CAIRNCYBER ADVISORY

How to engage

Cairn Cyber Advisory Ltd contracts on a business-to-business basis. This page covers the practical questions procurement and hiring managers ask, so you can establish early whether this will work.

Engagement shapes

Discovery

1 to 2 weeks

You need a defensible view of where you stand before committing to a programme.

You receive: Written assessment, prioritised risk picture, and a costed recommendation on what to do next.

Architecture review

2 to 4 weeks

A specific design, platform or third-party system needs independent sign-off.

You receive: Threat model, findings rated by risk, and an approve / approve-with-conditions / reject recommendation.

Embedded advisory

3 to 12 months, part or full time

A programme needs security design authority in the room while decisions are still being made.

You receive: Target-state architecture, design decisions and their rationale, and capability left behind in your team.

Retained advisory

Ongoing, defined days per month

You need senior architectural input available on demand without carrying the headcount.

You receive: Agreed availability for reviews, escalations and design input, with a standing point of contact.

Rates are quoted on application against a defined scope. Fixed-price is available where the scope is tight enough to support it. Otherwise I work on a day rate.

Contracting and IR35

Engagements are contracted business-to-business through Cairn Cyber Advisory Ltd and are intended to operate outside IR35. I work to defined deliverables rather than a role, direct my own working methods, and am not integrated into your organisational structure.

I expect to review the Status Determination Statement before contracts are signed, and I am happy to discuss how the engagement should be structured so the determination reflects how the work will actually be performed. Where a right of substitution is contractually required, it is available.

This describes how I contract. It is not tax advice, and the status determination remains the client's responsibility.

Insurance

Professional indemnity
Arranged per engagement, to £5m
Public liability
Arranged per engagement, to £5m

Cover is placed for each engagement, and the certificate is provided at contracting. Higher limits can be arranged where a framework requires it.

Onboarding

  1. Initial enquiry. Use the contact form with an outline of the problem and timescale.
  2. Call. I will reply with a link to book a 30-minute call if it looks like a fit. No charge, no obligation.
  3. Scope and proposal.Written scope, deliverables, timescale and price.
  4. Contracting. Your paper or mine. NDA first where you would prefer.
  5. Vetting. I hold a clean record and can complete standard financial services screening, including BPSS, credit and criminal record checks and employment referencing.

Supplier due diligence

Onboarding a supplier usually means a security questionnaire, and a security practice that answers one badly is answering the wrong question about itself. Most of what is asked is already published here: the capability statement carries the company, insurance and registration detail in a form you can attach to a procurement record, and the privacy notice states exactly what personal data the practice processes and for how long.

On the technical side: no client data is stored on this website, which has no database, no cookies, no analytics beacon and no third-party runtime scripts. The enquiry form posts to a single function that verifies the submission, relays it by email and persists nothing. Client material is handled under the terms of the engagement contract, on the client's systems wherever the client's policy allows it.

A vulnerability disclosure contact is published at /.well-known/security.txt, which is a fair thing to check before hiring anyone to review your architecture.

Common questions

Do you work outside IR35?
Yes. Engagements are contracted business-to-business, worked to defined deliverables rather than a role, and are intended to operate outside IR35. I review the Status Determination Statement before contracts are signed, and a right of substitution is available where one is contractually required.
Will you work on our paper or yours?
Either. I am happy to work on your standard consultancy terms, and I can provide my own where you would prefer. An NDA can be signed before any detail is discussed.
Can you complete our vetting?
Yes. I hold a clean record and can complete standard financial services screening, including BPSS, credit and criminal record checks, and employment referencing.
Do you work remotely, on site, or both?
Both. The practice is based in Edinburgh and works remotely across the UK, with on-site time where the work genuinely needs it. Workshops, design authority sessions and stakeholder work usually do.
Do you subcontract or use associates?
No. You get the person you engaged. Where a piece of work needs a specialism I do not hold, I will say so and help you find it rather than cover it thinly.
Will you be named as our supplier or reference?
Only with your written permission. No client is named on this website, and case studies are anonymised by sector and scale. The same protection applies to you.

Start an enquiry

An outline of the problem, the constraints and the timescale is enough to establish whether this is a fit. I reply to every enquiry that is a plausible one.