Cybersecurity and data protection,
Made simple.

Straightforward cybersecurity, data protection and compliance support for growing organisations, built on the expertise, reputation and commitment to quality that BH Consulting has established in the market.

Upfront pricing

Transparent annual

packages with no guesswork.

Broad expertise

Cybersecurity, data protection and AI governance.

Trusted guidance

Practical advice from experienced specialists.

Choose the level of support that’s right for you

Foundation

1–10 employees

2 consulting days

€1,558.33 / month

€17,000 / year equivalent

Standard

11–50 employees

6 consulting days

€2,750.00 / month

€30,000 / year equivalent

Professional

51–150 employees

12 consulting days

€4,812.50 / month

€52,500 / year equivalent

Scale

151–250 employees

24 consulting days

€7,333.33 / month

€80,000 / year equivalent

Compare key inclusionsView full comparison
Tier Sizing & Support
ServiceFoundationStandardProfessionalScale
Typical company size1–1010–5051–150151–250
Consulting days available261224
Governance & Strategic Advisory
ServiceFoundationStandardProfessionalScale
Virtual CISO advisoryQuarterlyQuarterlyQuarterlyQuarterly
Virtual Data Protection advisoryQuarterlyQuarterlyQuarterlyQuarterly
Virtual AI Officer advisoryQuarterlyQuarterlyQuarterlyQuarterly
Board presentationAnnualTwice yearly
Board awareness / cyber-literacy trainingAnnualTwice yearly
Key industry developments briefingAnnualAnnualTwice yearlyQuarterly
Compliance & security posture dashboardAnnualAnnualTwice yearlyQuarterly
Customer Trust Pack
Customer security questionnaire supportUp to 1/yearUp to 2/yearUp to 4/yearUp to 10/year
Executive reportingMonthly
Cybersecurity — Core Assurance
ServiceFoundationStandardProfessionalScale
Cybersecurity Maturity AssessmentLite
Cybersecurity Risk Assessment
Cybersecurity Risk Register
Cybersecurity PoliciesTemplatedTailoredTailoredTailored
Third-Party Vendor Risk Register
Third-party vendor exposure analysis3/year3/year
Supplier onboarding security pack
Backup & Restore posture review
Backup / DR tabletop exerciseAnnualAnnual
Backup & restore / ransomware recovery exerciseAnnual
Identity & Access Management review
MFA & privileged-access governance
Endpoint / EDR posture reviewAnnualAnnualTwice yearlyQuarterly
Dark web / credential monitoring
Firewall Security Assessment
Technical Testing & Exposure Management
ServiceFoundationStandardProfessionalScale
Vulnerability Assessment1 item/year2 items/year4 items/year4 items/year
External attack-surface monitoring
Penetration testing1/year2/year
Microsoft 365 / Google exposure review
Microsoft 365 / Google Workspace Security Assessment
Cloud Security Posture Assessment1/year2/year
Active Directory / Entra ID review
Simulated phishing testAnnualTwice yearlyQuarterlyQuarterly
Company & employee OSINT footprint
Domain & subdomain security
DNS / certificate / CA misconfiguration checks
Impersonation & brand protection – DMARC/SPF/DKIM
Exposed management interface checks
Public secrets exposure search
Awareness, Training & People
ServiceFoundationStandardProfessionalScale
Online Security Awareness Training platform
Staff awareness newsletter
Managed Cybersecurity Awareness Programme
Lunch & Learn awareness sessions1/year2/year
Role-based training – Developers, Finance, HR etc.1 role/year2 roles/year
