MENTARA
Software Services

Security work that changes what happens, not just what is recorded.

Most security programmes are not under-resourced — they are disconnected from business consequence. MENTARA connects risk, architecture, controls and response.

The decision in front of you

Security spending has rarely been higher and security confidence has rarely been lower. The common cause is not a missing tool. It is that control activity has become detached from the business services it exists to protect, so nobody can answer the only question that matters: if this went wrong tomorrow, what would actually stop working, and for how long?

That disconnection produces a recognisable pattern — a control catalogue that grows every year, an alert volume nobody has the capacity to action, a policy set that is technically current and operationally ignored, and a risk register that records concerns rather than resolving them.

The failure mode

Coverage is not the same as protection.

Most security programmes are measured on coverage — percentage of endpoints enrolled, percentage of findings closed, number of controls mapped to a framework. These are easy to report and weakly correlated with whether an attack would succeed, because they measure the presence of a control rather than its effect under adversarial conditions.

The gap shows up in three predictable places. Identity, where joiner-mover-leaver processes drift and privileged access accumulates quietly because revoking it is disruptive and nobody owns the disruption. Cloud and application change, where delivery moves weekly and control review moves quarterly, so the control set describes a system that no longer exists. And detection, where tuning is deferred because the team is consumed by the volume the untuned system produces — a loop that gets worse on its own.

None of this is solved by more findings. It is solved by deciding which business services genuinely matter, working backwards to the identities, data paths and dependencies that would compromise them, and then being willing to leave lower-consequence findings open on purpose and say so out loud. Most organisations know this. What stops them is that nobody has the authority to decide what will not be fixed.

Capability

What MENTARA does.

Scoped to the priority rather than sold as a bundle. Most engagements use two or three of these, not all six.

01Security strategy and architectureA risk-informed roadmap anchored to critical business services rather than to a framework's clause list, with a target architecture and control design that states explicitly what is being accepted, not only what is being addressed.
02Identity and accessIdentity governance, privileged access and joiner-mover-leaver lifecycle. Usually the highest-yield work in an enterprise estate, and usually the least popular, because it removes access people have grown used to having.
03Cloud and application securitySecurity patterns embedded into platforms and delivery pipelines so controls move at the speed of change — guardrails that fail builds rather than review meetings that generate findings after release.
04Data protectionClassification that reflects actual sensitivity, and controls over access, movement, retention and use. Scoped to where regulated or genuinely sensitive data lives rather than applied uniformly across everything.
05Security operations improvementDetection tuning, triage design, response runbooks, vulnerability prioritisation and recovery exercises — improving the decisions an operations team makes, not replacing the team.
06Governance and assuranceDecision rights, obligations, evidence, exceptions and residual-risk visibility, structured so that an exception is a dated decision with an owner rather than a permanent state nobody revisits.
Approach

How the work runs.

  1. 01 Frame around consequence

    Identify the business services whose failure would be material, then map the identities, data, dependencies and controls that determine their exposure. This is what makes the prioritisation defensible later.

  2. 02 Sequence by impact and feasibility

    Order improvements by the reduction in exposure per unit of delivery effort, and state plainly what is being deferred and accepted. A roadmap that pretends everything is being fixed is not a roadmap.

  3. 03 Embed rather than append

    Put controls into platforms, pipelines and processes so they operate by default. A control that depends on someone remembering is a control that will be reported as present and will not be.

  4. 04 Prove under conditions

    Test the response, not only the configuration — exercises, recovery validation, and evidence that a detection produces an action rather than a ticket.

Starting points

Where engagements usually begin.

Each of these is a contained piece of work with a deliverable you own, and is a sensible first engagement.

01Security posture assessmentWhere exposure actually sits across identity, cloud, data and operations, prioritised by business consequence, with a sequence rather than a findings dump.
02Identity and privileged access reviewWho has what, how they got it, what should be removed, and the lifecycle change that stops it recurring.
03Cloud security baselineLanding-zone guardrails, policy-as-code and pipeline controls for an estate where delivery has outpaced control review.
04Detection and response improvementTuning, triage design and runbooks for a team drowning in alert volume without the capacity to reduce it.
05Regulatory readinessGap assessment against a specific obligation — DPDP, GDPR, sector rules — with the evidence model that makes ongoing compliance sustainable rather than an annual scramble.
Questions

What buyers ask.

Do you run a 24/7 SOC or managed detection service?

No. MENTARA does not operate a security operations centre and does not offer managed detection and response. If you need someone watching your estate at 03:00, that is a specialist provider and we will say so.

What we do is improve the decisions a SOC makes — detection tuning, triage design, response runbooks, escalation paths — whether that SOC is yours or a third party's. Engagements frequently sit alongside an MDR provider rather than replacing one.

Can you help us achieve ISO 27001 or SOC 2?

We can help you build the management system, control set and evidence model that certification requires, and prepare you for audit. We cannot certify you — that requires an accredited body — and we are not that body.

Worth stating plainly: MENTARA does not hold these certifications itself. Our position on that is set out in full on the trust and security page, and you should weigh it.

Do you resell or implement specific security products?

We hold no reseller agreements and take no vendor commission, which means our tooling recommendations carry no commercial interest. That independence is worth something during a selection exercise.

It also means we are not a certified implementation partner for any specific security product. Where deep product-specific configuration is the requirement, a specialist partner is often the better answer and we will tell you.

Our team already knows what is wrong. Why bring you in?

That is usually true, and it is the most common situation we see. The blocker is rarely diagnosis — it is that nobody has the authority to decide what will not be fixed, so everything stays open and nothing gets sequenced.

In that case the useful engagement is short: turn what your team already knows into a defensible, prioritised sequence with named owners and explicit acceptance of residual risk, so the decisions can actually be made. If you do not need that either, you do not need us.

07

Where MENTARA fits best.

Scope

MENTARA fits where the problem is that security decisions are not being made, or are being made without reference to business consequence — and where you want one accountable owner connecting risk, architecture, engineering and operations rather than four suppliers each holding a piece.

Some adjacent needs are better served elsewhere: an incident response retainer for a live incident, an MDR provider for continuous monitoring coverage, and a certified product partner for deep configuration of one specific security tool.

Bring the exposure you cannot get a straight answer on.

Share the business context, constraints and expected outcome. MENTARA will identify the relevant accountable route.

One partner. One plan. Measurable outcomes.