Our capability
Across ten integrated service lines, FortressPoint provides end-to-end security services designed for the complex demands of enterprise organisations in the UK and Nigeria. Each practice is staffed by practitioners with relevant certifications and sector-specific experience.
Most security programmes are built by accumulating tools rather than designing a coherent architecture. We build security strategies aligned to NIST CSF 2.0 and Zero Trust principles from NIST SP 800-207, starting with threat modelling specific to your sector and geography across UK and Nigerian markets.
Passing audits and managing risk are not the same thing. We build GRC frameworks that start with the risks you actually face, not a generic template, covering UK GDPR, NDPA 2023, CBN cybersecurity frameworks, and ISO 27001 from a single engagement.
Most ISO 27001 projects produce documentation that satisfies the auditor but does not reflect how the organisation works. We build the ISMS the other way around, starting with a gap assessment against all 93 Annex A controls and your actual operating environment.
The Nigeria Data Protection Commission can investigate, audit, and fine organisations up to 2% of annual gross revenue. We build NDPA 2023 compliance programmes that align to the GAID 2025 directive, covering data mapping, lawful basis, privacy notices, DPIA, and NDPC registration.
Default Microsoft 365 and Azure configurations leave real attack surface exposed. We design and implement Azure security architecture covering Entra ID hardening, Conditional Access policy design, Privileged Identity Management, Defender for Endpoint, Intune BYOD, and Microsoft Sentinel SIEM.
Most organisations protect data at the network edge and stop there. Once a file moves into email, a cloud app, or a personal device, it is effectively unprotected. We build Microsoft Purview programmes that classify, label, and control data wherever it moves, covering data loss prevention, insider risk management, and security posture management in a single practice.
Running vulnerability scans and managing vulnerabilities are different activities. We design Continuous Threat Exposure Management programmes using Tenable, building risk-based prioritisation models that tell your team which findings to fix first based on exploitability and business impact, not CVSS scores alone.
The EU AI Act entered into force in August 2024 and applies to UK and Nigerian organisations with EU operations or customers. We build AI governance programmes aligned to the EU AI Act risk tiers and NIST AI RMF, starting with an AI inventory and classification of every system in scope.
A full-time CISO costs over £150,000 per year. Most mid-market organisations need board-level security leadership at the right moments, not daily. We provide fractional CISO engagements structured around fixed days per month, covering security committees, board reporting, regulatory liaison, and incident response leadership across UK and Nigerian markets.
Business email compromise, phishing, and social engineering succeed because people make decisions without the information they need. We design security awareness programmes around your actual threat profile, using phishing simulations with sector-relevant templates and role-based training targeted at the functions that carry the most risk.
Our process
Initial risk assessment, stakeholder workshops, and threat analysis to establish your current security posture.
Security architecture design, control selection, and a prioritised implementation roadmap tailored to your risk profile.
Technical deployment, policy creation, team enablement, and change management, delivered to timeline and budget.
Continuous testing, metrics review, lessons-learned cycles, and programme optimisation to maintain security effectiveness.
Book a free 30-minute assessment. We will identify the right starting point for your organisation.