AI literacy / staff AI awareness training
Incident Response & Resilience
ServiceFoundationStandardProfessionalScale
Incident Response & Data Breach PoliciesTemplatedTailoredTailoredTailored
Incident Response advisory support – business hoursAdd-onUp to 8 hrsUp to 16 hrsUp to 24 hrs
Incident Response runbooks12510
Incident Response Tabletop ExerciseAnnualTwice yearly
Breach notification drafting templates – DPC/ICOTemplated
Breach notification workflow & regulator communications playbook
Cyber Resilience & Business Continuity PlanAnnual reviewFull plan
Certification & Regulatory Compliance Readiness
ServiceFoundationStandardProfessionalScale
Cyber Essentials readiness & certification supportAdd-on
Cyber Essentials Plus readiness*Add-onAdd-on
Cyber Fundamentals alignment*Add-on
ISO 27001 alignment / gap analysisAdd-onAdd-on
ISO 27001 certification readiness*Add-onAdd-onAdd-on
SOC 2 readiness*Add-onAdd-onAdd-on
NIS2 / Cyber Security and Resilience Bill scoping & gap analysisAdd-onAdd-on
DORA / FCA Rules readiness – financial services*Add-onAdd-on
Other regulatory gap analysisAdd-onAdd-onAdd-onAdd-on
Readiness and alignment services support organisations in preparing for applicable standards, regulations, and certification schemes. BH Haven does not guarantee regulatory compliance or certification.
Cyber Insurance Support
ServiceFoundationStandardProfessionalScale
Cyber Insurance readiness assessment1/year1/year1/year
Cyber Insurance renewal assistance
PCI DSS — Where Applicable
ServiceFoundationStandardProfessionalScale
PCI Self-Assessment Questionnaire support
PCI DSS Assessment
PCI Vulnerability Scan
GDPR / Data Protection
ServiceFoundationStandardProfessionalScale
GDPR / Data Protection Gap AnalysisLite
GDPR / Data Protection PoliciesTemplatedTailoredTailoredTailored
ROPA development & review
ROPA annual maintenance
DPIA support1/year2/yearUp to 5/yearUp to 10/year
Transfer Impact AssessmentAdd-onAdd-onUp to 2/yearUp to 4/year
DSAR & data-subject rights procedureTemplatedTailoredTailoredTailored
Data retention & deletion process development
Cookie scan
Website Privacy Notice review
GDPR training
AI Governance
ServiceFoundationStandardProfessionalScale
AI AssessmentLite
AI PoliciesTemplatedTailoredTailoredTailored
AI inventory & shadow-AI discovery
AI Awareness Training
EU AI Act risk classification1 system/year
ISO 42001 alignment / gap analysisAdd-on
Sector-Specific Bolt-Ons
Optional serviceFoundationStandardProfessionalScale
FinTech – CBI/FCA outsourcing & operational resilienceAdd-onAdd-onAdd-onAdd-on
Healthcare – HSE/NHS supplier assurance packAdd-onAdd-onAdd-onAdd-on
Charity – OSCR/Charity Commission data-handling guidanceAdd-onAdd-onAdd-onAdd-on
SaaS/Technology – Customer due-diligence packAdd-onAdd-onAdd-onAdd-on
Compare key inclusionsView full comparison
ServiceFoundationStandardProfessionalScale
Consulting days261224
Cybersecurity maturity assessmentLiteIncludedIncludedIncluded
Vulnerability assessmentAnnual · 1 itemAnnual · 2 itemsSemi-annual · 4 itemsQuarterly · 4 items
Vulnerability assessmentAnnual · 1 itemAnnual · 2 itemsSemi-annual · 4 itemsQuarterly · 4 items
Vulnerability assessmentAnnual · 1 itemAnnual · 2 itemsSemi-annual · 4 itemsQuarterly · 4 items
Vulnerability assessmentAnnual · 1 itemAnnual · 2 itemsSemi-annual · 4 itemsQuarterly · 4 items

