§ 01Industries
Six sectors, each with its own regulator and change window
Eigenvector IT works in financial services, healthcare and life sciences, energy and utilities, government, manufacturing, and legal and professional services. Each sector answers to its own regulator, works to its own change window, and prices an hour of downtime differently. Scope, sequence and evidence are agreed against those constraints before design starts.
§ 02How we scope
The control is the same. The sequencing and the evidence are not
A payment platform runs through every maintenance window. A ward system cannot wait for the next release window. A turbine controller is patched during a scheduled outage, once or twice a year. Scoping starts with the change window, the regulatory date and the recovery target. Those three fix the order of work. The technology follows.
§ 03Six sectors
The six sectors we deliver in
Engagements are staffed against the regime and the change window. Everyone who will do the work is named in the proposal, and the consultants named in the proposal are the consultants who deliver it.
01
Financial Services
Trading, payments and core banking, with the register of information and the test evidence supervisors ask for.
02
Healthcare and Life Sciences
Clinical systems, connected medical devices, and patient data shared across systems, laboratories and suppliers under validation and audit trail requirements.
03
Energy and Utilities
Generation, grid and water operations, where control systems predate the networks attached to them and change waits for an outage.
04
Government and Public Sector
Procurement on fixed criteria, published spend, legacy estates, and assurance documentation written to each agency's own template and evidence standard.
05
Manufacturing and Industrial
Plant networks, time-limited supplier access, and segmentation work scheduled around shift patterns and planned annual shutdowns.
06
Legal and Professional Services
Engagement-level confidentiality, client security questionnaires before instruction, and people working from courts, client sites and travel.
§ 04In detail
What constrains each sector, and what we contract to do about it
Each row states the constraint and then the commitment, in the words the contract uses. No client engagements are described here. Eigenvector IT publishes the obligations it can be held to and the evidence its engagements produce.
Financial Services
Trading, payments and core banking sit under supervision that names its artefacts: the register of information under DORA, the annual assessment under PCI DSS, the IT general controls evidence under Sarbanes-Oxley, the retention and access record under GDPR. Each one carries a date. We build the register and the test evidence alongside the controls, and the contract names the date each artefact is due.
- Register of information due on fixed dates
- Payment platforms changed without taking authorisation offline
- Supervisory notification on deadlines measured in hours
- Cardholder environments assessed annually against platforms that change weekly
Healthcare and Life Sciences
Clinical systems carry patient safety, not just data. We work to the access controls and audit trails HIPAA and HITECH require, keep electronic records to the validation standard set by FDA 21 CFR Part 11, hold connected medical devices and legacy applications inside segmented networks, and maintain the GDPR record where patient data reaches the European Union. Change windows are agreed with clinical operations before design starts, and no change ships outside one.
- Change windows set by clinical operations and measured in minutes
- Connected medical devices with no supported patch path
- Patient data shared across systems, laboratories and suppliers
- Electronic records subject to validation and audit trail requirements
Energy and Utilities
Generation, grid and water operations run on control systems built before the networks now attached to them. We separate operational technology from corporate IT and monitor both, working to NERC CIP asset categorisation, IEC 62443 zone and conduit design, and the notification deadlines each NIS2 transposition sets. Work is scheduled inside the outage season you give us, and monitoring is designed not to touch safety instrumented systems.
- Operational technology and IT converging faster than the controls around them
- Safety instrumented systems that stay online through the work
- Regulated outage windows measured in hours per year
- Field engineers working hundreds of kilometres from the nearest colleague
Government and Public Sector
Public bodies buy on published criteria, publish their spend and answer to auditors. Control selection and tailoring run against NIST SP 800-53, profile work against NIST CSF 2.0, and suppliers to defence programmes are prepared for CMMC Level 2. Assurance documentation is written to your template and your evidence standard, and milestones are set against your fiscal year.
- Procurement with fixed evaluation criteria and published spend
- Legacy estates carrying decades of policy change
- Assurance documentation written to the agency's own template
- Delivery milestones that must survive an annual budget cycle
Manufacturing and Industrial
A stopped line costs a known amount per hour. We inventory plant networks in live production, segment them from the enterprise under IEC 62443 zone and conduit design, and assemble the supplier assurance and notification evidence NIS2 asks for. Every supplier account we issue is scoped, logged and time-limited, and segmentation is staged around your shutdowns.
- Production networks flat, unsegmented and rarely inventoried
- Supplier access spanning several countries and contracts
- Maintenance windows limited to planned shutdowns
- Plant equipment supported long past its vendor's end of life
Legal and Professional Services
Client confidentiality is the product, whether the file is a matter, an audit or a valuation. Client contracts impose their own security regimes, GDPR sets retention and access, and Sarbanes-Oxley sets the evidence audit practices are asked to produce. Engagement-level access boundaries are designed first, and we answer the client questionnaires in your name, on your deadline.
- Client security questionnaires arriving before every engagement
- Privileged and price-sensitive material held across mailboxes and devices
- People working from courts, client sites and travel
- Advisory and audit practices requiring separated access
§ 05Regulatory capability
The regimes we work against
Most institutions are assessed under several frameworks at once, by separate auditors, on separate dates. We collect evidence once and map it across regimes, so a control tested for one assessment is not tested again for the next.
01
DORA
ICT risk recorded in the prescribed register of information. Notification rehearsed against the clock: 4 hours from classification, 24 hours from detection. Impact tolerances set for each important business service. We support your threat-led testing programme; we are not the accredited tester and do not present ourselves as one.
02
NIS2
Scope determination across group entities, supplier assurance programmes, evidence of management accountability, and incident notification prepared to each national deadline.
03
GDPR
Data mapping, retention controls and access recertification, with a breach assessment process that reaches the 72-hour notification decision on evidence your counsel can act on.
04
PCI DSS
Scope reduction first, segmentation testing second, then readiness for the Report on Compliance. The assessment is signed by a Qualified Security Assessor you engage. We do not assess.
05
HIPAA, HITECH and FDA 21 CFR Part 11
Access controls, audit trails, electronic records and validation evidence for clinical and laboratory systems, prepared with clinical operations rather than around them.
06
Sarbanes-Oxley and IT general controls
Change management, logical access and segregation of duties evidence, produced in the format external audit requests and agreed before the walkthrough.
07
NERC CIP
Asset categorisation, electronic security perimeters, and evidence assembled for the audit cycle rather than after it.
08
IEC 62443
Zone and conduit design, asset inventory taken in live plant, and monitoring that respects safety instrumented systems.
09
NIST SP 800-53 and NIST CSF 2.0
Control selection and tailoring, profile work against the framework core, and CMMC Level 2 readiness for defence suppliers.
§ 06Sequencing
The regulator sets the deadline. The clinical lead sets the change window. We tell you which one is driving the schedule
Priyanka Raghunathan
Practice Lead, Cyber Defence
§ 07Next step
Scoping starts with the regulatory date and the change window
Enquiries are scoped by the practice that would deliver the work, Technology Services or Cyber Defence. Write to enquiries@eigenvector.group. Every enquiry is answered by a named person within one working day. Retained clients escalate through the channel agreed in their retainer. Everyone else starts at the same address.