A methodology built to end in implementation.

Five disciplined phases. Each produces a defined executive output, and each is designed to be auditable, proportionate and owned by the organization once we step back.

  1. 01

    Understand

    Business objectives, operating context, stakeholders and constraints. We map what the organization is actually trying to achieve before assessing what could prevent it.

    OutputContext & scope definition
  2. 02

    Assess

    Structured risk assessment across strategic, operational, environmental and human dimensions, with exposure expressed in terms leadership can compare and prioritise.

    OutputRisk register & exposure analysis
  3. 03

    Plan

    Treatment strategies, governance model, continuity and crisis architecture — sequenced against budget, operational reality and the organization’s risk appetite.

    OutputIntegrated risk & resilience plan
  4. 04

    Implement

    Protocols, roles, training, exercises and supplier alignment. We work alongside internal teams so the model is adopted rather than filed.

    OutputOperating protocols & capability build
  5. 05

    Strengthen

    Measurement, review cycles, lessons learned and maturity progression — converting a project into a durable organizational capability.

    OutputAssurance, metrics & maturity roadmap

In practice

How an engagement actually runs.

The five phases are a structure, not a fixed contract length. Some engagements stop after Assess because that is what the decision required. Others begin at Implement, because the analysis already exists and what is missing is adoption.

Scoped in writing

Deliverables, owners and review points are agreed before work begins.

Sequenced to the decision

Where a date is fixed, we deliver what unblocks it first and complete the rest in parallel.

Led personally

Senior involvement is not a pitch-team appearance; it continues through delivery.

Built with your team

Internal ownership is designed in, so the model survives our departure.

Proportionate

Controls are sized to real exposure and real budget, not to a template.

Confidential

Client identity, scope and findings are not disclosed. That is the default, not an option.

Grounded in

Recognized frameworks, applied locally.

The method draws on internationally recognized bodies of good practice in strategic risk, security risk management, business continuity and organizational resilience — giving clients a professional language their boards, insurers and lenders already understand.

See the methodology

Let’s start the conversation.

Request a Confidential Consultation

Response within two business days · Confidentiality assured