Advisory & Strategy

Security Architecture Review

An in-depth review of your network and systems architecture to ensure security is built into the design, not bolted on later.

Our experts review your technical architecture — segmentation, access control, encryption, and data flows — against best practices and Zero-Trust principles, delivering practical recommendations to close architectural weaknesses before they become operational risk.

What's included

  • Architecture and data-flow review: network diagrams, trust boundaries, data flows, the DMZ, and north-south and east-west traffic.
  • Threat modeling of critical systems and data flows using STRIDE and attack trees to expose design-level weaknesses.
  • Zero-trust assessment: identity-centric access, micro-segmentation, device trust, an assume-breach posture, and maturity against a zero-trust model.
  • Network segmentation and isolation: flat-network risk, segmentation design, isolation of crown-jewel assets, and IT/OT separation where present.
  • Defense-in-depth evaluation: layered controls across perimeter, network, host, application, and data.
  • Secure design patterns and their gaps: authentication and authorization architecture, key and secrets management, DevSecOps integration points, and resilience and redundancy.

Methodology & standards

01

Architecture discovery: gather diagrams, interview architects, and build a current-state view of systems, data flows, and trust boundaries.

02

Threat modeling: apply STRIDE per system and data flow, map to MITRE ATT&CK techniques, and identify design weaknesses and single points of failure.

03

Control and pattern evaluation: assess against zero-trust principles, defense-in-depth, segmentation, and reference architectures (SABSA and NIST).

04

Gap identification and target architecture: document weaknesses and propose a hardened target-state design.

05

A prioritized recommendations roadmap.

Deliverables

  • Architecture review report with annotated diagrams and identified weaknesses.
  • Threat-model artifacts: STRIDE tables and data-flow diagrams with mapped threats.
  • Zero-trust maturity assessment and gap analysis.
  • Target-state and reference-architecture recommendations.
  • Risk-prioritized remediation roadmap for design changes.
  • Executive summary for leadership.

Regulatory controls it satisfies

SAMA CSF — Cyber Security Architecture
Requires a documented and maintained security architecture alongside infrastructure security.
NCA ECC — Cybersecurity Defense
Network security management, segmentation, and cryptography, plus secure-design requirements.
NCA CSCC — Critical Systems
Stronger isolation and segmentation requirements where the architecture hosts critical systems.
ISO/IEC 27001
Network security and segregation controls and secure system-engineering principles.
PDPL
Privacy-by-design embedded into architectures that carry personal-data flows.

Typical timeline

Typically two to four weeks depending on the number of systems and data flows in scope and the complexity of the environment.

Common questions

Is this the same as a penetration test?

No. A penetration test attacks the running environment to find exploitable flaws; an architecture review examines the design itself to surface structural weaknesses before they are built or exploited. The two are complementary.

What do you need to start?

Current network and system architecture diagrams, data-flow documentation, and access to your architects; where diagrams are outdated, we help reconstruct an accurate current-state view.