing Applications, portals and exposed services
  • Infrastructure penetration testing Internal, external and Wi-Fi networks
  • Mobile penetration testing iOS and Android applications
03 · Protect

Protection & hardening

We sustainably reduce your attack surface.

  • System hardening Servers, endpoints, databases and network devices
  • Vulnerability management Regular scans, prioritisation and patch tracking
  • Identity & access IAM, privileged accounts and strong authentication
  • Secure architecture Network segmentation and cloud security
04 · Detect

Private SOC & monitoring

We watch your environment to detect threats as early as possible.

  • Security monitoring (SIEM) Event collection and correlation
  • Alert triage Analysis, qualification and escalation
  • Endpoint protection (EDR) Deployment and operation
  • Threat intelligence Tracking vulnerabilities and attack campaigns
05 · Respond

Incident response & recovery

We help you contain incidents and get back to business.

  • Incident response Containment, eradication and remediation
  • Digital forensics Forensic analysis and root-cause identification
  • Crisis management Coordination, communication and decision-making
  • Lessons learned Action plan to prevent recurrence
06 · Train

Awareness & training

We turn your teams into your first line of defence.

  • Staff awareness Everyday good practices and reflexes
  • Phishing simulation Measuring and improving vigilance
  • Technical training IT, development and security teams
  • Crisis exercises Tabletop incident simulations

Example deliverables

  • Security posture assessment and risk map.
  • Audit and penetration test reports with findings ranked by severity.
  • Monitoring setup, escalation procedures and dashboards.
  • Prioritised remediation plan and knowledge transfer.
Discuss your needs

Certifications

A network of certified experts

Nuwona draws on a network of consultants and experts holding the industry’s leading certifications, brought in according to the needs of each engagement.

Information security

  • ISO/IEC 27001 Lead Auditor
  • ISO/IEC 27001 Lead Implementer
  • CISSP
  • CISM
  • CISA
  • CEH
  • OSCP
  • CompTIA Security+

Cloud & infrastructure

  • AWS
  • Microsoft Azure
  • Google Cloud
  • Kubernetes (CKA)
  • Red Hat / Linux
  • Cisco CCNA / CCNP

Service & project management

  • ITIL 4
  • PMP
  • PRINCE2
  • TOGAF
  • Scrum / SAFe

Related expertise

Performance Engineering & Observability

Measure, understand and continuously improve service performance and reliability.

Explore this expertise →