Foundation

1–10 employees

2 consulting days

£1,500.00 / month

£15,750 / year equivalent

Standard

11–50 employees

6 consulting days

£2,500.00 / month

£27,000 / year equivalent

Professional

51–150 employees

12 consulting days

£4,500.00 / month

£47,500 / year equivalent

Scale

151–250 employees

24 consulting days

£6,600.00 / month

£72,000 / year equivalent

Compare key inclusionsView full comparison
Tier Sizing & Support
ServiceFoundationStandardProfessionalScale
Typical company size1–1010–5051–150151–250
Consulting days available261224
Governance & Strategic Advisory
ServiceFoundationStandardProfessionalScale
Virtual CISO advisoryQuarterlyQuarterlyQuarterlyQuarterly
Virtual Data Protection advisoryQuarterlyQuarterlyQuarterlyQuarterly
Virtual AI Officer advisoryQuarterlyQuarterlyQuarterlyQuarterly
Board presentationAnnualTwice yearly
Board awareness / cyber-literacy trainingAnnualTwice yearly
Key industry developments briefingAnnualAnnualTwice yearlyQuarterly
Compliance & security posture dashboardAnnualAnnualTwice yearlyQuarterly
Customer Trust Pack
Customer security questionnaire supportUp to 1/yearUp to 2/yearUp to 4/yearUp to 10/year
Executive reportingMonthly
Cybersecurity — Core Assurance
ServiceFoundationStandardProfessionalScale
Cybersecurity Maturity AssessmentLite
Cybersecurity Risk Assessment
Cybersecurity Risk Register
Cybersecurity PoliciesTemplatedTailoredTailoredTailored
Third-Party Vendor Risk Register
Third-party vendor exposure analysis3/year3/year
Supplier onboarding security pack
Backup & Restore posture review
Backup / DR tabletop exerciseAnnualAnnual
Backup & restore / ransomware recovery exerciseAnnual
Identity & Access Management review
MFA & privileged-access governance
Endpoint / EDR posture reviewAnnualAnnualTwice yearlyQuarterly
Dark web / credential monitoring
Firewall Security Assessment
Technical Testing & Exposure Management
ServiceFoundationStandardProfessionalScale
Vulnerability Assessment1 item/year2 items/year4 items/year4 items/year
External attack-surface monitoring
Penetration testing1/year2/year
Microsoft 365 / Google exposure review
Microsoft 365 / Google Workspace Security Assessment
Cloud Security Posture Assessment1/year2/year
Active Directory / Entra ID review
Simulated phishing testAnnualTwice yearlyQuarterlyQuarterly
Company & employee OSINT footprint
Domain & subdomain security
DNS / certificate / CA misconfiguration checks
Impersonation & brand protection – DMARC/SPF/DKIM
Exposed management interface checks
Public secrets exposure search
Awareness, Training & People
ServiceFoundationStandardProfessionalScale
Online Security Awareness Training platform
Staff awareness newsletter
Managed Cybersecurity Awareness Programme
Lunch & Learn awareness sessions1/year2/year
Role-based training – Developers, Finance, HR etc.1 role/year2 roles/year
AI literacy / staff AI awareness training
Incident Response & Resilience
ServiceFoundationStandardProfessionalScale
Incident Response & Data Breach PoliciesTemplatedTailoredTailoredTailored
Incident Response advisory support – business hoursAdd-onUp to 8 hrsUp to 16 hrsUp to 24 hrs
Incident Response runbooks12510
Incident Response Tabletop ExerciseAnnualTwice yearly
Breach notification drafting templates – DPC/ICOTemplated
Breach notification workflow & regulator communications playbook
Cyber Resilience & Business Continuity PlanAnnual reviewFull plan
Certification & Regulatory Compliance Readiness
ServiceFoundationStandardProfessionalScale
Cyber Essentials readiness & certification supportAdd-on
Cyber Essentials Plus readiness*Add-onAdd-on
Cyber Fundamentals alignment*Add-on
ISO 27001 alignment / gap analysisAdd-onAdd-on
ISO 27001 certification readiness*Add-onAdd-onAdd-on
SOC 2 readiness*Add-onAdd-onAdd-on
NIS2 / Cyber Security and Resilience Bill scoping & gap analysisAdd-onAdd-on
DORA / FCA Rules readiness – financial services*Add-onAdd-on
Other regulatory gap analysisAdd-onAdd-onAdd-onAdd-on
Readiness and alignment services support organisations in preparing for applicable standards, regulations, and certification schemes. BH Haven does not guarantee regulatory compliance or certification.
Cyber Insurance Support
ServiceFoundationStandardProfessionalScale
Cyber Insurance readiness assessment1/year1/year1/year
Cyber Insurance renewal assistance
PCI DSS — Where Applicable
ServiceFoundationStandardProfessionalScale
PCI Self-Assessment Questionnaire support
PCI DSS Assessment
PCI Vulnerability Scan
GDPR / Data Protection
ServiceFoundationStandardProfessionalScale
GDPR / Data Protection Gap AnalysisLite
GDPR / Data Protection PoliciesTemplatedTailoredTailoredTailored
ROPA development & review
ROPA annual maintenance
DPIA support1/year2/yearUp to 5/yearUp to 10/year
Transfer Impact AssessmentAdd-onAdd-onUp to 2/yearUp to 4/year
DSAR & data-subject rights procedureTemplatedTailoredTailoredTailored
Data retention & deletion process development
Cookie scan
Website Privacy Notice review
GDPR training
AI Governance
ServiceFoundationStandardProfessionalScale
AI AssessmentLite
AI PoliciesTemplatedTailoredTailoredTailored
AI inventory & shadow-AI discovery
AI Awareness Training
EU AI Act risk classification1 system/year
ISO 42001 alignment / gap analysisAdd-on
Sector-Specific Bolt-Ons
Optional serviceFoundationStandardProfessionalScale
FinTech – CBI/FCA outsourcing & operational resilienceAdd-onAdd-onAdd-onAdd-on
Healthcare – HSE/NHS supplier assurance packAdd-onAdd-onAdd-onAdd-on
Charity – OSCR/Charity Commission data-handling guidanceAdd-onAdd-onAdd-onAdd-on
SaaS/Technology – Customer due-diligence packAdd-onAdd-onAdd-onAdd-on

