CyberMarrow
Solutions

Controls that end up running in production

Six solution areas we deploy, operate through the bedding-in period, and then hand to your team with the runbook written. Each one ends with something switched on.

Identity & access management

Least privilege that survives contact with a real org chart.

Talk it through

Scope

  • Single sign-on and MFA rollout across workforce and customer identity
  • Joiner-mover-leaver automation wired to your HR system, so access ends when employment does
  • Privileged access management, just-in-time elevation and break-glass procedures that are actually tested
  • Quarterly access review that produces evidence auditors accept
  • Service account and workload identity clean-up — usually the largest single risk reduction available

SIEM integration

Detection you can act on, rather than a bill for log storage.

Talk it through

Scope

  • Source onboarding and normalisation across cloud, endpoint, identity and network telemetry
  • Detection rules mapped to MITRE ATT&CK and tuned against your own traffic
  • Alert triage workflow and severity model, so on-call knows what a page means
  • Retention and cost design — hot, warm and archive tiers sized to your obligations
  • Purple-team validation: we generate the activity and confirm the alert fires

Data loss prevention

Classify what matters, then enforce it without grinding the business to a halt.

Talk it through

Scope

  • Data discovery and classification across file stores, databases and SaaS
  • Policy design with a monitor-first rollout, so you see the false positives before users do
  • Enforcement across email, endpoint, browser and sanctioned SaaS applications
  • Exception handling that gives people a legitimate route rather than a workaround
  • Reporting for regulators and for the executive who has to sign it

Application security testing

Findings your developers can act on, in the tools they already open.

Talk it through

Scope

  • SAST, DAST, secrets scanning and software composition analysis wired into CI
  • Baseline suppression so the first run does not bury the team in legacy noise
  • Triage and false-positive tuning — we own the signal quality, not just the tooling
  • Secure code review of the components that carry the most risk
  • Developer enablement sessions on the classes of bug your codebase actually produces

Penetration testing

Scoped, evidence-led testing with a report that reads like a work plan.

Talk it through

Scope

  • Web, mobile and API application testing against OWASP methodology
  • Internal and external network testing, including assumed-breach scenarios
  • Cloud configuration and privilege-escalation testing across AWS, Azure and GCP
  • Reproduction steps, proof of exploitation and a remediation order by risk and effort
  • Free retest of the findings you fix within the agreed window

Custom solution development

Where nothing off the shelf fits the constraint you are actually under.

Talk it through

Scope

  • Bespoke security tooling, internal portals and automation
  • Integrations between systems that were never designed to talk to each other
  • Data pipelines and reporting for compliance and operational reviews
  • Proof-of-concept work to de-risk a decision before you commit a budget to it
  • Handover with source, documentation and a working local environment
Selected work

What the engagements look like

Client names are withheld under our standard confidentiality terms. We are happy to talk through any of these in detail on a call.

Architecture review

Ride-hailing platform

A regional ride-hailing operator was hitting scaling limits during peak hours. We reviewed the target architecture, identified the coupling causing cascading failures, and sequenced a decomposition that held through the next peak season.

App modernisation

Information management vendor

A ten-year-old monolith was blocking a compliance certification. We containerised it, extracted three services along the audit boundary, and got the release cycle from quarterly to fortnightly.

Data analytics

Network services provider

Operational data sat in six systems and nobody trusted the numbers. We built the pipeline, the reconciliation and the reporting layer, then handed the whole thing to their internal team.

Data security

E-commerce retailer

Cardholder and personal data were spread across environments with inconsistent controls. We classified it, applied DLP and tokenisation where it mattered, and produced the evidence set for their PCI DSS assessment.

Service mesh

Network security vendor

Service-to-service traffic was unencrypted and unobservable. We implemented a service mesh with mutual TLS, traffic policy and per-service SLOs, without a maintenance window.

Start with the assessment

Most of these engagements began with a short, fixed-price review. You get a written findings note with severity, effort and a recommended order of work — useful whether or not you carry on with us.