independent  ·  tool-neutral  ·  implementer-agnostic

Independent governance for the full lifecycle of a cybersecurity programme.

01  —  practice

Three phases. One discipline.

Every cybersecurity programme moves through three phases. Each one fails for different reasons. Each one needs a different intervention.

i

Readiness

before the implementer arrives

Translate regulatory exposure into a defensible target operating model. Scope what is and isn't in the programme. Qualify implementers. Validate the procurement package before it leaves the building.

deliverables target operating model procurement package review implementer qualification governance charter

ii

Decision facilitation

while the implementer works

Sit between the buyer and the implementer. Frame decisions cleanly. Cost alternatives honestly. Produce steering minutes that read, twelve months later, like a defensible record.

deliverables steering & assurance secretariat decision papers architecture-decision review independent risk acceptance log

iii

Stabilisation

after go-live

Rehearse the operating cadence with the team. Close out residual risk. Produce the document the firm will hand to its auditor twelve months later, and stand behind every line of it.

deliverables operating cadence rehearsal residual risk closure control-evidence binder twelve-month audit pack

02  —  posture

We sit on the third line. Structurally.

i Management controls The operators of the programme. The first hands on the work.
ii Risk & compliance The internal oversight that frames policy and tests adherence.
iii Independent assurance A structurally separate seat. Cannot mark its own homework. This is ours.

The Three Lines of Defence model exists because no one organisation can plausibly mark its own homework.

Thirdline takes the third line seriously. We have no delivery business, no vendor ecosystem, and no implementation partnerships to defend. That posture is the entire product.

what we are

  • An independent advisory practice
  • A buyer-side governance function
  • A defensible record of decisions
  • A steady hand across the lifecycle

what we are not

  • A delivery firm or system integrator
  • A reseller or vendor partner
  • A consulting franchise
  • A managed-service provider

03  —  coverage

Any domain. Any implementer.

The governance work is the same shape across domains. The technical detail is different. We have practitioners in each.

04  —  regulatory

Built for the regulation our buyers actually answer to.

Most cybersecurity programmes do not fail in the build. They fail when an auditor asks for the paper trail twenty-four months later. Our work is the paper trail.

eu  ·  in force

NIS2

Network & Information Security Directive

eu  ·  in force

DORA

Digital Operational Resilience Act

iso  ·  2022 revision

ISO 27001

Information Security Management Systems

aicpa  ·  type i & ii

SOC 2

Service Organization Control

05  —  perspectives

Recent writing from the practice.

Short, considered pieces on programme governance. No vendor opinions. No ‘thought leadership’. Sometimes the most useful piece is the one that argues against the prevailing direction.