Skip to content
Prefort Consult

Know where you're exposed before someone else finds out for you.

Prefort Consult runs risk assessments, closes compliance gaps and trains your people then hands you a written record of what was found and what was fixed.

About

Assessment, not theatre.

Prefort Consult runs risk assessments, closes compliance gaps and trains staff for organisations operating in the UK. The output of every engagement is something written down in a register, a report, a closure statement not a slide deck.

Who we work with

Sectors served

  • Banking & financial services
  • Fintech
  • Healthcare
  • Insurance
  • Education
  • Government & public sector
  • Telecommunications
  • Manufacturing
  • Retail & e-commerce
  • Hospitality
  • Legal services
  • NGOs & non-profits

What we do

Services

Consulting first. Every engagement ends with something written down not a category description, a deliverable.

Start here

Risk assessment

A structured review of where your organisation is exposed. Systems, access, process and people ranked by risk likelihood and impact, not by how alarming it sounds.

You receive

A ranked risk register with findings, severity and recommended remediation order.

Compliance

Gap analysis

A control by control analysis of current practice against the standard you're working toward (UK GDPR), (ISO 27001), (PCI DSS) or Cyber Essentials with what's missing made explicit.

You receive

A control by control gap report mapped to the chosen standard, with an owner and effort estimate per gap.

Technical

Vulnerability assessment

Identification of weaknesses across your enterprise assets, scored by how easily each could be exploited and what it would cost you if it were.

You receive

A vulnerability register, scored and ranked, with a remediation timeframe for each finding.

Ongoing

Network protection

Implementation and monitoring of the controls a risk assessment or gap analysis marks as priority, like access hardening, backup verification, monitoring handed over with evidence it works.

You receive

A closure statement confirming each agreed control is in place, with the evidence behind it.

Who does the work

Credentials and team

Adaeze Okonkwo

Principal Consultant

Leads engagement scoping and final reporting. Focused on turning technical findings into decisions boards can act on.

  • CISSP
  • CISM
  • ISO 27001 Lead Auditor

Priya Nair

Senior Security Analyst

Runs technical assessments network testing, vulnerability scoring and control verification across banking and fintech clients.

  • CEH
  • OSCP
  • CompTIA Security+

Elena Novak

Compliance Lead

Maps client environments against UK GDPR, ISO 27001 and Cyber Essentials, and owns gap closure tracking through to sign off.

  • CISA
  • ISO 27001 Lead Implementer

Kwame Mensah

Training Lead

Designs and delivers the awareness, incident-response and executive briefing tracks, tailoring each session to the client's actual risk exposure rather than a generic curriculum.

  • CISSP
  • PMP

6 years in operation.

Corporate training

Train your team, not just your policy

Delivered on-site or remote to your staff, IT leads and leadership — not an open-enrolment course.

All staff

Security awareness

Practical training on the everyday habits that cause most breaches phishing, password reuse, unsecured file sharing.

  • Staff can identify a phishing attempt
  • Shared credentials and personal-email workarounds are retired
  • A documented record of who's been trained, and when

Duration to be confirmed

IT and operations leads

Incident response

What to do in the first hour after something goes wrong, and who is responsible for each step.

  • A written incident response plan with named owners
  • A tested escalation path
  • A team that has rehearsed it, not just read it

Duration to be confirmed

Leadership and board

Executive briefing

A non-technical briefing on organisational exposure, regulatory obligation, and what governance looks like in practice.

  • Leadership can state the organisation's top three exposures
  • Clarity on who is accountable when something goes wrong
  • A shared understanding of UK GDPR and sector specific obligations

Duration to be confirmed

Get in touch

Talk to us about what you're dealing with

Tell us where things stand and we'll tell you what an engagement would look like.