Cyber security advisory
A specialist practice for security architecture, management and compliance. We assess, design, build and run, and we take on as much of it as you want.
Scope agreed in writing before any work. No obligation.
When teams bring us in
You will probably recognise at least one of them.
“Our audit is in three months and we are not going to be ready.”
An audit, a customer contract that will not sign without a security questionnaire, or a new rule with a date attached. You know what needs doing. There are not enough weeks and not enough people.
We take the work that has to happen first and do it beside your team, so it is not queued behind everything else.
“I have just taken over security here and I need to establish the current state.”
You are new in the job, or the program has changed hands. You have been told it is all fine. You would rather see for yourself before you put your name to a plan.
We assess it independently and show you the evidence behind every finding, so you can take the answer to your board and defend it.
“We are being asked to secure something nobody here has secured before.”
AI tools your teams have already started using. A research cluster. Patient records or export-controlled data you have not held until now. Your team is good. This one is new to them.
We bring the architecture from somewhere we have already done it, then stay and build it rather than handing you a diagram.
Each one has an end date on it.
You are buying a period of senior help, not a dependency.
How we work
We assess where you stand, design the target state, stand it up, and run it. Each track is a full practice in its own right, with a dedicated page and named services behind it, and you decide how far it goes.
Every boundary is a decision you control: continue with us, bring it in-house, or pause. Nothing commits you to the next track.
The honest comparison
Here is the honest version, including the things the other three do better than we do.
A large consulting firm
The safe choice
A brand your board already recognises, and the scale to work in a dozen countries at once.
Contractors
Hands, at a day rate
Cheap capacity on a task you can specify precisely and supervise yourself.
Hiring for it
The long-run answer
The long run. Nothing replaces someone who is yours, and eventually you want that.
Alvor Advisory
One team, all four
The joins. The people who designed it are the people who build it and the people who run it.
A large consulting firm
The safe choice
A brand your board already recognises, and the scale to work in a dozen countries at once.
Contractors
Hands, at a day rate
Cheap capacity on a task you can specify precisely and supervise yourself.
Hiring for it
The long-run answer
The long run. Nothing replaces someone who is yours, and eventually you want that.
Alvor Advisory
One team, all four
The joins. The people who designed it are the people who build it and the people who run it.
All three can be the right call.
What none of them gives you is one team that stays.
What we are good at
Five kinds of work we have done many times over, and the part of each that catches people out.
Enterprise security architecture
Identity, cloud, network and endpoint, designed as one system rather than a shelf of products bought at different times by different people. This is most of what we do.
Redesigning it while it runs. Nobody gets to stop the business for a quarter.
Regulated and restricted data
Health records, research data held under conditions, export-controlled material, payment data. The rules that carry real penalties nearly all attach to one of these.
The obligation follows the copies, and almost nobody has a list of the copies.
Research and high-performance computing
Explore HPC securityShared machines, schedulers and the people who use them, secured against NIST SP 800-223 without taking the throughput the machine exists to deliver.
Enterprise controls assume a host you administer and can reboot. A cluster is neither.
One control set, every framework
We design the controls once and map them across ISO 27001, SOC 2 and NIST CSF, so a single piece of work evidences every standard you answer to.
Doing it in this order costs less than doing it four times, and almost no one does.
Governing AI adoption
From finding what your teams are already using through to a control plane built on ISO 42001 and the NIST AI Risk Management Framework.
It is already happening in your company. The only question is whether it is governed.
Enterprise security architecture
Identity, cloud, network and endpoint, designed as one system rather than a shelf of products bought at different times by different people. This is most of what we do.
Redesigning it while it runs. Nobody gets to stop the business for a quarter.
Regulated and restricted data
Health records, research data held under conditions, export-controlled material, payment data. The rules that carry real penalties nearly all attach to one of these.
The obligation follows the copies, and almost nobody has a list of the copies.
Research and high-performance computing
Explore HPC securityShared machines, schedulers and the people who use them, secured against NIST SP 800-223 without taking the throughput the machine exists to deliver.
Enterprise controls assume a host you administer and can reboot. A cluster is neither.
One control set, every framework
We design the controls once and map them across ISO 27001, SOC 2 and NIST CSF, so a single piece of work evidences every standard you answer to.
