Technology Services and Cyber Defence
We engineer critical infrastructure and defend it through every change
Eigenvector IT engineers and defends the systems that regulated organisations cannot switch off: payments, patient records, grid control. Two practices, Technology Services and Cyber Defence, are bought under one master services agreement, with the service levels written into the schedule. Every enquiry is answered by a named person within one working day.
§ 02The firm
Owned by the people who do the work
Eigenvector IT LLC has taken no outside investment. Both practices sit under one master services agreement, one service level schedule and one accountable lead, so a detection raised by the analysts becomes engineering work under the same contract. Delivery is by our own employees; nothing is subcontracted except hardware forensics beyond our laboratory and external legal counsel during a regulated incident, both named in the proposal and both under our contract. The lead who scopes an engagement attends the reviews and signs the report.
§ 03Practices
Eight service lines across two practices
Every engagement names the service levels it is measured against and the manager who reports on them. Managed services are reported monthly against every agreed service level, missed targets included, and reviewed every quarter. Testing engagements produce one written report, with a retest within 90 days that confirms each fix before the report closes.
Four service lines
We design, migrate and operate the platforms that carry regulated workloads: cloud landing zones, identity, the service desk, and recovery targets proved by a timed failover you attend. The migration date, the rollback point and the run book are fixed in the scope before work starts.
Four service lines
We watch the estate inside contracted coverage hours, mobilise on an incident response retainer when an incident starts, test defences by exploitability rather than scanner severity, and map control evidence to the framework your auditor uses.
§ 04Commitments
Four commitments, written into the contract
15 minutes
Priority one alert acknowledged1
30 minutes
Containment action taken2
90 days
Retest after remediation3
8
Service lines under two practices4
1 An analyst acknowledges and begins triage within 15 minutes of a priority one alert.
2 Actions in the authority matrix agreed at onboarding are taken without waiting for approval.
3 A retest within 90 days confirms each fix and closes the report at no additional charge.
4 Four in Technology Services, four in Cyber Defence, each scoped and reported on its own.
§ 05How we work
The same firm builds it, watches it and signs the report
Built and defended together
The person who builds your identity platform and the analyst who watches it work for the same firm, under one master services agreement and one accountable lead. There is no handover between suppliers, because there is only one supplier. That is what the structure is for.
Evidence, not assertion
Every engagement produces artefacts a third party can check: test results with timestamps, a recovery time recorded during a failover you attended, control evidence mapped to the framework your auditor uses. The commitments are written into the contract, and performance against every one of them is reported monthly, with missed targets shown beside their cause and the corrective action.
Senior people on site
Everyone who will do the work is named in the proposal with the prior roles that qualify them, and the named person is the person who arrives. Named personnel are not substituted without notice and the replacement's résumé. The lead who scoped the engagement attends the reviews and signs the final report.
§ 06Industries
Six sectors where the regulator sets the deadline
01
Financial Services
Trading, payments and core banking run to DORA testing dates, PCI DSS scope and supervisory reporting clocks. We build the register and the test evidence alongside the controls, and the contract names the date each artefact is due.
02
Healthcare and Life Sciences
Clinical systems carry patient safety, not just data. Change windows are agreed with clinical operations before design starts, and connected medical devices stay inside segmented networks.
03
Energy and Utilities
Grid, generation and water run on control systems older than the networks attached to them. We separate operational technology from corporate IT, work inside the outage season you give us, and monitor in a way that does not touch safety instrumented systems.
04
Government and Public Sector
Public bodies buy against fixed evaluation criteria and answer to auditors. Assurance documentation is written to your template and your evidence standard, and milestones are set against your fiscal year.
05
Manufacturing and Industrial
A stopped line costs a known amount per hour. We inventory plant networks, stage segmentation around your shutdowns, and scope, log and time-limit every supplier account we issue.
06
Legal and Professional Services
Client confidentiality is the product. Engagement-level access boundaries are designed first, and we answer the client security questionnaires in your name, on your deadline.
§ 07Credentials
Credentials held by people, not by the firm
Eigenvector IT holds no corporate certification. SOC 2 Type I is in preparation and the examination date is set. Everything below it is a personal credential, held by the named practitioner and verifiable with the body that issued it.
- SOC 2 Type IIn preparation. Not held.Readiness work with an independent CPA firm is underway. The Type I examination is scheduled for 1 December 2026 and the report is expected by 31 January 2027. The Type II observation window opens 1 January 2027 and closes 30 June 2027.
- CISSPNadia Ben Salah, Priyanka RaghunathanPersonal certification, ISC2
- OSCPPriyanka Raghunathan, Rania HaddadPersonal certification, OffSec
- GCFAIfeoma Adeyemi, Aleksandra NowakPersonal certification, GIAC
- CISASofia Marchetti, Katharina VogtPersonal certification, ISACA
- CCSPDiego SotomayorPersonal certification, ISC2
- AWS and AzureHenrik Lindqvist, Tobias Reinhardt, Diego SotomayorAzure Solutions Architect Expert and AWS Solutions Architect – Professional, held individually
§ 08Field notes
The latest field notes
Written by the consultants and analysts doing the work, for the people who have to act on it. Each note states its basis: bench work on our own estate, the published regulatory text, or a named practitioner's experience in a prior role. The Eigenvector Briefing carries new field notes and the regulatory dates worth diarising, on the first Tuesday of each month.
§ 09Next step
Every engagement starts with a scoping conversation
Scoping starts with the estate you already have. The first scoping call carries no fee; a baseline assessment, if one follows, is fixed-fee against a written scope. Write to enquiries@eigenvector.group, and a named person replies within one working day.