Flagship engagement

Secure architecture review

A structured review of application and infrastructure design before threats harden into incidents.

Duration
2–4 weeks typical
Delivery
Remote workshops with optional on-site days in London
Pricing
From £6,800 per engagement
Request scheduling details
Security operations desk with multiple monitors showing network maps

Who it is for

Engineering leads and security owners preparing a new platform, a major rewrite, or a regulated launch.

Result you leave with

A written threat-informed architecture brief, prioritised remediation map, and a walkthrough with your build team.

Included

  • Scoped inventory of trust boundaries, identity flows, and data classes
  • Threat modelling sessions with product and platform engineers
  • Review of authn/authz patterns, secrets handling, and logging posture
  • Prioritised findings with effort estimates and acceptance criteria
  • Final briefing deck and architecture notes your team can own

Explicitly excluded

  • Full penetration testing or red-team operations
  • Ongoing SOC staffing or 24/7 monitoring
  • Writing production code on your repositories unless separately scoped

How the engagement runs

1

Scope lock

We agree systems in scope, data sensitivity, and decision owners before any deep dive.

2

Evidence gather

Diagrams, runbooks, IAM policies, and sample configs are reviewed offline between workshops.

3

Threat workshop

Facilitated sessions map attack paths against your real deployment topology.

4

Remediation map

Findings are ranked by exploitability and blast radius, with concrete engineering next steps.

Provider

Lead consultant with hands-on cybersecurity engineering background across UK product and infrastructure teams.

Preparation

Share current architecture diagrams, identity provider configuration summaries, and a list of systems that process customer or regulated data.

Constraints

We do not access live production secrets or private keys. Reviews stay within agreed environments and change windows.

Next step

If the perimeter matches your systems, use the contact page for phone, email, and office details, or read how Softgategrid engagements are staged.