Built around the requirements that matter in your market

The Ireland / EU and UK versions of BH Haven can surface the relevant standards, regulators and market-specific services.

Optional services can be added when you need support beyond your package allowance.

Extra consulting days
Extra DPIA / TIA / DSAR / AI-FRIA
Extra incident response

Find the right level of support for your organisation

BH Haven is designed around clearly defined, packaged support. For more complex or bespoke requirements, contact us at BH Consulting.

Frequently Asked Questions

What is BH Haven?

BH Haven is an ongoing governance and assurance service designed specifically for SMEs. It brings together cybersecurity, data protection, AI governance, risk management, regulatory readiness, and business resilience within one structured service. You get access to experienced BH Consulting specialists, practical technical assurance, and regular reporting without having to build all of those capabilities internally or rely on multiple providers.

The objective is simple, BH Haven helps you understand your risks, decide what matters most, improve your resilience, and demonstrate to customers, regulators, insurers, and other stakeholders that those risks are being properly managed.

Cybersecurity, privacy, and AI risks are no longer issues only for large organisations. SMEs increasingly face cyber incidents, customer security requirements, data protection obligations, AI risks, and regulatory expectations. BH Haven is designed specifically to make good governance practical and proportionate for SMEs rather than imposing an enterprise-sized security and compliance programme.

Your IT provider and BH Haven perform different roles. Your IT provider will typically focus on operating and supporting your technology. BH Haven focuses on governance, risk, resilience, and assurance helping management understand whether your business is appropriately managing its cybersecurity, privacy, AI, and related business risks. BH Consulting is completely independent from any hardware or software vendors so we provide independent advice rather than designing recommendations around any technology products.

BH Haven brings together activities that your company would otherwise have to manage separately either internally or with the help of various third-party providers. BH Haven provides you with a one point of contact for all your cybersecurity, data protection, and AI needs. This includes;

  • Cybersecurity
  • Data Protection and Privacy
  • AI Governance
  • Risk Management
  • Policies
  • Incident Response and Business Continuity Support
  • Third-Party Risk Management
  • Staff Awareness Training
  • Regulatory and Certification Readiness
  • Executive Reporting
  • Technical Assurance

Most importantly, we help identify what needs attention first, what can wait and where your investment will have the greatest impact.

Yes. That is one of the main reasons BH Haven was created. Rather than treating cybersecurity, GDPR, AI governance, and resilience as separate projects, BH Haven brings them together within one governance programme. This reduces duplication and gives management a clearer view of the risks and priorities facing the business.

Yes. Depending on your requirements, BH Haven can support readiness and alignment for frameworks and requirements including ISO 27001, ISO 42001, SOC 2, Cyber Essentials, Cyber Fundamentals, NIS2, DORA and PCI DSS.

BH Haven does not guarantee certification or legal compliance. Where independent certification, formal assessment or legal advice is required, the appropriate qualified third party will be needed.

Yes. This is becoming an increasingly important issue for SMEs selling to larger or regulated organisations. BH Haven helps you establish the governance, policies, risk management processes, and evidence needed to respond more confidently to customer and supplier due-diligence requests.

The “BH Haven Customer Trust Pack” is designed to make it easier to provide approved, reusable evidence about your cybersecurity, privacy and governance arrangements to customers, procurement teams, insurers and business partners.

