Skip to content

What we do

Capabilities across the technology estate

Coldgrid is a technology and cybersecurity firm. Strategy, delivery, resilience, regulatory support, and outsourced operations sit under one operating model the client owns.

01

Strategy and architecture

Boards and executives get a technology and cyber strategy they can fund, sequence, and own.

We set the direction of the estate before tools are chosen. Architecture, operating model, and investment cases sit in one argument the Board can repeat.

An empty executive boardroom with a long table and tall windows

Direction

  • Technology strategy and operating-model design

    How the estate is owned, funded, and run — not a slide of initiatives.

  • Cyber strategy and security operating model

    Diagnose, design, deliver. Residual risk labelled, owned, and dated.

  • Enterprise, cloud, and integration architecture

    One picture of systems, identity, and the paths that join them.

  • Digital and data strategy

    Analytics and platforms as a business asset, with classification from the start.

  • AI strategy with security and privacy constraints

    Where models and copilots may sit, and where they must not.

  • Board, audit-committee, and CISO/CIO advisory

    Judgement for listed groups and public organizations, not a vendor briefing.

  • Transformation roadmaps and investment cases

    Sequence, cost, and what stops if a year of funding is cut.

02

Technology and cyber delivery

The estate is built and secured as one system, not a stack of tools.

Identity, applications, data, networks, and operational technology are installed so the client owns the controls. Cyber is not a side shop.

An industrial operations gallery with process consoles behind glass

Technology

  • Cloud, infrastructure, and network engineering

    On the platforms the client already runs, without a single-vendor mandate.

  • Identity and privileged access

    Just-in-time, purpose-bound access. Identity attack-path discovery included.

  • Application platforms, APIs, and software supply chain

    Build and change paths that can be evidenced, not gated the night before release.

  • Data platforms, analytics, and data security

    Classification, encryption, and logged export treated as privileged actions.

  • Operational technology and the IT–OT boundary

    Plant, terminal, field device, and telemetry — not another IT VLAN.

  • Collaboration, workplace, and enterprise applications

    The estate people actually use, hardened to the same operating system.

Cyber

  • AI security

    Copilots and agents purpose-bound. No standing privilege on operational or market-sensitive data.

  • Security operations

    Detection and response on systems already run, including surge coverage. Not a parallel SOC by default.

  • Security testing

    Vulnerability scanning and authorised penetration testing. No unattended testing against production.

  • Application security

    Shift-left in the development workflow, so portals and APIs are evidenced as they are built.

03

Resilience: BIA, BCP, and disaster recovery

Process owners name recovery times. Technology is designed to those times. Residual risk sits on the Board record.

Business impact analysis first. Continuity plans from signed RTOs. IT and OT disaster recovery rewritten to the BIA — not the reverse. Cyber incident response is an annex, not a substitute for continuity.

A large industrial plant and tank terminal in pale morning light, with twin stacks and dual feeders

Resilience

  • Business impact analysis

    Signed RTO, RPO, MTPD, and MBCO, with a named owner for each critical process.

  • Business continuity plans

    One template. Band 0–1 processes first. Plans operations can run at 2 a.m.

  • Crisis and incident management

    A plan the executive can activate, with depth behind the named seats.

  • IT disaster recovery designed to BIA targets

    Restore windows follow the business clock. Residual risk is written down if they cannot.

  • OT, field, and plant recovery annexes

    Lanes, plants, terminals, and transmission paths as recovery objects — not an IT afterthought.

  • Vendor and concentration-risk continuity

    Cloud, OEM, CSC, and interconnect paths treated as part of recovery, not as documentation tails.

  • Exercises, after-action, and residual-risk reporting

    A functional exercise with a written after-action. Residual risk on the Board record.

  • Cyber IR as annex

    Incident response cross-walked to the incident-management plan so ransomware does not create dual command.

04

Regulatory support

Overlapping duties become one control model and one evidence pack the Board, audit committee, and regulators can be shown.

We map duties, harmonize controls, and produce evidence the Board can stand on — without substituting for counsel, and without issuing certificates we do not award.

A quiet audit-committee room with stacked reports, a bronze lamp, and empty chairs

Map and harmonize

  • Multi-regime gap assessment

    One review across the duties that actually apply — privacy, critical-infrastructure, listing, and sector rules — so the organizations builds once and answers many.

  • Control and policy harmonisation

    A single control framework and policy hierarchy, not a parallel file for each regulator.

  • Regulatory change and horizon scanning

    What is coming, what it changes in the estate, and what can wait. Dated residual risk where it cannot yet be met.

Evidence and programs

  • Board and audit-committee evidence

    Reporting the executive can stand on: ownership, residual risk, and what was tested. Not a technical dump.

  • Privacy programme

    NDPA 2023 / GAID, and UK GDPR where listing or establishment applies. ROPA, DPIA support, rights processes, and breach clocks. Not a substitute for counsel.

  • ISO 27001 readiness

    Gap, Statement of Applicability, internal audit, and certification support. We do not issue the certificate.

  • Internal audit support for technology and cyber

    Scoped reviews the third line can use. We do not replace the client's internal audit function.

  • Third-party, vendor, and partner assurance

    Vendor, OEM, cloud, and interconnect paths treated as part of the control model, with evidence a Board can be shown.

  • Incident and breach reporting support

    Clocks, facts, and a pack for the organizations's counsel and communications. We do not give market-disclosure advice.

  • Critical-infrastructure and sector-duty mapping

    Energy, public, listed, and transport duties mapped into the same operating system — not a separate compliance project.

05

Outsourced technology and cyber

Clients who do not want to build every function in-house still run a professional estate, with Coldgrid as the named operator.

We run the stack the client already chose. Vendor-independent. Not a helpdesk mill, and not a 24/7 global SOC product we do not operate.

A quiet professional operations floor with long desks and tall windows

Run

  • Managed infrastructure and workplace

    Operate and harden the environment the client already selected.

  • Managed security operations

    Detection and response on systems already run. Not a default parallel SOC.

  • Identity operations and privileged-access administration

    Issue, purpose-bind, and withdraw access as duties begin and end.

  • vCIO and vCISO retainers

    Named advisory capacity for boards and executives who need a technology principal, not a ticket queue.

  • Application and platform support

    Keep the systems the business already depends on operable and evidenced.

  • Resilience retainers

    Plan upkeep, exercise cadence, and DR test windows after the BIA is signed.

  • Regulatory and GRC retainers

    Obligation register upkeep, evidence cadence, and internal-audit support after the control model is in place.

  • Specialist bench and surge

    Campaigns, cutovers, turnarounds, and peak operating periods.

  • Selective staff augmentation

    The client owns the work. Coldgrid supplies named capacity.

Independent of vendors. We do not issue ISO certificates, we do not substitute for counsel, and we do not claim a global SOC we do not operate.

Contact us