Abstract network of secured nodes protecting a central shield

DEFENCE · NUCLEAR · GOVERNMENT

Security architecture for systems that cannot fail.

We embed as your senior security and enterprise architecture authority — governing design, evidencing compliance and keeping high-classification programmes inside their Authority to Operate.

30+
Years in architecture
12
Architects led
OFFICIAL–SECRET
Environments assured
Multi-cloud
Azure · AWS · GCP

Capabilities

End-to-end assurance, from principle to production evidence

Secure-by-Design & Assurance

JSP 440 / JSP 453 aligned Secure-by-Design processes, self-assessment trackers, risk treatment plans and continuous Authority to Operate evidence packs.

Governance & Compliance

NCSC CAF / GovAssure, GovS 007 & GovS 005, ISO 27001, Cyber Essentials Plus, CIS 18 and NIST SP 800-53/37/30 assessment and audit readiness.

Enterprise Security Architecture

Architecture governance frameworks, security principles, TRMs and ArchiMate modelling aligned to CSOC, NATO STANAGs, NCMS data standards and TOGAF.

SIEM & Detection Engineering

Microsoft Sentinel and Defender XDR strategy and delivery, MITRE ATT&CK aligned use cases, AWS/GCP connectors and SOC service onboarding.

Identity, PAM & Data Protection

Entra ID, Okta, Zscaler, CyberArk SaaS PAM, conditional access and MFA design, data classification, DLP and data access governance (PAM/IAM/CIEM).

Zero Trust & Cloud Migration

NIST SP 800-207 data-centric Zero Trust, Azure/GCP/AWS landing zones, segmentation, crypto and HSM key management to FIPS 140-3 Level 3.

Frameworks & standards

We speak the language of your regulator

Every artefact we produce — HLDs, threat models, risk treatment plans, ITHC scopes and CAF reports — is written to survive design authority boards, accreditor scrutiny and audit.

  • NCSC CAF / GovAssure
  • JSP 440
  • JSP 453
  • NIST SP 800-207
  • NIST SP 800-218 SSDF
  • NIST SP 800-53
  • ISO 27001
  • Cyber Essentials Plus
  • CIS 18
  • GovS 007 / GovS 005
  • NATO STANAG / NATv4
  • MITRE ATT&CK
  • STRIDE / DREAD
  • TOGAF & ArchiMate

Selected engagements

Track record on national-scale programmes

2026

R&D ADDI Programme

Senior Enterprise Architect — Governance & Assurance

  • Aligned the NEXOR capability with the CSOC architecture framework and the Common Approach to Architecture.
  • Built the architecture governance framework, security principles and TRM mapped to NATv4 STANAGs and NCMS data standards.
  • Produced NIST SP 800-218 SSDF artefacts for SOA development and Zero Trust patterns for a data-centric solution.
  • Supported SIRA, SROs and security architects to sustain Authority to Test through the SDLC.

Jun 2025 – Dec 2025

Leonardo UK Helicopters

Enterprise Security Architect — Obsolescence Exit & SIEM Strategy

  • Owned security governance and assurance for data centre transformation and the new Microsoft Sentinel / Defender EDR capability.
  • Delivered the SIEM digital strategy, HLDs, threat models (STRIDE) and secure-by-design patterns for Azure and GCP.
  • Ran ITAR risk assessments, DLP policy creation and CyberArk Endpoint Privilege Manager rollout into the SOC service.
  • Chaired Technical and Security Design Authorities, assuring supplier designs and Cyber Essentials Plus audit compliance.

Apr 2023 – Jun 2025

Atomic Weapons Establishment

Lead Architect, Security Focus — Capital Programme

  • Led a 12-strong architecture practice across security, solutions, service, data and integration.
  • Designed the Tier 2 Azure 'Capital Platform' for supply chain hosting, including AVD, M365 collaboration and platform-wide DLP.
  • Delivered Sentinel across multi-cloud with AWS and GCP connectors, Defender Vulnerability Management and Defender CSPM.
  • Assured ONR regulatory alignment, Secure-by-Design, ISO 27001 and NIST 800 series controls end to end.

May 2021 – Apr 2023

Ministry of Defence — Defence Digital

Lead Solutions Architect — Battlespace & Hosting

  • Provided enterprise governance and assurance across RAF, Army and Navy domains and their industry suppliers.
  • Led identity transformation (NetIQ vaults, SSO, conditional access) under Zero Trust policy and governance.
  • Authored the Common Approach to Architecture and security principles for cloud cryptography and DPKI.
  • Assured hosting designs across MOD Cloud, Azure Stack Hub, AWS, VMware and hyperscale platforms.

Apr 2019 – Apr 2021

FCDO Services — UKVI & Cross-Government

Senior Design Architect — Data Centre & Application Migration

  • Technical authority for government private cloud hosting across FCDO, Home Office, UKVI, HMPO and MOJ accounts.
  • Delivered cloud-first migration strategy, run books and transition into production at scale.
  • Hardened designs to NCSC guidance and integrated SOC/SIEM (LogRhythm) monitoring.

Contact

Bring in a design authority before the audit does

Short-notice architecture reviews, secure-by-design assessments and interim security architecture leadership across the UK.