Skip to content

Cybersecurity capabilities

Cybersecurity capability areas for government and public-sector delivery.

Our practice is organized into six capability areas covering security strategy and architecture, cloud and Microsoft security, security operations, identity, cyber risk and professional services.

01 / 06

Cybersecurity strategy and architecture

  • Cybersecurity roadmaps
  • Security architecture
  • Zero Trust strategy
  • Security program development
The cybersecurity challenge
Security investments are often made tool by tool, which leaves organizations with overlapping controls and no shared view of the target state.
What Frank Dolphins provides
We set the security direction and the architecture behind it, from a costed cybersecurity roadmap through Zero Trust strategy and the structure of the security program itself.
The security outcome
A defensible target architecture and sequenced roadmap that security, IT and executive stakeholders can plan and budget against.
02 / 06

Cloud and Microsoft security

  • Microsoft security technologies
  • Cloud security architecture
  • Microsoft Defender
  • Microsoft Sentinel
  • Azure and Microsoft 365 security
The cybersecurity challenge
Cloud and Microsoft 365 estates grow quickly, and configuration decisions made early are difficult and expensive to unwind later.
What Frank Dolphins provides
We design and harden cloud security architecture across Azure and Microsoft 365, and engineer the Microsoft security stack, including Microsoft Defender and Microsoft Sentinel, to fit the environment it protects.
The security outcome
A cloud estate with security controls that hold their intended boundaries as the environment scales.
03 / 06

Security operations and threat detection

  • SIEM engineering
  • Security monitoring
  • Detection engineering
  • Incident response
  • Security automation
The cybersecurity challenge
Monitoring platforms produce volume, but teams still lack the specific detections, context and playbooks an incident actually demands.
What Frank Dolphins provides
We engineer the SIEM and its data pipelines, build and tune detections, automate repetitive response steps and prepare the incident response procedures that surround them.
The security outcome
Operations teams that see what matters, respond on an agreed sequence and spend less time on manual triage.
04 / 06

Identity and access security

  • Identity architecture
  • Privileged access
  • Conditional Access
  • Identity governance
  • Zero Trust access controls
The cybersecurity challenge
Identity has become the primary control plane, yet privileged access and access reviews are frequently the least governed part of the estate.
What Frank Dolphins provides
We design identity architecture, tighten privileged access, build Conditional Access and identity governance, and align access controls to Zero Trust principles.
The security outcome
Access that is granted deliberately, reviewed on a cycle and revoked when it is no longer warranted.
05 / 06

Cyber risk, compliance and assurance

  • Security assessments
  • Governance and risk management
  • Control implementation
  • Vulnerability management
  • Compliance readiness
The cybersecurity challenge
Teams are held to security policy expectations without a clear, evidenced picture of where their controls currently stand.
What Frank Dolphins provides
We run security assessments, implement and document controls, structure governance and risk management, build vulnerability management into a repeatable cycle and prepare organizations for compliance review.
The security outcome
A defensible view of current risk and a prioritized remediation plan that holds up under audit and executive scrutiny.
06 / 06

Cybersecurity professional services

  • Experienced cybersecurity professionals
  • Technical project delivery
  • Advisory and engineering support
  • Subcontracting and teaming support
The cybersecurity challenge
Requirements arrive with firm dates while the specialized cybersecurity capacity to meet them is not available internally.
What Frank Dolphins provides
We provide experienced cybersecurity professionals for technical project delivery, advisory and engineering support, and we support prime contractors through subcontracting and teaming arrangements.
The security outcome
Continuity of delivery through peak periods, without a permanent headcount commitment.

Guidance we work with

Security frameworks and guidance behind the work

These are the references our assessments, architecture and detection work are structured against. They describe familiarity and working practice, not certification or approval.

  • CCCS / Government of Canada

    ITSG-33

    Control profile selection and security assessment baseline

  • Treasury Board

    Policy on Government Security

    Departmental security obligations and accountability

  • NIST

    NIST SP 800-53 Rev. 5

    Control catalogue mapping

  • NIST

    NIST Cybersecurity Framework 2.0

    Security program maturity narrative

  • NIST

    NIST SP 800-207

    Zero Trust architecture reference

  • NIST

    NIST AI Risk Management Framework

    AI security and governance mapping

  • ISO

    ISO/IEC 27001:2022

    Management system readiness

  • CIS

    CIS Critical Security Controls v8

    Prioritized hardening

  • MITRE

    MITRE ATT&CK

    Detection coverage and threat modelling

Engagement models

Ways we take on the work

Subcontracting

Defined cybersecurity scopes of work under a prime, with deliverables, reporting and escalation agreed before work begins.

Teaming arrangements

Joint responses where our security capabilities complement a partner's coverage for a specific requirement.

Professional services

Direct engagements for security assessment, architecture, engineering and advisory work against a defined statement of work.

Embedded capacity

Experienced cybersecurity professionals working inside an existing team through a project burst or an interim gap.

Discuss a Requirement

Engage

Strengthen your next cybersecurity initiative.

Connect with Frank Dolphins regarding cybersecurity requirements, subcontracting, teaming arrangements and professional-services opportunities.