Services

Security

Cyber Security

Security for the systems that hold identities, payments and operational data.

Overview

Operations that handle passports, patient records, card payments and door access are worth attacking. Cyber Security covers the systems that hold that data, from the architecture they are built on to the people who can reach them and the response when something goes wrong.

We start by finding out what is actually there: which systems hold sensitive data, who has access and why, where credentials are kept and what is logged. Findings are ranked by risk and fixed in order, with least-privilege access, managed secrets, separation of duties and audit logging built into the systems rather than documented beside them.

Security does not end at handover. We monitor for suspicious activity, write incident response plans that say who is called and what happens first, and review the architecture again whenever the systems change.

Capabilities

Security assessments

Systems, configurations, code and access reviewed against known weaknesses, including penetration testing, with findings ranked by risk.

Identity and access control

Role-based access, separation of duties, multi-factor authentication and single sign-on, so each person reaches only what their work requires.

Secrets and encryption

Credentials held in a managed vault, rotated and scanned for in code, with sensitive data encrypted at rest and in transit.

Monitoring and incident response

Logging and alerting on the events that matter, and a written plan for who responds, how an incident is contained and how it is reviewed afterwards.

Secure architecture review

Designs for new and existing systems reviewed before they are built or changed, with security requirements written into the plan.

Vendor and supply chain security

Third-party software, integrations and suppliers assessed for the access they hold and the risk they carry.

Technical detail

Industries

Questions

Where does the work start?
With an assessment of what is actually running and who can reach it, delivered as a document you own. Remediation is scoped from its findings.
Do you only secure systems Opsian built?
No. We assess and secure the systems an organisation already runs, whoever built them.
Do you cover kiosks, door locks and other devices?
Yes. In a physical operation, connected devices are part of the attack surface, so they are assessed alongside the software and networks they depend on.
Talk to us about Cyber Security

More services