Services
Cybersecurity engagements built around evidence and decisions.
Clear scope, practical deliverables, and collaboration with the people already responsible for your technology.
01
Northstar Security Evidence Review
Intended customer
Organizations that need a clear view of whether critical controls are documented and operating.
Problem addressed
Turns security assumptions into evidence management, insurers, and customers can review.
Scope
- Identity and access management
- Microsoft 365 or Google Workspace
- Endpoint, patch, external exposure, backup, and incident evidence
- Vendor risk, policies, and ownership
Deliverables
- Executive findings report
- Evidence and prioritised risk registers
- 30-, 60-, and 90-day roadmap
- Management presentation, technical recommendations, assumptions, and limitations
Estimated timeframe
Approximately 7–10 business days, depending on scope and access.
Client responsibilities
Provide agreed access, existing documentation, and a point of contact.
Exclusions
Not a penetration test, certification, legal review, or complete risk assessment.
Process
We agree the scope and access, review evidence, discuss findings, and document practical next actions.
Request an Evidence Review02
Northstar 90-Day Hardening Sprint
Intended customer
Organizations ready to act on agreed assessment findings.
Problem addressed
Converts a practical roadmap into coordinated security improvements.
Scope
- MFA and conditional access
- Administrative account separation and endpoint improvements
- Patch, firewall, backup, restoration, logging, policy, and playbook improvements
Deliverables
- Agreed implementation plan
- Documented changes and evidence
- Progress reviews and handover notes
Estimated timeframe
Planned around the environment and agreed scope.
Client responsibilities
Approve changes and coordinate required IT, MSP, and vendor access.
Exclusions
Final scope depends on the environment; it does not include unapproved production changes.
Process
We agree the scope and access, review evidence, discuss findings, and document practical next actions.
Discuss a Hardening Sprint03
Northstar Assurance
Intended customer
Leadership teams that need ongoing security governance without a full-time security team.
Problem addressed
Keeps evidence, ownership, and priorities current between major projects.
Scope
- Monthly control, identity, privileged-access, endpoint, patch, and exposure review
- Quarterly recovery review and executive risk discussion
- Documentation maintenance, questionnaire support, and incident escalation planning
Deliverables
- Regular evidence-informed reporting
- Updated risk and action register
- Coordinated review with internal IT or an MSP
Estimated timeframe
Ongoing monthly engagement with agreed review cadence.
Client responsibilities
Maintain agreed contacts and make timely ownership decisions.
Exclusions
Does not include 24/7 monitoring or incident response unless separately agreed.
Process
We agree the scope and access, review evidence, discuss findings, and document practical next actions.
Discuss Ongoing Assurance04
Incident Readiness Workshop
Intended customer
Leadership and IT teams that need to practise decision-making before an incident.
Problem addressed
Clarifies roles, escalation paths, and communications for ransomware or business email compromise scenarios.
Scope
- Facilitated executive tabletop
- Responsibilities, communications, insurance, legal, MSP, and leadership coordination review
Deliverables
- After-action report
- Updated response checklist
- Practical next actions
Estimated timeframe
Half-day or full-day engagement.
Client responsibilities
Identify participants and provide available response materials.
Exclusions
A workshop does not replace incident response, legal advice, or an active technical investigation.
Process
We agree the scope and access, review evidence, discuss findings, and document practical next actions.
Plan a Readiness Workshop