What we do
Capabilities across the technology estate
Coldgrid is a technology and cybersecurity firm. Strategy, delivery, resilience, regulatory support, and outsourced operations sit under one operating model the client owns.
01
Strategy and architecture
Boards and executives get a technology and cyber strategy they can fund, sequence, and own.
We set the direction of the estate before tools are chosen. Architecture, operating model, and investment cases sit in one argument the Board can repeat.

Direction
Technology strategy and operating-model design
How the estate is owned, funded, and run — not a slide of initiatives.
Cyber strategy and security operating model
Diagnose, design, deliver. Residual risk labelled, owned, and dated.
Enterprise, cloud, and integration architecture
One picture of systems, identity, and the paths that join them.
Digital and data strategy
Analytics and platforms as a business asset, with classification from the start.
AI strategy with security and privacy constraints
Where models and copilots may sit, and where they must not.
Board, audit-committee, and CISO/CIO advisory
Judgement for listed groups and public organizations, not a vendor briefing.
Transformation roadmaps and investment cases
Sequence, cost, and what stops if a year of funding is cut.
02
Technology and cyber delivery
The estate is built and secured as one system, not a stack of tools.
Identity, applications, data, networks, and operational technology are installed so the client owns the controls. Cyber is not a side shop.

Technology
Cloud, infrastructure, and network engineering
On the platforms the client already runs, without a single-vendor mandate.
Identity and privileged access
Just-in-time, purpose-bound access. Identity attack-path discovery included.
Application platforms, APIs, and software supply chain
Build and change paths that can be evidenced, not gated the night before release.
Data platforms, analytics, and data security
Classification, encryption, and logged export treated as privileged actions.
Operational technology and the IT–OT boundary
Plant, terminal, field device, and telemetry — not another IT VLAN.
Collaboration, workplace, and enterprise applications
The estate people actually use, hardened to the same operating system.
Cyber
AI security
Copilots and agents purpose-bound. No standing privilege on operational or market-sensitive data.
Security operations
Detection and response on systems already run, including surge coverage. Not a parallel SOC by default.
Security testing
Vulnerability scanning and authorised penetration testing. No unattended testing against production.
Application security
Shift-left in the development workflow, so portals and APIs are evidenced as they are built.
03
Resilience: BIA, BCP, and disaster recovery
Process owners name recovery times. Technology is designed to those times. Residual risk sits on the Board record.
Business impact analysis first. Continuity plans from signed RTOs. IT and OT disaster recovery rewritten to the BIA — not the reverse. Cyber incident response is an annex, not a substitute for continuity.

Resilience
Business impact analysis
Signed RTO, RPO, MTPD, and MBCO, with a named owner for each critical process.
Business continuity plans
One template. Band 0–1 processes first. Plans operations can run at 2 a.m.
Crisis and incident management
A plan the executive can activate, with depth behind the named seats.
IT disaster recovery designed to BIA targets
Restore windows follow the business clock. Residual risk is written down if they cannot.
OT, field, and plant recovery annexes
Lanes, plants, terminals, and transmission paths as recovery objects — not an IT afterthought.
Vendor and concentration-risk continuity
Cloud, OEM, CSC, and interconnect paths treated as part of recovery, not as documentation tails.
Exercises, after-action, and residual-risk reporting
A functional exercise with a written after-action. Residual risk on the Board record.
Cyber IR as annex
Incident response cross-walked to the incident-management plan so ransomware does not create dual command.
04
Regulatory support
Overlapping duties become one control model and one evidence pack the Board, audit committee, and regulators can be shown.
We map duties, harmonize controls, and produce evidence the Board can stand on — without substituting for counsel, and without issuing certificates we do not award.

Map and harmonize
Multi-regime gap assessment
One review across the duties that actually apply — privacy, critical-infrastructure, listing, and sector rules — so the organizations builds once and answers many.
Control and policy harmonisation
A single control framework and policy hierarchy, not a parallel file for each regulator.
Regulatory change and horizon scanning
What is coming, what it changes in the estate, and what can wait. Dated residual risk where it cannot yet be met.
Evidence and programs
Board and audit-committee evidence
Reporting the executive can stand on: ownership, residual risk, and what was tested. Not a technical dump.
Privacy programme
NDPA 2023 / GAID, and UK GDPR where listing or establishment applies. ROPA, DPIA support, rights processes, and breach clocks. Not a substitute for counsel.
ISO 27001 readiness
Gap, Statement of Applicability, internal audit, and certification support. We do not issue the certificate.
Internal audit support for technology and cyber
Scoped reviews the third line can use. We do not replace the client's internal audit function.
Third-party, vendor, and partner assurance
Vendor, OEM, cloud, and interconnect paths treated as part of the control model, with evidence a Board can be shown.
Incident and breach reporting support
Clocks, facts, and a pack for the organizations's counsel and communications. We do not give market-disclosure advice.
Critical-infrastructure and sector-duty mapping
Energy, public, listed, and transport duties mapped into the same operating system — not a separate compliance project.
05
Outsourced technology and cyber
Clients who do not want to build every function in-house still run a professional estate, with Coldgrid as the named operator.
We run the stack the client already chose. Vendor-independent. Not a helpdesk mill, and not a 24/7 global SOC product we do not operate.

Run
Managed infrastructure and workplace
Operate and harden the environment the client already selected.
Managed security operations
Detection and response on systems already run. Not a default parallel SOC.
Identity operations and privileged-access administration
Issue, purpose-bind, and withdraw access as duties begin and end.
vCIO and vCISO retainers
Named advisory capacity for boards and executives who need a technology principal, not a ticket queue.
Application and platform support
Keep the systems the business already depends on operable and evidenced.
Resilience retainers
Plan upkeep, exercise cadence, and DR test windows after the BIA is signed.
Regulatory and GRC retainers
Obligation register upkeep, evidence cadence, and internal-audit support after the control model is in place.
Specialist bench and surge
Campaigns, cutovers, turnarounds, and peak operating periods.
Selective staff augmentation
The client owns the work. Coldgrid supplies named capacity.
Independent of vendors. We do not issue ISO certificates, we do not substitute for counsel, and we do not claim a global SOC we do not operate.
Contact us