Our Services

Designed to address every critical aspect of risk.

From advisory to 24/7 operations, our services span the full security lifecycle. Each is delivered to one standard, by practitioners who have done the work — so the parts add up to a coherent whole rather than a patchwork of point solutions.

SERVICE 01

Crisis Response & Management

When an incident hits, hours matter. We stand up command, contain the event and bring you back to business — then make sure it never lands the same way twice.

24/7 incident command & crisis hotline
Business continuity & disaster recovery planning
Tabletop exercises & crisis simulations
Post-incident review & resilience uplift
Explore this serviceOutcome: Faster recovery, lower loss, a board that sleeps at night.
Crisis Response & Management
SERVICE 02

Security Planning & Engineering

Security designed in, not bolted on. We engineer protective systems around how your people, sites and assets actually operate.

Site & facility security master-planning
Electronic security & surveillance design
Access control & integration architecture
Construction & commissioning oversight
Explore this serviceOutcome: Infrastructure that deters, detects and delays — by design.
Security Planning & Engineering
SERVICE 03

Cyber & Digital Risk Management

The enemy within now arrives by email and API. We assess, harden and monitor your digital estate against a threat landscape that never stands still.

Cyber risk & maturity assessments
POPIA & ISO 27001 readiness
Threat detection & response advisory
Third-party & supply-chain risk reviews
Explore this serviceOutcome: A measurable, defensible cyber posture leadership can trust.
Cyber & Digital Risk Management
SERVICE 04

Workplace Violence & Threat Management

Most serious incidents give warning. We build the programmes that surface threats early and resolve them before they escalate.

Threat assessment & case management
Workplace violence prevention programmes
Executive & VIP protection advisory
Investigations & protective intelligence
Explore this serviceOutcome: A workforce that is safer — and feels it.
Workplace Violence & Threat Management
SERVICE 05

Security & Intelligence Programmes

Decisions are only as good as the intelligence behind them. We design and run intelligence capabilities tuned to your risk profile.

Intelligence programme design & build
Open-source & human-source collection
Risk monitoring & early-warning dashboards
Due diligence & integrity investigations
Explore this serviceOutcome: Foresight you can act on, not noise you have to filter.
Security & Intelligence Programmes
SERVICE 06

Specialised Security Risk Management

A holistic view of risk across your enterprise — quantified, prioritised and translated into a plan the board will fund.

Enterprise security risk assessments
Security strategy & policy frameworks
Maturity benchmarking & roadmaps
Audit, assurance & compliance support
Explore this serviceOutcome: Risk made visible, measurable and manageable.
Specialised Security Risk Management
How we work

A disciplined, repeatable engagement.

01

Assess

We map your threat landscape, exposure and current posture — quantified against your objectives and obligations.

02

Design

We engineer a proportionate, layered strategy across people, process and technology, costed for the board.

03

Implement

We deliver — engineering, programmes and capability — with disciplined project governance and assurance.

04

Operate

We monitor, respond and continually improve, keeping you ahead of a threat landscape that never stands still.

Common questions

What boards ask us first.

How does an engagement with Gray Guardians begin?

Most engagements start with a conversation about what is keeping your leadership awake, followed by a structured risk-profile assessment of your exposure, your current posture and your obligations. From there we propose a proportionate way forward — which may be a single piece of advisory work or a programme spanning the full security lifecycle. You are never committed to more than the next, clearly scoped step.

Which sectors do you serve?

We work across financial services, mining and resources, government and the public sector, higher education, technology and fintech, logistics and transport, and energy and utilities, among others. What our clients share is not an industry but a profile: organisations whose scale, exposure or public role makes risk a board-level concern. Our methodology adapts to the sector; the rigour does not change.

What is your geographic coverage?

Our head office is in Sandton, Johannesburg, with a further office in the Cape Town CBD, giving us deep local presence across South Africa. Beyond our borders we operate across nine African markets — into SADC, East and West Africa — through trusted partners and our own intelligence network. For organisations working across the continent, we combine ground-level local knowledge with genuine continental reach.

How do you protect confidentiality and personal information?

Discretion is fundamental to this work, and confidentiality is maintained with every client as a matter of professional integrity. We process personal information lawfully and accountably in line with POPIA, and our engagements are governed by clear confidentiality and data-handling terms from the outset. Sensitive findings are shared only with the people you authorise to receive them.

How are you different from a guarding or security company?

A guarding company sells manpower; we provide judgement. Our approach is intelligence-led rather than guarding-led — we begin with an accurate picture of your risk and design the right response, which may or may not involve more guards. Where a guarding contract leaves strategy, engineering and assurance to you, we hold the full lifecycle and remain accountable for the outcome.

What is the assess, design, implement and operate model?

It is how we deliver protection end to end. We assess your threat landscape and exposure, design a proportionate strategy costed for the board, implement it across people, process and technology with disciplined governance, and then operate it — monitoring, responding and continually improving. Holding all four phases under one accountable team is what prevents the handoffs where most security programmes fail.

Will you work alongside our existing security providers?

Yes. Many of our engagements are designed to make incumbent providers more effective rather than to replace them, by giving them the strategy, intelligence and assurance they lack. We assess what you already have objectively, integrate what works, and recommend change only where the risk justifies it. Our loyalty is to your protection, not to displacing your suppliers.

How long does a typical engagement last?

It depends entirely on scope. A focused risk assessment or readiness review may run over a few weeks, while designing and implementing a security programme typically spans several months, and operational and assurance partnerships are ongoing by design. We will always set out expected timelines before you commit, and structure the work in defined phases so you retain control at every stage.

How do you approach pricing and scoping?

We price on the value and risk involved, not on headcount or hours, and every engagement is scoped to your specific exposure rather than sold as a fixed package. After an initial assessment we set out a clear scope, the outcomes it targets and the investment required, so you can weigh it against the risk it addresses. You will never be asked to approve work you have not seen costed and justified.

Can you respond to an emergency or active crisis?

Yes. Our operations run on a 24/7 basis, and we can stand up incident command, contain an unfolding event and guide your organisation back to business at short notice. After the immediate crisis is resolved, we conduct a post-incident review and uplift your resilience so the same event cannot land the same way twice. If you are facing an active incident, contact us directly without delay.

How do you align with our governance and compliance obligations?

Governance is the first principle of our work, not a later consideration. Every engagement is aligned to the standards your stakeholders already expect — King IV™, POPIA, the OHS Act and ISO 27001 and 22301 — so that the security we build strengthens your governance and assurance position. We work with your risk, audit and compliance functions, not around them.

How do we obtain a risk-profile assessment?

The simplest first step is to contact us and request one. We will arrange a confidential discussion to understand your concerns, then conduct a structured assessment of your threat landscape, exposure and current posture. You receive a clear, quantified picture of your risk and a prioritised view of what to address first — with no obligation to proceed further.

Not sure where your exposure sits?

Start with an assessment. We will map your threat landscape and current posture, then show you exactly where a proportionate investment pays back.