Baselines are useful when applied with context.
A control is not useful just because it appears on a checklist. Baselines earn their value through judgment about scope, applicability, and environment.
Baseline Based helps regulated entities improve secure configuration, technical baselines, and remediation follow-through. Our focus is the implementation layer: what is configured, what is missing, what needs to change, and how the result is documented.
Baseline Based was built around a simple observation: in regulated environments expectations are often clear, but implementation is not. Policies, frameworks, and audit requirements exist. What is missing is a practical way to move from those requirements to secure baselines, validated gaps, prioritised changes, and defensible evidence.
We work in the translation layer between broad regulatory language and the systems, controls, and configurations that actually need to hold up.
A control is not useful just because it appears on a checklist. Baselines earn their value through judgment about scope, applicability, and environment.
Treating hardening as a scan-and-file activity produces reports, not outcomes. We look at baseline, gaps, remediation, exceptions, and evidence as one connected piece of work.
What matters, what is missing, what can be fixed, how to show the result holds up. Frameworks such as DORA and NIS2 shape the context, but the work is largely framework and tech-agnostic.
Engagements move through five connected stages. Each one produces something usable for the next; none of them exist in isolation.
Understand the environment, systems in scope, relevant benchmarks, existing maturity, internal constraints, and the control objectives that matter for this engagement.
Use established benchmarks and implementation guidance, but apply them with judgment to the specific environment rather than as a wholesale checklist by creating customised baselines.
Separate meaningful gaps from expected deviations, based on technical limitations or business needs and low-value noise. Review findings with the technical team before they become an action list.
Turn findings into a practical path: what to fix first, what needs stakeholder input, how to fix and what should be formally documented.
Document decisions, outputs and evidence so the result is understandable internally and supportable externally during audit, review, or handover.
A scoped and structured engagement, not open-ended consulting.
A benchmark-led but context-aware approach to hardening.
Clear separation between high-value findings and background noise.
Practical and detailed remediation guidance rather than generic recommendations.
Documented outputs that support internal ownership and external scrutiny.
Clarity about what Baseline Based does not do is part of what makes the work useful.
A generic policy-writing shop.
Broad GRC theatre detached from implementation.
A one-off scanner that drops a PDF and disappears.
A substitute for internal ownership.
A firm trying to be everything across cyber, risk, and compliance.
Most engagements start with a defined piece of work. Where it makes sense, they extend into one of three continuation paths.
Support the internal team with documentation, walkthroughs, and clean ownership transfer once the initial work is in place.
Stay involved to help track progress, keep baselines up to date with evolving benchmarks, assist with audits and support follow-through over time without owning the day-to-day.
When you deploy a new technology, the infra-requirements might change and this means the existing baselines need modifications as well. Moreover, the new technology might need to be baselined altogether.
Controls & compliance
Former founder and startup operator. Experience building compliance-heavy products and the ISMS, risk, and control structures behind them.
A short call is the fastest way to see whether Baseline Based is the right fit for your environment, your scope, and what you need to hold up.
Let's talk