We measure programmes three ways, because one is not enough.
Every engagement starts with a diagnostic: is the programme performing, does it run fast enough, and who has the better information? A programme can pass one and fail the other two, and the failure is invisible until you ask all three.
Three lenses
Is it performing?
Availability — does the control exist where it should. Coverage — does it reach the population it was built for. Efficacy — does it mitigate the threat it was meant to. Efficiency — how much of the money becomes security. All four, composited, or the number lies.
Does it run fast enough?
Observe, orient, decide, act — treated as four named layers of architecture rather than a metaphor, each with its own measurable latency. A programme that decides correctly but slowly has already lost the exchange.
Who has the upper hand?
Security is a match-up, and the party with better information dominates it. We measure what your programme knows against what an adversary knows — per phase — and close the gap with reconnaissance, deception, and disclosure.
The three lenses triangulate. Where they agree, you have a finding. Where they diverge, you have the more interesting finding — and eight recognisable configurations to read it against.
What you can hire us for
Data security strategy & governance
A governance framework, a team that owns it, and uniform control objectives drawn from regulation, law, and your own policy. The deliverable is a programme that can be run, not a document that can be filed.
DLP programme design
Discovery, classification, and labelling; one global rule set instead of regional drift; and a review queue a human can actually keep up with. Usually the fastest measurable win in a data security programme.
Incident response
Timeline reconstruction from surviving evidence, containment that does not destroy what you need later, and a written account your regulator and your board can both read.
Custom tooling & automation build
Manual operation has a speed limit. We build the scanners, pipelines, and metrics platforms that lift it — in your stack, with your team, documented for handover.
Training & courseware
Material that teaches practitioners and students to think in match-ups rather than checklists — built on the same doctrine, delivered as workshops or as courseware your institution keeps.
Four stages, no surprises
Three-lens read on the programme as it stands. Two weeks, and it produces the scope for everything after.
Hands-on work against the systems that matter. Read-only in production unless agreed otherwise in writing.
Findings walked through with your engineers before the report exists. You will not be surprised by your own report.
Report, one-page summary, evidence index, and a remediation schedule with a named owner and a date per item.
Exclusions are agreed up front and printed at the same size as the scope. Evidence is held encrypted for ninety days from delivery, then destroyed — hashes are published in the report so you can verify any copy you were sent.
Volume problems and judgement problems
Every security programme contains two kinds of work. One is volume: classifying events, correlating records, checking a control still exists in ten thousand places. The other is judgement: deciding what a finding means, what it is worth, and what to do about it.
Programmes fail when the volume work crowds out the judgement work — when analysts spend the day clearing a queue and nobody has time to ask whether the queue measures anything. Machine augmentation is worth having precisely where it restores that time, and worth refusing where it pretends to make the judgement call.
That distinction is also the honest limit on automation. A model can tell you that ten thousand events look like ninety. It cannot tell you which of the ninety would end up in a regulator's letter.
Model the volume work explicitly, and measure what it costs you today before automating it.
Keep adjudication human, and give it enrichment rather than a verdict.
Compute the lenses programmatically. A metric assembled by hand each quarter is not a metric.
Assume the other side has the same tooling. Augmentation is available to adversaries too.
All of this comes from one place
The diagnostic, the pipeline, and the measurement lenses are all set out in full in our doctrine, with worked examples.