Cybersecurity

Governance, monitoring and response sized for organisations that need a real security capability but not yet a forty-person one — built around Philippine regulatory obligations from the start.

Our Service Line

vCISO / Virtual CISO

A senior security executive for two to eight days a month — enough to own the risk register, roadmap and board conversation.

  • Ranked, costed risk register
  • 12-month security roadmap
  • Quarterly board reporting
Request a vCISO 

Managed Security (MSSP)

Twenty-four hour detection and response from our own security operations teams in Makati and Cebu.

  • SIEM and log management
  • Endpoint and identity monitoring
  • 15-minute P1 acknowledgement
Request Managed Security 

Compliance & Data Privacy (NPC/DPA)

Gap assessment, records of processing, filings and DPO support — privacy compliance finished, not perpetually in progress.

  • Data Privacy Act gap assessment
  • Records of processing inventory
  • NPC filings and DPO support
Request Compliance Support 

Incident Response

A retained response team with Philippine-based forensics and a two-hour response commitment.

  • 2-hour retained response, 24/7
  • Forensics with chain of custody
  • NPC notification support
Request Incident Response 

Our Process

How we build your security function

No recommendations before we know what you have, and every control leaves evidence an auditor can read.

  • Technical assessment, policy review and interviews to establish what is actually true today.

  • A ranked risk register with cost and effort against each item, agreed with your exec team.

  • Controls, tooling and process rolled out in the agreed order, with evidence captured as you go.

  • Detection tuned monthly, hunts scheduled, alert volume trending down rather than up.

  • Board reporting, tabletop exercises and an annual independent review.

Case Study

A national government agency

A vCISO engagement plus managed monitoring for an agency with no prior security operations coverage.

90 days
to 24/7 monitoring, from no coverage
15 min
P1 acknowledgement time
The Problem
No security function, no asset inventory and no monitoring — and hiring a CISO through public procurement would have taken longer than the exposure allowed.
The Solution
A fractional security executive built the inventory and roadmap, remediation was sequenced by consequence, and managed detection went live once logging was reliable.
The Results
24/7 monitoring within 90 days, a board-approved risk register, and a 15-minute P1 acknowledgement.

Case Studies

Results we’ve delivered

Cybersecurity engagements — the problem, what we did and what changed.

Frequently Asked Questions

If yours isn’t here, ask a practice lead directly.

Book a Call with Us
  • No. We give them a security function to work with, and we take the on-call burden they should never have had.

  • We implement what fits and we disclose every commercial relationship. Where you already own licences, we use them.

  • Yes, though retained clients get the two-hour commitment. Call the number on the contact page and say it is live.

  • We draft the notification and manage the 72-hour clock alongside your counsel. We have been through the process, including the follow-up questions.