Doing it in this order costs less than doing it four times, and almost no one does.
Governing AI adoption
From finding what your teams are already using through to a control plane built on ISO 42001 and the NIST AI Risk Management Framework.
It is already happening in your company. The only question is whether it is governed.
Why architecture-led
A control added to clear a finding, a tool bought to satisfy a clause, and no one ever decided what good actually looks like. We design the target state first, then build and run to it, so the program holds together and holds up. One control set, designed once, evidences every standard you answer to at the same time.
What changes
Not a certificate on the wall. Four things you can check for yourself.
The audit is a six-week scramble
The evidence is already there
Four frameworks, four sets of the same work
One control set, mapped to all of them
It lives in one person's head
It is written down, with the reasons
You find out what is broken when someone asks
You knew, and it was already on the list
Who does the work
Architects and engineers who have built and run these systems in production, not career consultants. The people advising you have been on call for what they designed.
The obligation
Customers, regulators, and boards now expect demonstrable security, not intent. Whichever standard applies to you, it expects evidence on a schedule.
ISO 27001
The international baseline for an information security management system, and increasingly a condition of doing business with larger customers.
SOC 2
The report your customers ask for before they trust you with their data, assessed against the criteria you scope: the mandatory Security criteria, then Availability, Confidentiality, Processing Integrity, and Privacy as your commitments require.
NIST CSF 2.0
The common language for security posture and maturity, and the spine most board and regulator conversations now hang on, with governance now a function in its own right.
ISO 42001 · NIST AI RMF
As AI lands in your products and your teams' hands, customers and regulators are starting to ask the question they once asked of security: show us how you govern it.
DORA · NIS2
Binding for financial entities and essential services operating in Europe, with management accountability and incident-reporting clocks written into the statute.
HIPAA · GDPR · PCI DSS
Where you handle health, personal, or cardholder data, the obligation is statutory and the penalties for failure are real.
Working to a regional or sector regime, such as the Essential Eight, APRA CPS 234 and CPS 230, SOCI or IRAP in Australia, DORA or NIS2 in the EU and UK, or NIST SP 800-171 and CMMC in the US defence supply chain? We map the engagement to it directly. Region-specific guidance is published separately.
The practice
Alvor Advisory is the consulting arm of Alvor, the security architecture management and compliance platform company. We are new, and we are not going to pretend otherwise. We built the practice the way we tell clients to build a program, design first, so there is no legacy methodology to defend, no junior bench to keep billable, and no pyramid to feed.
The senior team that scopes your engagement designs the work, directs the hands-on delivery, and signs off the validation. Engineers build under that direction, never as a separate delivery organisation. Everyone holds the certifications relevant to their line of work: CISSP, ISO 27001 Lead Auditor and Lead Implementer, cloud security, and offensive security credentials.
We run our own security program on the platform we sell, held to the same separation of builder and judge we recommend to you: we build the posture, and independent assessors judge it.
Our advice is independent, never steered by a vendor's licences. Tooling is selected against your architecture, independent of any single vendor, our own platform included. We recommend Alvor where it is the right answer and say so plainly when it is not.
We take you to assessor-ready and stop. The certificate or attestation is issued by an independent body, by design: we build the posture, your assessor judges it. That separation is what makes the result count.
Global, with a named senior lead on every engagement. We work in the international standards and map directly to regional regimes, from the Essential Eight and APRA to DORA and NIS2.
Every engagement runs under a master services agreement and mutual NDA, with professional indemnity and cyber liability cover in place. Engagement data and evidence are segregated per client, and sub-processors are disclosed under NDA.
Proof of method
Eight pages of the standard Security Program Assessment report, redacted: the executive summary, the NIST CSF 2.0 maturity profile, the per-category summaries for Govern, a full control-level assessment with observations and recommendations, the risk-ranked gap register, and the prioritised roadmap. Names, owners, dates, and figures are removed; the method and depth are exactly what you receive.
Download the sample reportPDF · 8 pages · Reproduced from the 31-page deliverable, redacted for publication.