No. BH Haven is a service delivered by BH Consulting expert and experienced consultants, supported by technology and proportionate technical assurance. You are not simply given access to another governance platform and left to populate and manage it yourself.

BH Consulting also uses proprietary AI capabilities to augment our experienced consultants, helping us deliver a breadth of governance and assurance expertise in a way that is practical and cost-effective for SMEs.

BH Haven is designed around the resource constraints of SMEs. We will need input from relevant people to understand your business, technology, risks, and existing arrangements, but BH Consulting undertakes much of the specialist governance and assurance work. The aim is to strengthen your internal capability without creating another major administrative burden for your team.

Select the level of service you feel is most appropriate to your business. Otherwise start with a conversation.

We will discuss your organisation, your current challenges, customer and regulatory requirements, and your existing cybersecurity, privacy and governance arrangements. We can then recommend the appropriate BH Haven service level and explain what the first stage of your programme would involve.

Find the right level of support for your organisation

Not sure which BH Haven package is right for you? Tell us a little about your organisation and we’ll help you identify the most appropriate level of support.

Compare key inclusionsView full comparison
Tier Sizing & Support
ServiceFoundationStandardProfessionalScale
Typical company size1–1010–5051–150151–250
Consulting days available261224
Governance & Strategic Advisory
ServiceFoundationStandardProfessionalScale
Virtual CISO advisoryQuarterlyQuarterlyQuarterlyQuarterly
Virtual Data Protection advisoryQuarterlyQuarterlyQuarterlyQuarterly
Virtual AI Officer advisoryQuarterlyQuarterlyQuarterlyQuarterly
Board presentationAnnualTwice yearly
Board awareness / cyber-literacy trainingAnnualTwice yearly
Key industry developments briefingAnnualAnnualTwice yearlyQuarterly
Compliance & security posture dashboardAnnualAnnualTwice yearlyQuarterly
Customer Trust Pack
Customer security questionnaire supportUp to 1/yearUp to 2/yearUp to 4/yearUp to 10/year
Executive reportingMonthly
Cybersecurity — Core Assurance
ServiceFoundationStandardProfessionalScale
Cybersecurity Maturity AssessmentLite
Cybersecurity Risk Assessment
Cybersecurity Risk Register
Cybersecurity PoliciesTemplatedTailoredTailoredTailored
Third-Party Vendor Risk Register
Third-party vendor exposure analysis3/year3/year
Supplier onboarding security pack
Backup & Restore posture review
Backup / DR tabletop exerciseAnnualAnnual
Backup & restore / ransomware recovery exerciseAnnual
Identity & Access Management review
MFA & privileged-access governance
Endpoint / EDR posture reviewAnnualAnnualTwice yearlyQuarterly
Dark web / credential monitoring
Firewall Security Assessment
Technical Testing & Exposure Management
ServiceFoundationStandardProfessionalScale
Vulnerability Assessment1 item/year2 items/year4 items/year4 items/year
External attack-surface monitoring
Penetration testing1/year2/year
Microsoft 365 / Google exposure review
Microsoft 365 / Google Workspace Security Assessment
Cloud Security Posture Assessment1/year2/year
Active Directory / Entra ID review
Simulated phishing testAnnualTwice yearlyQuarterlyQuarterly
Company & employee OSINT footprint
Domain & subdomain security
DNS / certificate / CA misconfiguration checks
Impersonation & brand protection – DMARC/SPF/DKIM
Exposed management interface checks
Public secrets exposure search
Awareness, Training & People
ServiceFoundationStandardProfessionalScale
Online Security Awareness Training platform
Staff awareness newsletter
Managed Cybersecurity Awareness Programme
Lunch & Learn awareness sessions1/year2/year
Role-based training – Developers, Finance, HR etc.1 role/year2 roles/year
AI literacy / staff AI awareness training
