§ 01Industries

Six sectors, each with its own regulator and change window

Eigenvector IT works in financial services, healthcare and life sciences, energy and utilities, government, manufacturing, and legal and professional services. Each sector answers to its own regulator, works to its own change window, and prices an hour of downtime differently. Scope, sequence and evidence are agreed against those constraints before design starts.

See the service lines

§ 02How we scope

The control is the same. The sequencing and the evidence are not

A payment platform runs through every maintenance window. A ward system cannot wait for the next release window. A turbine controller is patched during a scheduled outage, once or twice a year. Scoping starts with the change window, the regulatory date and the recovery target. Those three fix the order of work. The technology follows.

§ 03Six sectors

The six sectors we deliver in

Engagements are staffed against the regime and the change window. Everyone who will do the work is named in the proposal, and the consultants named in the proposal are the consultants who deliver it.

§ 04In detail

What constrains each sector, and what we contract to do about it

Each row states the constraint and then the commitment, in the words the contract uses. No client engagements are described here. Eigenvector IT publishes the obligations it can be held to and the evidence its engagements produce.

Financial Services

Trading, payments and core banking sit under supervision that names its artefacts: the register of information under DORA, the annual assessment under PCI DSS, the IT general controls evidence under Sarbanes-Oxley, the retention and access record under GDPR. Each one carries a date. We build the register and the test evidence alongside the controls, and the contract names the date each artefact is due.

  • Register of information due on fixed dates
  • Payment platforms changed without taking authorisation offline
  • Supervisory notification on deadlines measured in hours
  • Cardholder environments assessed annually against platforms that change weekly

Healthcare and Life Sciences

Clinical systems carry patient safety, not just data. We work to the access controls and audit trails HIPAA and HITECH require, keep electronic records to the validation standard set by FDA 21 CFR Part 11, hold connected medical devices and legacy applications inside segmented networks, and maintain the GDPR record where patient data reaches the European Union. Change windows are agreed with clinical operations before design starts, and no change ships outside one.

  • Change windows set by clinical operations and measured in minutes
  • Connected medical devices with no supported patch path
  • Patient data shared across systems, laboratories and suppliers
  • Electronic records subject to validation and audit trail requirements

Energy and Utilities

Generation, grid and water operations run on control systems built before the networks now attached to them. We separate operational technology from corporate IT and monitor both, working to NERC CIP asset categorisation, IEC 62443 zone and conduit design, and the notification deadlines each NIS2 transposition sets. Work is scheduled inside the outage season you give us, and monitoring is designed not to touch safety instrumented systems.

  • Operational technology and IT converging faster than the controls around them
  • Safety instrumented systems that stay online through the work
  • Regulated outage windows measured in hours per year
  • Field engineers working hundreds of kilometres from the nearest colleague

Government and Public Sector

Public bodies buy on published criteria, publish their spend and answer to auditors. Control selection and tailoring run against NIST SP 800-53, profile work against NIST CSF 2.0, and suppliers to defence programmes are prepared for CMMC Level 2. Assurance documentation is written to your template and your evidence standard, and milestones are set against your fiscal year.

  • Procurement with fixed evaluation criteria and published spend
  • Legacy estates carrying decades of policy change
  • Assurance documentation written to the agency's own template
  • Delivery milestones that must survive an annual budget cycle

Manufacturing and Industrial

A stopped line costs a known amount per hour. We inventory plant networks in live production, segment them from the enterprise under IEC 62443 zone and conduit design, and assemble the supplier assurance and notification evidence NIS2 asks for. Every supplier account we issue is scoped, logged and time-limited, and segmentation is staged around your shutdowns.

  • Production networks flat, unsegmented and rarely inventoried
  • Supplier access spanning several countries and contracts
  • Maintenance windows limited to planned shutdowns
  • Plant equipment supported long past its vendor's end of life

Client confidentiality is the product, whether the file is a matter, an audit or a valuation. Client contracts impose their own security regimes, GDPR sets retention and access, and Sarbanes-Oxley sets the evidence audit practices are asked to produce. Engagement-level access boundaries are designed first, and we answer the client questionnaires in your name, on your deadline.

  • Client security questionnaires arriving before every engagement
  • Privileged and price-sensitive material held across mailboxes and devices
  • People working from courts, client sites and travel
  • Advisory and audit practices requiring separated access

What we believe

§ 05Regulatory capability

The regimes we work against

Most institutions are assessed under several frameworks at once, by separate auditors, on separate dates. We collect evidence once and map it across regimes, so a control tested for one assessment is not tested again for the next.

01

DORA

ICT risk recorded in the prescribed register of information. Notification rehearsed against the clock: 4 hours from classification, 24 hours from detection. Impact tolerances set for each important business service. We support your threat-led testing programme; we are not the accredited tester and do not present ourselves as one.

02

NIS2

Scope determination across group entities, supplier assurance programmes, evidence of management accountability, and incident notification prepared to each national deadline.

03

GDPR

Data mapping, retention controls and access recertification, with a breach assessment process that reaches the 72-hour notification decision on evidence your counsel can act on.

04

PCI DSS

Scope reduction first, segmentation testing second, then readiness for the Report on Compliance. The assessment is signed by a Qualified Security Assessor you engage. We do not assess.

05

HIPAA, HITECH and FDA 21 CFR Part 11

Access controls, audit trails, electronic records and validation evidence for clinical and laboratory systems, prepared with clinical operations rather than around them.

06

Sarbanes-Oxley and IT general controls

Change management, logical access and segregation of duties evidence, produced in the format external audit requests and agreed before the walkthrough.

07

NERC CIP

Asset categorisation, electronic security perimeters, and evidence assembled for the audit cycle rather than after it.

08

IEC 62443

Zone and conduit design, asset inventory taken in live plant, and monitoring that respects safety instrumented systems.

09

NIST SP 800-53 and NIST CSF 2.0

Control selection and tailoring, profile work against the framework core, and CMMC Level 2 readiness for defence suppliers.

See governance, risk and compliance

§ 06Sequencing

The regulator sets the deadline. The clinical lead sets the change window. We tell you which one is driving the schedule

Priyanka Raghunathan

Practice Lead, Cyber Defence

§ 07Next step

Scoping starts with the regulatory date and the change window

Enquiries are scoped by the practice that would deliver the work, Technology Services or Cyber Defence. Write to enquiries@eigenvector.group. Every enquiry is answered by a named person within one working day. Retained clients escalate through the channel agreed in their retainer. Everyone else starts at the same address.