Findings at a glance
4.1 Maturity scorecard
NIST CSF 2.0 · Scale 0–5 · Prepared for
4.2 Gap register (extract)
Rows 14–16 of 27 · prioritised, risk-ranked
No privileged-access workflow for production
Owner · Remediation · Cost
Recovery objectives undefined for core services
Owner · Remediation · Cost
Vendor tiering absent above 50 suppliers
Owner · Remediation · Cost
The work behind this
That is about as hard as this work gets. The controls have to satisfy a federal auditor, on a machine where nobody will accept security that slows the science down. The same people do the work described on this page.
Named references on request.
We publish no anonymous or invented quotes.
The bridge
The advisory and the platform are two delivery models of the same thing: security architecture, management, and compliance. The advisory does it with people. The platform runs it as software. When the controls are standing, Operate keeps them current on Alvor, so your program maintains its own evidence and your team is not rebuilding the capability by hand. The program and its evidence stay portable: the platform earns the run, it never locks it.
The advisory
Designs the target state and stands it up, with people.
The platform
Runs the program as software, keeping the evidence current.
Who we work with
Regulated and high-growth organisations, typically 50 to 5,000 people, in the sectors where the obligation is sharpest: software, financial services, health, and critical services.
Founders, CTOs, and COOs writing the first security cheque. We stand up the first program in the right order and carry the leadership as a virtual CISO until you are ready to hire, then hand it over cleanly.
An established function that needs the scarce, intermittent work it cannot justify staffing: a target-state architecture, a unified control set, a build delivered to spec under your direction.
Leadership under pressure to show posture, not intent. We give you the maturity scorecard, the roadmap, and the evidence to stand up in front of a board, a regulator, or a customer's security team.
Questions
A focused diagnostic against the framework that applies to you. You receive a maturity scorecard, a prioritised gap register, and a risk-ranked view of your exposure. Scope is agreed in writing before any work begins.
The major international standards, including ISO 27001, SOC 2, NIST CSF, HIPAA, GDPR, and PCI DSS. Where a regional regime applies to you, we map the engagement to it directly.
No. Each phase ends in a decision that is yours. You can exit, bring the work in-house, or continue. The assessment stands on its own and commits you to nothing.
Both. After the architecture is designed, the build can be delivered hands-on, alongside a delivery partner, or by directing your own team under architectural oversight.
They are two delivery models of the same thing. The advisory designs and stands up your program with people. The platform runs it as software, so Operate keeps your evidence current on Alvor.
It is architecture-led. We treat designing the target state as the scarce, valuable work, and separate it from the build so the design is decided deliberately. Good architecture makes compliance a by-product rather than a scramble.
The architecture work is scarce and intermittent, so you get the design capability without carrying a permanent hire for it. Once the program is built, Operate can hand the run to your own team whenever you are ready, rather than leaving you dependent on us.
Seniority, not breadth. The senior team that scopes your engagement stays accountable for it from the whiteboard to the run book: the same people design the work, direct the hands-on delivery, and validate the result. There is no pyramid, no rotating bench of junior analysts, and no offshore delivery centre, and scope is fixed up front, so nothing is lost in a handover.
We set the architecture and the standard, then let your team execute under that oversight, so we add direction rather than displace anyone. You can engage a single phase, an assessment or an architecture, without committing to more, and keep us for the design work that never justifies a permanent hire.
No, and that is by design. We take you all the way to assessor-ready; the certificate or attestation is issued by an independent body. We build the posture, your assessor judges it. That separation is what makes the result count.
Yes, because the continuity is structural rather than heroic. The Alvor platform carries the operational load, the evidence collection, the scheduling, and the tracking, so the senior team stays on the decisions that need them. That is how the same team stays accountable across the lifecycle without a pyramid underneath it.
Operate runs the program: the controls, the evidence, the leadership cadence, and the tuning of the detection stack Build deployed. Around-the-clock eyes-on-glass monitoring is deliberately out of scope; where you need it, we scope a managed-detection provider into the operating model and hold them to the architecture.
Start here
Start anywhere on the lifecycle: a one-off assessment, a target-state architecture, a hands-on build, or a fully managed service. Every engagement is scoped in writing before any work begins, with no obligation to go further.
A call · 45 minutes, no slides
A scope, in writing · before anything starts
We start · usually with the assessment
Your enquiry
Tell us where you are and what you are looking for. We reply within one business day, and you see the scope in writing before you commit to anything.