CyberMarrow
Services

Engineering practices, not billable line items

Five practices, staffed by the same people from assessment through to handover. Below is what each one actually involves and what you are left holding at the end.

AWS · Azure · GCP Kubernetes Terraform ISO 27001 · SOC 2 · PCI DSS Open Policy Agent

Cyber security

Threat modelling, control design and hands-on hardening — for the estate you actually have, not the reference architecture.

Typical engagement: a four-week posture review producing a prioritised remediation backlog, followed by a delivery phase that closes it.

Discuss this work

What is included

  • Cloud security posture review across AWS, Azure and GCP, with drift detection wired into your pipelines
  • Network and endpoint hardening, segmentation and egress control
  • Identity estate review: privileged accounts, service principals, standing access and break-glass
  • Incident readiness — detection coverage, runbooks and a tabletop exercise with your on-call team
  • Security audits mapped to ISO 27001, SOC 2 and PCI DSS control sets

Software development

Product teams that ship. Web, API and data platforms built to a security standard from the first commit.

We work in two-week increments with a demo at the end of each. You own the repositories throughout.

Discuss this work

What is included

  • Greenfield product engineering — discovery, architecture, build and launch
  • API and integration platforms, event-driven services and internal tooling
  • Front-end engineering with accessibility and performance budgets held as acceptance criteria
  • Threat modelling and secure-by-default patterns in the codebase, not in a policy document
  • Automated test suites and CI gates you inherit with the code

Application modernisation

Break the monolith deliberately. Decompose to services, contain workloads, and land on a platform your team can operate.

Modernisation only counts if the operating burden goes down. We measure that explicitly before and after.

Discuss this work

What is included

  • Domain decomposition and a sequenced migration plan with a rollback at every step
  • Containerisation and Kubernetes onboarding, including the parts most teams skip: quotas, policy and cost visibility
  • Service mesh implementation for traffic control, mutual TLS and useful failure isolation
  • Strangler-pattern delivery so the legacy system keeps serving traffic while it shrinks
  • Data migration with reconciliation, not hope

DevOps & platform engineering

Pipelines, infrastructure as code and release automation that turn deployment from an event into a routine.

The goal is boring deploys. We hand over the pipelines with the documentation your next hire will read.

Discuss this work

What is included

  • CI/CD design and rebuild — build, test, scan, sign, deploy, with the security gates in line rather than bolted on
  • Infrastructure as code in Terraform, with modules, review and drift detection
  • Observability: metrics, logs, traces and SLOs that map to something a customer would notice
  • Release strategy — blue/green, canaries, feature flags and a tested rollback
  • Developer platform work that removes the tickets between an engineer and an environment
Specialised services

The work that does not fit a neat category

Engagements we run alongside the core practices, sized to the problem rather than to a retainer.

Product engineering

End-to-end ownership of a product line — discovery, delivery and the roadmap in between.

Cloud services

Migration, landing zones, cost engineering and the operating model to run it all afterwards.

Cloud security posture review

A point-in-time read on your cloud accounts against a hardened baseline, with the remediation ordered by risk.

Project & delivery management

Delivery leadership for programmes with several vendors and no single throat to choke.

Architecture & solution design

Target-state architecture, trade-off analysis and the migration path between the two.

Compliance as code

Controls expressed as policy — Open Policy Agent, Terraform Sentinel and CI gates that generate audit evidence.

Staff augmentation

Vetted security and platform engineers who integrate with your team and your standards.

Security audits

Independent review against your chosen framework, with findings written for both the board and the backlog.

Not sure which of these you need?

That is the normal starting point. Book a call and describe the symptom — the failed audit, the slow release, the system nobody wants to touch. We will tell you what the underlying work is.