Our offerings

Structured engagements for organisations that need clarity.

Every Oxford Systems Cyber Strategy Translation engagement applies the management discipline to
your organisation: your sector, your leadership, and your specific gap. There are no off-the-shelf
programmes, no junior consultants, and no generic content.
Every engagement is scoped, designed, and delivered personally by Dr John McCarthy.
Choose the format that fits where you are right now. Many clients begin with an entry-level engagement
and build from there.

Executive Briefing: Understand the Landscape. Know Where You Stand.

From £1,800 + VAT

Book Executive Briefing

Secure card payment is processed by Stripe.
You will be redirected to Stripe checkout.

What it is

The Executive Briefing is an input engagement. Dr John McCarthy works directly with up to four senior people in a focused, tailored session that maps the cyber-strategy landscape in terms your leadership team can use. You leave with clarity on what cyber risk means for your business, what good looks like, and where the conversation in your organisation is working or breaking down. This is not a lecture and it is not a generic awareness session. It is a working conversation, built around your organisation, your sector, and your strategic context.

What you get

  • A tailored full-day briefing session with Dr John McCarthy
  • Sector-specific framing of your industry's risk landscape in plain language
  • An interactive leadership session designed to surface the questions that matter
  • A post-session summary document suitable for board records
  • Clear next steps framed as decisions, not a list of actions for the IT team

Right for you if

Your board or senior leadership team needs to genuinely understand cyber risk in business terms, not just be told it is important. Particularly valuable ahead of a regulatory review, board refresh, M&A activity, or in the wake of an incident elsewhere in your sector.

One Day Assessment & Rapid Review: Find the Gap. Get the Verdict.

From £1,800 + VAT

Book One Day Assessment

Secure card payment is processed by Stripe.
You will be redirected to Stripe checkout.

What it is

The One Day Assessment is an output engagement. Dr John McCarthy examines your organisation and tells you what he finds. Working with your senior team, he runs a structured diagnostic of where your cyber-strategy translation is breaking down: where commercial leadership and technical capability are misaligned, where communication is failing, and what the business consequence of that gap looks like in your specific context.

You leave with a clear, expert view of where you are. This is not a technical audit, but a plain-language assessment of your organisation's cyber-strategy translation posture, written in terms the board can act on.

What you get

  • A full structured assessment day with Dr John McCarthy
  • Diagnostic mapping of your cyber-strategy translation gap
  • A plain-language written feedback report, board-ready
  • Prioritised recommendations framed entirely in business terms
  • A clear picture of where you are most exposed and what to do about it

Right for you if

You want a rapid, independent expert view of the translation gap in your organisation before committing to a longer programme. Also valuable where a board or executive team needs credible, external evidence of the gap to make the case for investment, or to satisfy a regulatory or governance requirement.

Immersive Company Programme: Transform the Conversation. Permanently.

From £10,500 + VAT

Book Immersive Company Programme

Secure card payment is processed by Stripe.
You will be redirected to Stripe checkout.

What it is

The most comprehensive Oxford Systems Cyber Strategy Translation engagement. Over three days, Dr John McCarthy works exclusively with your organisation to build a lasting translation capability, not just to brief your team, but to fundamentally change how your commercial and technical leadership communicate on cyber risk. Every element is bespoke. The framework is applied in full. The output is permanent.

What you get

  • Three full days with Dr John McCarthy, exclusive to your organisation, up to 8 people
  • Full application of the Oxford Systems Cyber Strategy Translation Framework
  • Working sessions across both commercial and technical leadership
  • Development of a shared language and decision framework specific to your company
  • A complete board-ready cyber strategy narrative in your organisation's own terms
  • A prioritised, strategy-linked cyber roadmap
  • Post-programme report and recommended ongoing model

Right for you if

You want to fundamentally transform how your organisation handles the cyber-strategy conversation, embedding the translation capability permanently, not just receiving a report. Particularly valuable for complex organisations, regulated industries, and those undergoing significant transformation, M&A activity, or major digital change programmes.

Retained Advisory: A Trusted Voice. Always at the Table.

Pricing on application

What it is

For organisations that want ongoing access to Dr McCarthy's expertise as the cyber-strategy conversation evolves, as the threat landscape shifts, and as business strategy changes. A retained arrangement provides a consistent, trusted external voice at the intersection of cyber and commercial leadership. It is structured entirely around your organisation's needs.

What you get

  • Ongoing advisory access to Dr John McCarthy
  • Support for board, executive, and senior leadership cyber discussions
  • Independent challenge on cyber strategy, governance, and communication
  • Assistance translating technical risk into business decisions
  • Continuity as your cyber-strategy conversation develops

Right for you if

You require sustained board-level advisory support, whether as a standing arrangement following a programme, or as an ongoing external resource for your CISO and executive team.

