Technology Services and Cyber Defence

We engineer critical infrastructure and defend it through every change

Eigenvector IT engineers and defends the systems that regulated organisations cannot switch off: payments, patient records, grid control. Two practices, Technology Services and Cyber Defence, are bought under one master services agreement, with the service levels written into the schedule. Every enquiry is answered by a named person within one working day.

Retained clients escalate through the channel agreed in their retainer. Everyone else starts at enquiries@eigenvector.group.

A linear transformation and its invariant line A square lattice is sheared by the matrix A = [1.6 0.6 ; 0.4 1.4]. Two lines through the origin keep their direction: the line along (3, 2), which is stretched by a factor of 2, and the line along (1, -1), which is left exactly where it is because its eigenvalue is 1. λ₁ = 2 λ₂ = 1 — fixed A = [1.6 0.6 ; 0.4 1.4]
A = [1.6 0.6 ; 0.4 1.4]. λ₁ = 2, λ₂ = 1. Every vector on the line spanned by (1, −1) is unchanged by A: A(2, −2) = (2, −2).

§ 02The firm

Owned by the people who do the work

Eigenvector IT LLC has taken no outside investment. Both practices sit under one master services agreement, one service level schedule and one accountable lead, so a detection raised by the analysts becomes engineering work under the same contract. Delivery is by our own employees; nothing is subcontracted except hardware forensics beyond our laboratory and external legal counsel during a regulated incident, both named in the proposal and both under our contract. The lead who scopes an engagement attends the reviews and signs the report.

About the firm

§ 03Practices

Eight service lines across two practices

Every engagement names the service levels it is measured against and the manager who reports on them. Managed services are reported monthly against every agreed service level, missed targets included, and reviewed every quarter. Testing engagements produce one written report, with a retest within 90 days that confirms each fix before the report closes.

Technology Services

Four service lines

We design, migrate and operate the platforms that carry regulated workloads: cloud landing zones, identity, the service desk, and recovery targets proved by a timed failover you attend. The migration date, the rollback point and the run book are fixed in the scope before work starts.

Cyber Defence

Four service lines

We watch the estate inside contracted coverage hours, mobilise on an incident response retainer when an incident starts, test defences by exploitability rather than scanner severity, and map control evidence to the framework your auditor uses.

See all services

§ 04Commitments

Four commitments, written into the contract

15 minutes

Priority one alert acknowledged1

30 minutes

Containment action taken2

90 days

Retest after remediation3

8

Service lines under two practices4

1 An analyst acknowledges and begins triage within 15 minutes of a priority one alert.

2 Actions in the authority matrix agreed at onboarding are taken without waiting for approval.

3 A retest within 90 days confirms each fix and closes the report at no additional charge.

4 Four in Technology Services, four in Cyber Defence, each scoped and reported on its own.

§ 05How we work

The same firm builds it, watches it and signs the report

Built and defended together

The person who builds your identity platform and the analyst who watches it work for the same firm, under one master services agreement and one accountable lead. There is no handover between suppliers, because there is only one supplier. That is what the structure is for.

Evidence, not assertion

Every engagement produces artefacts a third party can check: test results with timestamps, a recovery time recorded during a failover you attended, control evidence mapped to the framework your auditor uses. The commitments are written into the contract, and performance against every one of them is reported monthly, with missed targets shown beside their cause and the corrective action.

Senior people on site

Everyone who will do the work is named in the proposal with the prior roles that qualify them, and the named person is the person who arrives. Named personnel are not substituted without notice and the replacement's résumé. The lead who scoped the engagement attends the reviews and signs the final report.

How we deliver

§ 06Industries

Six sectors where the regulator sets the deadline

01

Financial Services

Trading, payments and core banking run to DORA testing dates, PCI DSS scope and supervisory reporting clocks. We build the register and the test evidence alongside the controls, and the contract names the date each artefact is due.

Sector detail

02

Healthcare and Life Sciences

Clinical systems carry patient safety, not just data. Change windows are agreed with clinical operations before design starts, and connected medical devices stay inside segmented networks.

Sector detail

03

Energy and Utilities

Grid, generation and water run on control systems older than the networks attached to them. We separate operational technology from corporate IT, work inside the outage season you give us, and monitor in a way that does not touch safety instrumented systems.

Sector detail

04

Government and Public Sector

Public bodies buy against fixed evaluation criteria and answer to auditors. Assurance documentation is written to your template and your evidence standard, and milestones are set against your fiscal year.

Sector detail

05

Manufacturing and Industrial

A stopped line costs a known amount per hour. We inventory plant networks, stage segmentation around your shutdowns, and scope, log and time-limit every supplier account we issue.

Sector detail

06

Legal and Professional Services

Client confidentiality is the product. Engagement-level access boundaries are designed first, and we answer the client security questionnaires in your name, on your deadline.

Sector detail

See all industries

§ 07Credentials

Credentials held by people, not by the firm

Eigenvector IT holds no corporate certification. SOC 2 Type I is in preparation and the examination date is set. Everything below it is a personal credential, held by the named practitioner and verifiable with the body that issued it.

  • SOC 2 Type IIn preparation. Not held.Readiness work with an independent CPA firm is underway. The Type I examination is scheduled for 1 December 2026 and the report is expected by 31 January 2027. The Type II observation window opens 1 January 2027 and closes 30 June 2027.
  • CISSPNadia Ben Salah, Priyanka RaghunathanPersonal certification, ISC2
  • OSCPPriyanka Raghunathan, Rania HaddadPersonal certification, OffSec
  • GCFAIfeoma Adeyemi, Aleksandra NowakPersonal certification, GIAC
  • CISASofia Marchetti, Katharina VogtPersonal certification, ISACA
  • CCSPDiego SotomayorPersonal certification, ISC2
  • AWS and AzureHenrik Lindqvist, Tobias Reinhardt, Diego SotomayorAzure Solutions Architect Expert and AWS Solutions Architect – Professional, held individually

The SOC 2 timetable

§ 08Field notes

The latest field notes

Written by the consultants and analysts doing the work, for the people who have to act on it. Each note states its basis: bench work on our own estate, the published regulatory text, or a named practitioner's experience in a prior role. The Eigenvector Briefing carries new field notes and the regulatory dates worth diarising, on the first Tuesday of each month.

18 August 2026 · Governance, Risk and Compliance · Sofia Marchetti

Two register cycles under DORA: the questions supervisors put in writing

Registers of information have now been through two cycles, and the supervisory follow-ups cluster in four areas. Read from the published regulatory text and the questions put in writing, with the evidence that answers each point.

12 August 2026 · Managed Detection and Response · Aleksandra Nowak

Purple team on our own estate: what our detection missed

We ran the attack techniques against our own systems and our own rules. The techniques that raised nothing, the rules we rewrote afterwards, and the way we now test coverage before a client sees it.

All field notes

§ 09Next step

Every engagement starts with a scoping conversation

Scoping starts with the estate you already have. The first scoping call carries no fee; a baseline assessment, if one follows, is fixed-fee against a written scope. Write to enquiries@eigenvector.group, and a named person replies within one working day.