Incident Response & Resilience
ServiceFoundationStandardProfessionalScale
Incident Response & Data Breach PoliciesTemplatedTailoredTailoredTailored
Incident Response advisory support – business hoursAdd-onUp to 8 hrsUp to 16 hrsUp to 24 hrs
Incident Response runbooks12510
Incident Response Tabletop ExerciseAnnualTwice yearly
Breach notification drafting templates – DPC/ICOTemplated
Breach notification workflow & regulator communications playbook
Cyber Resilience & Business Continuity PlanAnnual reviewFull plan
Certification & Regulatory Compliance Readiness
ServiceFoundationStandardProfessionalScale
Cyber Essentials readiness & certification supportAdd-on
Cyber Essentials Plus readiness*Add-onAdd-on
Cyber Fundamentals alignment*Add-on
ISO 27001 alignment / gap analysisAdd-onAdd-on
ISO 27001 certification readiness*Add-onAdd-onAdd-on
SOC 2 readiness*Add-onAdd-onAdd-on
NIS2 / Cyber Security and Resilience Bill scoping & gap analysisAdd-onAdd-on
DORA / FCA Rules readiness – financial services*Add-onAdd-on
Other regulatory gap analysisAdd-onAdd-onAdd-onAdd-on
Readiness and alignment services support organisations in preparing for applicable standards, regulations, and certification schemes. BH Haven does not guarantee regulatory compliance or certification.
Cyber Insurance Support
ServiceFoundationStandardProfessionalScale
Cyber Insurance readiness assessment1/year1/year1/year
Cyber Insurance renewal assistance
PCI DSS — Where Applicable
ServiceFoundationStandardProfessionalScale
PCI Self-Assessment Questionnaire support
PCI DSS Assessment
PCI Vulnerability Scan
GDPR / Data Protection
ServiceFoundationStandardProfessionalScale
GDPR / Data Protection Gap AnalysisLite
GDPR / Data Protection PoliciesTemplatedTailoredTailoredTailored
ROPA development & review
ROPA annual maintenance
DPIA support1/year2/yearUp to 5/yearUp to 10/year
Transfer Impact AssessmentAdd-onAdd-onUp to 2/yearUp to 4/year
DSAR & data-subject rights procedureTemplatedTailoredTailoredTailored
Data retention & deletion process development
Cookie scan
Website Privacy Notice review
GDPR training
AI Governance
ServiceFoundationStandardProfessionalScale
AI AssessmentLite
AI PoliciesTemplatedTailoredTailoredTailored
AI inventory & shadow-AI discovery
AI Awareness Training
EU AI Act risk classification1 system/year
ISO 42001 alignment / gap analysisAdd-on
Sector-Specific Bolt-Ons
Optional serviceFoundationStandardProfessionalScale
FinTech – CBI/FCA outsourcing & operational resilienceAdd-onAdd-onAdd-onAdd-on
Healthcare – HSE/NHS supplier assurance packAdd-onAdd-onAdd-onAdd-on
Charity – OSCR/Charity Commission data-handling guidanceAdd-onAdd-onAdd-onAdd-on
SaaS/Technology – Customer due-diligence packAdd-onAdd-onAdd-onAdd-on
Compare key inclusionsView full comparison
Tier Sizing & Support
ServiceFoundationStandardProfessionalScale
Typical company size1–1010–5051–150151–250
Consulting days available261224
Governance & Strategic Advisory
ServiceFoundationStandardProfessionalScale
Virtual CISO advisoryQuarterlyQuarterlyQuarterlyQuarterly
Virtual Data Protection advisoryQuarterlyQuarterlyQuarterlyQuarterly
Virtual AI Officer advisoryQuarterlyQuarterlyQuarterlyQuarterly
Board presentationAnnualTwice yearly
Board awareness / cyber-literacy trainingAnnualTwice yearly
Key industry developments briefingAnnualAnnualTwice yearlyQuarterly
Compliance & security posture dashboardAnnualAnnualTwice yearlyQuarterly
Customer Trust Pack
Customer security questionnaire supportUp to 1/yearUp to 2/yearUp to 4/yearUp to 10/year
Executive reportingMonthly
Cybersecurity — Core Assurance
ServiceFoundationStandardProfessionalScale
Cybersecurity Maturity AssessmentLite
Cybersecurity Risk Assessment
Cybersecurity Risk Register
Cybersecurity PoliciesTemplatedTailoredTailoredTailored
Third-Party Vendor Risk Register
Third-party vendor exposure analysis3/year3/year
Supplier onboarding security pack
Backup & Restore posture review
Backup / DR tabletop exerciseAnnualAnnual
