Our methodology

One framework, from first scan to audit-ready proof.

The SHIELD Framework is how we secure a business end to end — six stages, fifty controls, and a single score out of 100 that tells you exactly where you stand. It's the backbone behind every audit, diagnostic, and roadmap we deliver.

✔ SHIELD™ · Scope · Harden · Identify · Evaluate · Layered Remediation · Document
IS
6 stages · 50 controls
1 score / 100
Scope Harden Identify Evaluate Remediation Document
6
Stages

A repeatable lifecycle, from scoping to sign-off.

50
Controls

Concrete checks mapped to real-world risk and regulation.

1
Score / 100

One honest number your leadership can act on.

The six stages

SHIELD, stage by stage

Each letter is a phase of the engagement — and a slice of your final score. Together they take a business from "we hope we're secure" to "we can prove it."

S

Scope

6 controls
Map everything worth protecting.

Define the boundary — assets, data flows, cloud accounts, endpoints, and which regulations apply. You can't secure, or score, what you haven't first scoped.

H

Harden

10 controls
Close the obvious doors first.

Apply the baseline protections that stop the most common attacks — MFA, patching, secure configuration, and access control — before chasing anything exotic.

I

Identify

9 controls
Find the weaknesses before attackers do.

Vulnerability assessment, VAPT, and threat identification across the scoped environment — surfacing the gaps that matter, not just a long list of noise.

E

Evaluate

8 controls
Score every control, honestly.

Measure the environment against the fifty SHIELD controls and the regulations that apply to you — producing the maturity score and the evidence behind it.

L

Layered Remediation

10 controls
Fix in priority order, in depth.

Remediate by risk, building defence in layers rather than one-off patches — each finding assigned an owner and tracked to closure, not left on a list.

D

Document

7 controls
Turn the work into proof.

Policies, evidence, and reporting an auditor, client, or regulator will accept — so your score isn't just a number, it's defensible when someone asks.

How the score works

Six stages in. One number out.

STEP 01
6 stages

Every engagement runs through all six SHIELD phases in order.

STEP 02
50 controls

Each stage carries a set of concrete controls, checked against your systems.

STEP 03
1 score /100

Control results roll up into a single maturity score — and a band.

0 – 39
Exposed
40 – 64
Developing
65 – 84
Managed
85 – 100
Resilient
See it on your own business

Get an indicative SHIELD score in three minutes.

The free Scorecard runs a light version of the framework on your own answers — a preview of the number a full SHIELD audit would verify against all fifty controls, on your actual systems.