Know where you're exposed before someone else finds out for you.
Prefort Consult runs risk assessments, closes compliance gaps and trains your people then hands you a written record of what was found and what was fixed.
About
Assessment, not theatre.
Prefort Consult runs risk assessments, closes compliance gaps and trains staff for organisations operating in the UK. The output of every engagement is something written down in a register, a report, a closure statement not a slide deck.

Who we work with
Sectors served
- Banking & financial services
- Fintech
- Healthcare
- Insurance
- Education
- Government & public sector
- Telecommunications
- Manufacturing
- Retail & e-commerce
- Hospitality
- Legal services
- NGOs & non-profits
What we do
Services
Consulting first. Every engagement ends with something written down not a category description, a deliverable.
Start hereRisk assessment
A structured review of where your organisation is exposed. Systems, access, process and people ranked by risk likelihood and impact, not by how alarming it sounds.
You receive
A ranked risk register with findings, severity and recommended remediation order.
ComplianceGap analysis
A control by control analysis of current practice against the standard you're working toward (UK GDPR), (ISO 27001), (PCI DSS) or Cyber Essentials with what's missing made explicit.
You receive
A control by control gap report mapped to the chosen standard, with an owner and effort estimate per gap.
TechnicalVulnerability assessment
Identification of weaknesses across your enterprise assets, scored by how easily each could be exploited and what it would cost you if it were.
You receive
A vulnerability register, scored and ranked, with a remediation timeframe for each finding.
OngoingNetwork protection
Implementation and monitoring of the controls a risk assessment or gap analysis marks as priority, like access hardening, backup verification, monitoring handed over with evidence it works.
You receive
A closure statement confirming each agreed control is in place, with the evidence behind it.
Who does the work
Credentials and team
Adaeze Okonkwo
Principal Consultant
Leads engagement scoping and final reporting. Focused on turning technical findings into decisions boards can act on.
- CISSP
- CISM
- ISO 27001 Lead Auditor
Priya Nair
Senior Security Analyst
Runs technical assessments network testing, vulnerability scoring and control verification across banking and fintech clients.
- CEH
- OSCP
- CompTIA Security+
Elena Novak
Compliance Lead
Maps client environments against UK GDPR, ISO 27001 and Cyber Essentials, and owns gap closure tracking through to sign off.
- CISA
- ISO 27001 Lead Implementer
Kwame Mensah
Training Lead
Designs and delivers the awareness, incident-response and executive briefing tracks, tailoring each session to the client's actual risk exposure rather than a generic curriculum.
- CISSP
- PMP
6 years in operation.
Corporate training
Train your team, not just your policy
Delivered on-site or remote to your staff, IT leads and leadership — not an open-enrolment course.

All staff
Security awareness
Practical training on the everyday habits that cause most breaches phishing, password reuse, unsecured file sharing.
- Staff can identify a phishing attempt
- Shared credentials and personal-email workarounds are retired
- A documented record of who's been trained, and when
Duration to be confirmed

IT and operations leads
Incident response
What to do in the first hour after something goes wrong, and who is responsible for each step.
- A written incident response plan with named owners
- A tested escalation path
- A team that has rehearsed it, not just read it
Duration to be confirmed

Leadership and board
Executive briefing
A non-technical briefing on organisational exposure, regulatory obligation, and what governance looks like in practice.
- Leadership can state the organisation's top three exposures
- Clarity on who is accountable when something goes wrong
- A shared understanding of UK GDPR and sector specific obligations
Duration to be confirmed
Insights
Writing on cybersecurity, risk and compliance
Get in touch
Talk to us about what you're dealing with
Tell us where things stand and we'll tell you what an engagement would look like.