Backup & restore / ransomware recovery exerciseAnnual
Identity & Access Management review
MFA & privileged-access governance
Endpoint / EDR posture reviewAnnualAnnualTwice yearlyQuarterly
Dark web / credential monitoring
Firewall Security Assessment
Technical Testing & Exposure Management
ServiceFoundationStandardProfessionalScale
Vulnerability Assessment1 item/year2 items/year4 items/year4 items/year
External attack-surface monitoring
Penetration testing1/year2/year
Microsoft 365 / Google exposure review
Microsoft 365 / Google Workspace Security Assessment
Cloud Security Posture Assessment1/year2/year
Active Directory / Entra ID review
Simulated phishing testAnnualTwice yearlyQuarterlyQuarterly
Company & employee OSINT footprint
Domain & subdomain security
DNS / certificate / CA misconfiguration checks
Impersonation & brand protection – DMARC/SPF/DKIM
Exposed management interface checks
Public secrets exposure search
Awareness, Training & People
ServiceFoundationStandardProfessionalScale
Online Security Awareness Training platform
Staff awareness newsletter
Managed Cybersecurity Awareness Programme
Lunch & Learn awareness sessions1/year2/year
Role-based training – Developers, Finance, HR etc.1 role/year2 roles/year
AI literacy / staff AI awareness training
Incident Response & Resilience
ServiceFoundationStandardProfessionalScale
Incident Response & Data Breach PoliciesTemplatedTailoredTailoredTailored
Incident Response advisory support – business hoursAdd-onUp to 8 hrsUp to 16 hrsUp to 24 hrs
Incident Response runbooks12510
Incident Response Tabletop ExerciseAnnualTwice yearly
Breach notification drafting templates – DPC/ICOTemplated
Breach notification workflow & regulator communications playbook
Cyber Resilience & Business Continuity PlanAnnual reviewFull plan
Certification & Regulatory Compliance Readiness
ServiceFoundationStandardProfessionalScale
Cyber Essentials readiness & certification supportAdd-on
Cyber Essentials Plus readiness*Add-onAdd-on
Cyber Fundamentals alignment*Add-on
ISO 27001 alignment / gap analysisAdd-onAdd-on
ISO 27001 certification readiness*Add-onAdd-onAdd-on
SOC 2 readiness*Add-onAdd-onAdd-on
NIS2 / Cyber Security and Resilience Bill scoping & gap analysisAdd-onAdd-on
DORA / FCA Rules readiness – financial services*Add-onAdd-on
Other regulatory gap analysisAdd-onAdd-onAdd-onAdd-on
Readiness and alignment services support organisations in preparing for applicable standards, regulations, and certification schemes. BH Haven does not guarantee regulatory compliance or certification.
Cyber Insurance Support
ServiceFoundationStandardProfessionalScale
Cyber Insurance readiness assessment1/year1/year1/year
Cyber Insurance renewal assistance
PCI DSS — Where Applicable
ServiceFoundationStandardProfessionalScale
PCI Self-Assessment Questionnaire support
PCI DSS Assessment
PCI Vulnerability Scan
GDPR / Data Protection
ServiceFoundationStandardProfessionalScale
GDPR / Data Protection Gap AnalysisLite
GDPR / Data Protection PoliciesTemplatedTailoredTailoredTailored
ROPA development & review
ROPA annual maintenance
DPIA support1/year2/yearUp to 5/yearUp to 10/year
Transfer Impact AssessmentAdd-onAdd-onUp to 2/yearUp to 4/year
DSAR & data-subject rights procedureTemplatedTailoredTailoredTailored
Data retention & deletion process development
Cookie scan
Website Privacy Notice review
GDPR training
AI Governance
ServiceFoundationStandardProfessionalScale
AI AssessmentLite
AI PoliciesTemplatedTailoredTailoredTailored
AI inventory & shadow-AI discovery
AI Awareness Training
EU AI Act risk classification1 system/year
ISO 42001 alignment / gap analysisAdd-on
Sector-Specific Bolt-Ons
Optional serviceFoundationStandardProfessionalScale
FinTech – CBI/FCA outsourcing & operational resilienceAdd-onAdd-onAdd-onAdd-on
Healthcare – HSE/NHS supplier assurance packAdd-onAdd-onAdd-onAdd-on
Charity – OSCR/Charity Commission data-handling guidanceAdd-onAdd-onAdd-onAdd-on
SaaS/Technology – Customer due-diligence packAdd-onAdd-onAdd-onAdd-on