HOW WE WORK

Built for regulated environments.

Baseline Based helps regulated entities improve secure configuration, technical baselines, and remediation follow-through. Our focus is the implementation layer: what is configured, what is missing, what needs to change, and how the result is documented.

§ 01What Baseline Based is

A translation layer between requirements and technical reality.

Baseline Based was built around a simple observation: in regulated environments expectations are often clear, but implementation is not. Policies, frameworks, and audit requirements exist. What is missing is a practical way to move from those requirements to secure baselines, validated gaps, prioritised changes, and defensible evidence.

We work in the translation layer between broad regulatory language and the systems, controls, and configurations that actually need to hold up.

§ 02Our perspective

Opinions we hold, and why they matter.

A

Baselines are useful when applied with context.

A control is not useful just because it appears on a checklist. Baselines earn their value through judgment about scope, applicability, and environment.

B

Secure configuration is not a one-off exercise.

Treating hardening as a scan-and-file activity produces reports, not outcomes. We look at baseline, gaps, remediation, exceptions, and evidence as one connected piece of work.

C

The practical questions matter more than the framework.

What matters, what is missing, what can be fixed, how to show the result holds up. Frameworks such as DORA and NIS2 shape the context, but the work is largely framework and tech-agnostic.

§ 03How we work

A structured, connected operating model.

Engagements move through five connected stages. Each one produces something usable for the next; none of them exist in isolation.

  1. 01

    Scope and context

    Understand the environment, systems in scope, relevant benchmarks, existing maturity, internal constraints, and the control objectives that matter for this engagement.

  2. 02

    Benchmark selection

    Use established benchmarks and implementation guidance, but apply them with judgment to the specific environment rather than as a wholesale checklist by creating customised baselines.

  3. 03

    Assessment and validation

    Separate meaningful gaps from expected deviations, based on technical limitations or business needs and low-value noise. Review findings with the technical team before they become an action list.

  4. 04

    Prioritisation and remediation

    Turn findings into a practical path: what to fix first, what needs stakeholder input, how to fix and what should be formally documented. 

  5. 05

    Evidence and follow-through

    Document decisions, outputs and evidence so the result is understandable internally and supportable externally during audit, review, or handover.

§ 04What to expect

A defined scope, and a defensible result.

  • 01

    A scoped and structured engagement, not open-ended consulting.

  • 02

    A benchmark-led but context-aware approach to hardening.

  • 03

    Clear separation between high-value findings and background noise.

  • 04

    Practical and detailed remediation guidance rather than generic recommendations.

  • 05

    Documented outputs that support internal ownership and external scrutiny.

§ 05What we are not

Narrow by design.

Clarity about what Baseline Based does not do is part of what makes the work useful.

  • — not

    A generic policy-writing shop.

  • — not

    Broad GRC theatre detached from implementation.

  • — not

    A one-off scanner that drops a PDF and disappears.

  • — not

    A substitute for internal ownership.

  • — not

    A firm trying to be everything across cyber, risk, and compliance.

§ 06What comes after

Three ways the work can continue.

Most engagements start with a defined piece of work. Where it makes sense, they extend into one of three continuation paths.

  1. Path I

    Handover and knowledge transfer

    Support the internal team with documentation, walkthroughs, and clean ownership transfer once the initial work is in place.

  2. Path II

    Ongoing advisory or retainer

    Stay involved to help track progress, keep baselines up to date with evolving benchmarks, assist with audits and support follow-through over time without owning the day-to-day.

  3. Path III

    Managed service

    When you deploy a new technology, the infra-requirements might change and this means the existing baselines need modifications as well. Moreover, the new technology might need to be baselined altogether.

§ 07Background

Regulated-sector experience as builders & implementors.

Chris

Controls & compliance

Former founder and startup operator. Experience building compliance-heavy products and the ISMS, risk, and control structures behind them.

Madalina

Secure configuration & hardening

Banking and insurance background with hands-on CIS implementation, remediation guidance, exception handling, and audit evidence across enterprise environments.

§ 08Let's talk

If this is the kind of work you need, let's talk.

A short call is the fastest way to see whether Baseline Based is the right fit for your environment, your scope, and what you need to hold up.

Let's talk