Advisory built for regulated finance.
Three pillars, one discipline: security decisions made legible to boards, regulators and the executives accountable for them.
Enterprise Security Risk Management
Board-grade visibility of the cyber risks that are actually material. Risk profiles built from business impact, threat modelling on the applications that move money, and reporting that lets a risk committee decide with confidence.
- Risk profiles & materiality assessmentFAIR · NIST CSF
- Executive & board cyber-risk reportingC-SUITE
- Crown-jewels & high-value-asset identificationBIA
- Threat modelling on critical applicationsSTRIDE · MITRE
Cyber Strategy & Roadmap Development
Strategy that survives contact with the regulator and the budget cycle. Independent validation of multi-year roadmaps, maturity benchmarked against global peers, and operating models that make the strategy executable.
- Multi-year strategy design & independent validation3-YR HORIZON
- Maturity assessment & peer benchmarkingREGIONAL · GLOBAL
- Target operating model designPEOPLE · PROCESS · TECH
- Zero Trust & enterprise security architectureSABSA · TOGAF
Governance, Risk & Compliance
Compliance treated as an operating discipline, not paperwork. Readiness for DORA and NIS 2, harmonisation across UK, EU and APAC regimes, and certification programmes led end to end.
- DORA readiness & enhanced risk managementDORA
- Regulatory harmonisation across regimesNIS 2 · MAS TRM
- Certification programme leadershipISO 27001:2022
- Policies, standards & control frameworksCIS · PCI DSS
A ledger of mandates.
Nine years of advisory across the institutions where cyber risk is systemic: market infrastructure, sovereign capital, exchanges, banks and the platforms they depend on.
Client confidentiality is absolute — engagements are listed by sector.
| Sector | Mandate | Region |
|---|---|---|
| Systemically important European FMI | Repeatable assessment methodology for mission-critical applications under DORA’s enhanced risk-management mandate; executive reporting translating systemic cyber risk for C-suite and senior management. | UK · EU |
| Sovereign wealth fund | Zero Trust architecture blueprint and a refreshed enterprise security architecture, embedding Zero Trust principles in support of a new business model. | Singapore |
| One of Singapore’s largest financial institutions | Independent review and validation of a three-year cyber defence roadmap and strategy, with maturity benchmarking against regional and global peers. | APAC |
| National ICT ministry | Sector-level cyber strategy and framework — vulnerability, threat, incident and crisis management — aligned to leading international standards. | Middle East |
| Financial subsidiary of a German automotive group | Crown-jewels and high-value-asset identification across the region: the framework, the executive engagement and the prioritised asset register. | APAC |
| Satellite communications operator | ISO 27001:2022 re-certification leadership for critical platforms, with harmonisation of UK, EU and national cybersecurity mandates. | UK · US |
From assessment to the boardroom.
The same arc on every mandate — evidence first, materiality second, and a story the board can act on at the end of it.
Assess
Maturity, threat exposure and control reality — benchmarked against regional and global peers, not against vendor marketing.
Prioritise
Business impact analysis with the executives who own the assets. Materiality decides the order of work; investment follows the crown jewels.
Chart
A roadmap the board can fund and the CISO can deliver — sequenced, costed in effort, and mapped to the regulatory horizon.
Report
Systemic risk translated into business language: board papers, committee reporting and the ongoing counsel that keeps direction.
CISSP 2023–2029LondonUK · EU · APAC · ME
Alyssa Sevilla, CISSP
LSVL Cyber is the independent practice of Alyssa Sevilla — nine years of international security advisory across London, Brussels, Singapore and the Middle East, most of it inside the world’s most regulated industry.
Her career spans Big Four financial-services consulting, global telecommunications and satellite operators, and Europe’s market infrastructure — advising sovereign wealth funds, stock exchanges, banks and asset managers on the risks that reach the board.
Begin the conversation.
For advisory enquiries, board briefings or engagement availability — a direct line to the principal, without a gatekeeper.
contact@lsvlcyber.com