OBS services

Information systems, IT assurance, cybersecurity and forensics.

OBS provides consulting, IT systems audit, penetration testing, cyber-risk assessment, forensic analysis, monitoring, training and project management.

Security and assurance services

OBS audit, security and resilience services.

Engagements can cover a defined system, process, technology environment or organisation-wide audit programme.

01

Penetration testing

Penetration testing & vulnerability assessment

Discover internet-facing assets, scan for known weaknesses and manually validate findings through realistic attack techniques.

Explore in detail
  • External, internal and social-engineering testing
  • Web application and website testing
  • Email, password-service and VoIP testing
  • Manual vulnerability validation and remediation guidance
02

Security assessment & assurance

IT system & cyber-risk audit

Examine whether technology, supporting controls and governance help the organisation meet its objectives efficiently and securely.

Explore in detail
  • IT systems and control audit
  • Cyber-risk and resilience gap assessment
  • Business process controls
  • Prioritised enhancement roadmaps
03

Network & application security

Network & application security

Assess architecture, access, configuration and interfaces across networks, applications, servers, databases and the wider environment.

Explore in detail
  • Network architecture and control review
  • Application security and capacity
  • Firewall, router and VPN configuration
  • Database and server security
04

Business continuity audit

Business continuity & capacity assurance

Review recovery capability and identify gaps across backups, restoration, system clusters, failover and supporting documentation.

Explore in detail
  • Backup and restoration review
  • Cluster and failover testing
  • Capacity and continuity gap analysis
  • Recovery control recommendations
05

Governance, risk & compliance

Governance, risk & compliance

Review policies, procedures, controls and regulatory requirements, then identify gaps and corrective actions.

Explore in detail
  • Security strategy and process development
  • PCI DSS and ISO 27001 readiness assessment
  • Data-protection and regulatory gap reviews
  • Fraud-management framework and enhancement planning
06

Forensic analysis

Digital forensics & incident response

Review incident response programmes and analyse selected forensic evidence, logs and security events.

Explore in detail
  • Incident response programme review
  • Selected forensic analysis
  • Log monitoring and investigation
  • Detection and response readiness

Consulting and project support

Information systems, project management and capacity building.

OBS supports information asset acquisition, deployment, use and support through consulting, project delivery, training and ongoing assurance.

07

Information systems

Information Systems Advisory

Advise on information asset acquisition, deployment, use, support and ongoing improvement.

  • Information-system strategy and process development
  • Asset acquisition and deployment advisory
  • Security controls implementation
  • Current-state and desired-state roadmaps
08

Project management

Digital Transformation & Project Management

Provide project management and staff augmentation from planning and audit design through fieldwork and reporting.

  • Digital transformation advisory
  • Project management and staff augmentation
  • IT steering, audit and board participation
  • Programme oversight and reporting
09

Training & awareness

Training & Capacity Building

Provide security awareness, systems and forensic-audit training, workshops and engagement knowledge transfer.

  • Cybersecurity awareness programmes
  • Systems and forensic-audit training
  • Knowledge transfer during engagements
  • Security process and control workshops
10

Threat detection & monitoring

Monitoring & Continuous Assurance

Provide recurring security reviews, vulnerability scanning, security-event analysis and compliance monitoring.

  • Quarterly vulnerability scanning
  • Security-event and breach monitoring
  • Periodic network posture reviews
  • Ongoing compliance monitoring

Work informed by recognised frameworks and good practice

COBIT®
IT governance
OWASP®
Application security
ITIL®
Service management
ISO / IEC
International standards
NIST
Cybersecurity framework

Contact OBS

Discuss the required scope of work with OBS.

Provide the information assets, systems, controls and service requirements to be included.

Contact OBS