What We Deliver

Services

Four service lines covering the full spectrum of security risk — from remote desktop assessment through to formally managed on-site inspections.

Service 01

Remote Risk Assessments

Core Service · Remote

Our flagship service. Using documentation and data provided by the client — site plans, operating procedures, existing security controls, incident records — we conduct a rigorous desktop-based security risk assessment without requiring physical access.

This approach is cost-effective, fast to initiate, and delivers the same analytical depth as an on-site review for the majority of industrial and estate security scenarios. All assessments are conducted by experienced security risk professionals and formally signed off before delivery.

Deliverables

  • Formal security risk assessment report
  • Prioritised risk register with likelihood and impact ratings
  • Threat and vulnerability analysis
  • Control effectiveness review
  • Remediation recommendations with implementation guidance
  • Executive summary suitable for board/regulatory audiences

Suitable for

Industrial facilities, manufacturing sites, logistics operations, commercial estates, energy infrastructure, and any facility where desktop documentation enables comprehensive assessment.

Service 02

Compliance & Policy Audits

Core Service · Remote

A structured review of your security policies, procedures, and operational controls against applicable industry standards, regulatory frameworks, and best practice benchmarks. We identify gaps, quantify exposure, and produce a prioritised remediation roadmap.

Audit scope is agreed during intake — we work against your specific regulatory environment whether that's ISO 27001, PCI DSS, sector-specific frameworks, or internal governance standards.

Deliverables

  • Compliance gap analysis report
  • Control mapping against applicable frameworks
  • Prioritised remediation roadmap
  • Policy and procedure recommendations
  • Formal audit findings document with expert sign-off

Suitable for

Organisations preparing for regulatory audit, seeking independent validation of their security posture, or requiring documented evidence of due diligence for insurance, M&A, or governance purposes.

Service 03

Security Planning & Advisory

Core Service · Remote

Expert advisory support for security architecture decisions, investment planning, and risk mitigation strategy. Whether you're commissioning new infrastructure, responding to an incident, or conducting a strategic security review, we provide the independent expert perspective that internal teams and boards need.

All advisory outputs are formal, written documents — not verbal opinion. Every recommendation is traceable to an assessed risk and signed off by our principal.

Deliverables

  • Security architecture review and recommendations
  • Risk-based investment prioritisation analysis
  • Threat environment briefing for leadership audiences
  • Security design review for new facilities or upgrades
  • Formal advisory report with expert sign-off

Suitable for

Executive teams, project managers, and boards requiring independent expert input on security decisions — particularly for capital projects, mergers, or insurance documentation.

Service 04

On-Site Assessments

Add-On · Field Work

When physical site access is required, Gattica commissions and manages experienced field operatives to conduct the on-site assessment on your behalf. The field team works to Gattica's assessment framework and quality standards — all findings are reviewed, validated, and formally signed off by Gattica before delivery.

This model gives you the depth of an on-site physical inspection combined with the analytical rigour and credibility of expert independent sign-off. The cost of field operatives is incorporated into the engagement fee — no separate procurement is required from your side.

Deliverables

  • Physical security assessment report (Gattica-signed)
  • On-site observations and photographic evidence
  • Perimeter and access control assessment
  • Physical vulnerability register
  • Remediation recommendations for physical controls
  • Integration with desktop assessment findings where applicable

Suitable for

Sites where physical access is required to complete the risk picture — high-security facilities, sites with complex physical controls, or engagements where regulators or insurers require on-site evidence. Typically added to a Remote Risk Assessment engagement.

Not sure which service fits?

Describe your situation in the inquiry form. We'll recommend the right scope during our initial review.

Submit an Inquiry