Digital Security Agency  ·  Independent Advisory

CIPHERPUNKS

Security advisory and secure communications design


We assess, design and lead security work for organisations in government, critical infrastructure and regulated industry — including the communications architecture for those who cannot outsource trust.

Services

Four things we are genuinely good at

We do not claim to cover the whole of security. These are the areas where we have done the work often enough to be useful from the first conversation.

01

Assessments & ISO 27001

Where you actually stand against the standard, what the gaps cost, and what it takes to close them. Threat modelling of specific systems.

Read more

02

AI Governance & ISO 42001

ISO 42001 readiness and AI security assessment — approached from security practice rather than audit practice.

Read more

03

Identity & Access

Passwordless and phishing-resistant authentication strategy, IAM and IGA target state. Architecture and assessment, not implementation.

Read more

04

Technology Programmes

Security architecture and technical leadership for programmes spanning several vendors, disciplines and delivery teams.

Read more

ISO27001 · 42001 · NIS2
NDAAs standard
NeutralNo implementation lock-in
GlobalWherever the work is

We work under NDA. Client references are discussed directly, not published.

The practice

Small on purpose

Cipherworks is a specialist practice rather than a consultancy with a bench to fill. Engagements are led personally, and specialist partners are brought in where a programme genuinely needs them.

That has a practical consequence for clients: the person who scopes the work is the person who does it, and there is no incentive to extend an engagement beyond what it needs.


About the practice
Arimo KoivistoFounder

Secure communications

When the channel is the exposure

For some organisations the exposure is not the endpoint or the perimeter but the conversation itself — who is able to compel access to it, and who holds the keys that are supposed to protect it.

We define requirements, design architecture and provide independent assurance for high-assurance voice and messaging, including cryptographic key management and the separation needed where confidentiality cannot rest on trusting a supplier.


Discuss a requirement

How this is engaged

RequirementsThreat-driven
ArchitectureVendor-neutral
Key managementDesign and review
AssuranceIndependent of supply
DeliveryWith your integrator

Technology

What we work with

AdvenicaNetwork separation
CiptorAuthentication
Jamf Mobile ForensicsMobile threat
FireTailAI security

How we use them, and where we hold commercial relationships

Contact

If any of this is relevant to your work

There is no sales process running from this website. If something here is useful, a direct conversation will establish fit faster than anything we could put on a page.

How to reach us