Information Risk Assessment
Identify key information assets, rate impact & probability, and prioritise controls using a clear 5×5 model.
I help small organisations make informed, defensible decisions about information risk, systems architecture, and security controls—using clear language, not jargon. Based in Cheltenham; working across the UK and remotely.
Fixed‑scope mini‑engagements and flexible advisory support. No nonsense, no vendor lock‑in.
Identify key information assets, rate impact & probability, and prioritise controls using a clear 5×5 model.
Lightweight review of network, identity, logging and data flows; practical roadmap aligned to ISO 27001 / CIS v8.
Right‑sized policies (British English), SoA templates, and procedures that people will actually follow.
Simple supplier questionnaires, proportionate due diligence, and clear pass/fail criteria.
Hardening baselines for Microsoft 365, endpoints and cloud services; practical monitoring & logging standards.
Ongoing advice by the hour—budget‑friendly guidance for small teams without a full‑time specialist.
Plain‑English, outcomes‑first. Measured by decisions made and risks reduced.
Within 2–6 weeks, clients often have:
Independent consultant in information security, information risk and systems engineering, based in Cheltenham.
I work with small organisations, start‑ups and public‑sector teams to make sensible, defensible choices about security. I combine hands‑on technical experience (networking, logging, identity) with pragmatic governance (ISO 27001, CIS v8).
Engagements are short, focused and designed to leave you more capable than when we started.
Prefer email? Use the form or write to info@wightmanbrown.ltd.uk.