Binary2

Six practices, one accountable team.

We work where the demand is real: AI adoption that outran its controls, regulators asking for evidence, identity-led attacks, and systems that were never designed to be defended.

AI security and governance

Your teams are already using AI. Most organisations adopted it faster than they built controls around it, and regulators have noticed.

What we do

  • AI risk assessment across models, data, integrations and agents
  • Adversarial testing of LLM applications and agents: prompt injection, data leakage, tool abuse
  • AI governance frameworks aligned to ISO/IEC 42001, NIST AI RMF and the OWASP Top 10 for LLM applications
  • Shadow AI discovery and acceptable-use policy that staff will follow
  • Security due diligence on AI vendors and AI-enabled suppliers

What you get

An inventory of where AI touches your data, a ranked risk register, and controls your board and regulator can inspect.

Cyber strategy, risk and compliance

Risk assessment is still where most security spend starts, because everything else depends on knowing what matters.

What we do

  • Security maturity and risk assessments against NIST CSF 2.0 and ISO/IEC 27001
  • Virtual CISO and security leadership for firms without a full-time one
  • Certification and audit readiness: ISO/IEC 27001, SOC 2 and PCI DSS v4
  • Regulatory and data-protection readiness, mapped to the rules of your sector and jurisdiction
  • Third-party and supply-chain risk management
  • Board and audit-committee reporting in plain language

What you get

A funded, sequenced security roadmap and the evidence to stand behind it in an audit.

Security testing and assurance

Controls on paper are assumptions. Testing tells you which of them hold when someone competent pushes.

What we do

  • Penetration testing of web, mobile, API and internal networks
  • Red team and assumed-breach exercises scoped to realistic adversaries
  • Cloud configuration reviews across AWS, Azure and Google Cloud
  • Secure code and architecture review
  • Retesting to confirm fixes, included in the engagement

What you get

Findings ranked by business impact, each with a reproducible proof and a specific fix. No scanner output passed off as a report.

Cloud and identity security

Attackers log in more often than they break in. Identity is now the perimeter, and MFA alone no longer closes it.

What we do

  • Zero-trust architecture and migration planning
  • Identity, privileged access and conditional-access design
  • Phishing-resistant authentication and defence against token theft and MFA fatigue
  • Cloud security posture and landing-zone hardening
  • Microsoft 365 and Google Workspace security baselines

What you get

A target architecture, a migration plan in priority order, and hardened configurations handed over as code where possible.

Detection, response and resilience

Assume a bad day will come. What you control is how quickly you see it and how well the first four hours go.

What we do

  • Incident response plans and playbooks, tested rather than filed
  • Executive and technical tabletop exercises
  • Ransomware readiness and recovery assessments
  • SOC and detection-engineering advisory, including MDR provider selection
  • Backup, recovery and business-continuity assurance

What you get

A response capability your people have rehearsed, with named decisions, owners and escalation paths.

Security architecture and engineering

Security bolted onto a weak design stays weak. We build it into the architecture, the pipeline and the estate itself.

What we do

  • Security architecture review and design for networks, applications and data
  • Network segmentation and secure remote access
  • Secure development lifecycle and DevSecOps pipeline controls
  • Security tooling rationalisation and independent vendor selection
  • Cybersecurity due diligence for mergers and acquisitions
  • OT and IoT security assessments

What you get

A defensible design and an honest view of which tools you need, with no licences, hardware or resale margin attached to the advice.

Not sure which of these you need?

Most clients are not. Describe the situation and we will tell you where we would start, and why.

Talk to us