Get left of bang.

Assent Cyber is an information security consultancy. We measure the whole programme first, then say what to do about it in the order that reduces the most risk for the money.

The full site is being written. Until then this page is the whole of it, and enquiries go to hello@assentcyber.com.

Scroll to cross the line ↓

The line

There is a line, and you are on one side of it

Left of bang comes from the Marine Corps' Combat Hunter program. Plot an incident on a timeline. The explosion is bang. Left of it you have time, choices and leverage. Right of it you have none of the three. Here is one incident, plotted.

Access review skipped
Backup never tested
Alert nobody owns
Containment
Disclosure
The regulator
bang

Left of bang

Access review skipped

Someone leaves. Their account does not. Multiply by three years of leavers and the number of live credentials stops matching the number of people who work here. Cost of fixing it today: an afternoon, and somebody willing to own the list.

Left of bang

Backup never tested

The job runs nightly and reports success every morning. Nobody has restored from one. Until somebody has, a backup is a claim rather than a control, and proving it takes a morning.

Left of bang

Alert nobody owns

The tool fires correctly. It goes to a shared mailbox, or a channel, or a person who left in March. Detection was never the missing piece. A name against it was.

Right of bang

Containment

Hours now, not afternoons. Somebody is deciding what to disconnect on incomplete information, at speed, probably at night, and every option on the table costs the business money.

Right of bang

Disclosure

Seventy-two hours to the ICO where personal data is involved. Customers, insurers and the board all want the same answer at once, and nobody has it yet.

Right of bang

The regulator

The questions are the ones from the left of this line. Who owned it. When did you know. What had you tested, and when. Those answers were cheap to buy three screens ago.

The assessment

The Bangline Assessment

A facilitated review of the entire programme: people, process, technology, and the decisions behind all three. Four to six weeks, fixed fee, nothing to install. Five domains are scored.

Governance & risk
Who owns security, what the business has decided, and which risks it has accepted without saying so out loud.
People
Awareness that changes behaviour, joiners and leavers in practice, insider risk, and how much standing security has internally.
Process
Change, access review, vendor and third-party management, and how much of the documentation describes what actually happens.
Technology
Identity, endpoints, network, data and cloud configuration, reviewed against what the business does rather than a generic baseline.
Resilience
Detection, response and recovery, and whether any of it has been tested by someone allowed to say it failed.

The output

The Assent Score

One number the board can hold onto, and the finding list behind it that the team can work through.

01000

Reactive

Controls exist, most of them bought after something went wrong. Nobody in the building could tell you what is covered and what is not.

The score is the diagnostic, not the goal. Nobody should be aiming at 1000. The right score is the one the business has consciously decided to pay for.

The work

Everything else follows the findings

The assessment decides what the work is, and sometimes it decides the answer is very little, and not from us.

Bangline Assessment4–6 weeks, fixed fee

The front door. A facilitated review of the whole programme, ending in a score, a ranked list of findings, and a readout written for the board.

Roadmap & programme build12–24 months

Findings ranked by risk reduced per pound, sequenced into a plan with owners and a budget the finance director can read.

Fractional CISOMonthly retainer

Programme ownership, board reporting, vendor decisions and escalation, for organisations that need the function without the headcount.

Incident readinessProject or retainer

A response plan, tabletop exercises run against your real environment, and a standing number so the first call is never a cold one.

Compliance readinessISO 27001, Cyber Essentials, NIS2, DORA

Mapped out of the assessment rather than run as a separate project. Most of the evidence you need already exists somewhere.

Commitments

Five things we will not do

These are constraints rather than values. They cost us revenue, which is the only reason they are worth printing.

  1. Vendor-neutral, permanently

    No resale, no referral fees, no product revenue. There is nothing to buy from us, so our recommendation cannot be bought.

  2. The method is published

    Every domain and scoring criterion is public. You can grade yourself before you ever call us, and some of you should.

  3. Fixed fee for the diagnostic

    No change orders on an assessment. If we scoped it wrong, that is ours to absorb.

  4. We do not audit what we build

    If we help build the programme, someone independent certifies it. We will introduce them and then stay out of the room.

  5. Findings go to the board

    Not only to the person who hired us. This work fails when the results stop with whoever is most embarrassed by them.

Contact

Ask what the assessment would find on your programme

First contact is a conversation, not a scoping call with a proposal attached. If the honest answer is that you do not need us yet, we will say so.

hello@assentcyber.com