Bespoke Programme

Pricing on application

What it is

Not every organisation fits a standard format. If your need sits outside the options above, including a different duration, audience configuration, sector, or regulatory context, we will design an engagement that fits. Speak to Sarah.

Professional Workshops

Practical, expert-led development for professionals responsible for governing, assuring and supporting organisational cyber risk. Workshops combine authoritative guidance with realistic exercises, governance scenarios and decision-making practice.

Cybersecurity Governance Professionals Workshop: Accountability, Assurance and Decisions

£995 + VAT per delegate

In-house delivery: From £4,500 + VAT for up to 6 people

Register your interest

What it is

A focused, full-day workshop for professionals responsible for governing, assuring or supporting organisational cybersecurity risk. Dr John McCarthy works with participants to examine how cyber risk should move through governance structures—from technical evidence and operational exposure to assurance, escalation, risk acceptance and executive decision.

Participants work with realistic governance papers, scenarios and decision exercises to identify weak accountability, test the quality of cyber reporting and improve the questions placed before boards and governance committees. This is not technical cybersecurity training. It is a practical governance workshop for professionals who must ensure that cyber risks are understood, challenged, escalated and governed effectively.

Who should attend

  • Company secretaries, governance professionals and committee secretariats
  • Enterprise risk, operational risk and GRC professionals
  • Internal audit, assurance, legal and regulatory compliance teams
  • Data protection, information governance and cyber assurance professionals
  • Business continuity, organisational resilience and third-party risk leaders
  • Board advisers, non-executive directors and public-sector governance representatives

Participants do not require technical cybersecurity expertise. The recommended group size is 6 people.

What the day includes

  • The governance responsibility: What boards and governance functions should require from cybersecurity reporting
  • Governance architecture mapping: Examining committees, accountabilities, escalation routes and delegated decision authority
  • Reporting quality review: Identifying technical detail, ambiguity and missing business consequences in a sample cyber paper
  • Translation exercise: Converting technical evidence into exposed outcomes, material consequences and governance relevance
  • Risk-acceptance exercise: Testing authority, evidence and risk-appetite context before risk is accepted or deferred
  • Assurance mapping: Identifying the evidence governance bodies need and where assurance is fragmented, duplicated or absent
  • Committee simulation: Determining what should be challenged, escalated, recorded or decided in a realistic cyber scenario
  • Governance improvement plan: Agreeing practical improvements participants can apply in their organisations

What you get

  • A full-day workshop delivered personally by Dr John McCarthy
  • Practical application of the Five-Layer Cyber Strategy Translation Framework
  • Governance scenarios, reporting reviews and decision exercises
  • A model for evaluating the quality of cyber papers
  • A structured set of questions for boards and governance committees
  • Practical principles for cyber-risk escalation and acceptance
  • A participant workbook and certificate of completion

Outcomes

By the end of the day, participants will be able to:

  • Recognise whether cyber reporting is genuinely decision-ready
  • Challenge technical information without becoming cybersecurity specialists
  • Connect cyber evidence to business outcomes and material consequences
  • Identify unclear ownership, accountability and decision authority
  • Determine when cyber risk requires escalation
  • Test whether risk acceptance is properly authorised and evidenced
  • Distinguish operational reporting from governance assurance
  • Improve the quality of board and committee discussions and decisions

Right for you if

You work in governance, risk, audit, assurance, legal or compliance and are expected to provide effective oversight of cybersecurity without always receiving information in a usable form. It is particularly valuable where cyber papers are highly technical, committee responsibilities overlap, risk acceptance is poorly evidenced, assurance is fragmented, or governance professionals need greater confidence when questioning senior and technical leaders.

Beyond Translation — Full Cyber
Security Services

Everything you need. Under one roof.

Cyber Strategy Translator is Oxford Systems' public knowledge and engagement platform for the management discipline of Cyber Strategy Translation. Oxford Systems delivers the consulting and advisory engagements. But Oxford Systems is a full-service cyber security consultancy, which means that when clients need specialist technical work alongside or following a translation engagement, they do not need to go elsewhere.

Dr John McCarthy and the Oxford Systems team deliver the complete range of cyber security services, including:

  • Penetration testing and vulnerability assessment
  • Cyber resilience auditing and assurance
  • Incident response planning and support
  • Cloud security assessment and migration support
  • Operational Technology (OT) and SCADA security
  • Governance, Risk and Compliance (GRC) advisory
  • Security architecture design and review
  • NCSC-aligned cyber assurance and CAF assessment
  • Digital forensics and investigation
  • Bespoke security programme design and delivery

Whether you need the translation work, the technical work, or both, Oxford Systems brings it together. One relationship. One trusted authority. No need to manage multiple suppliers.

To discuss which engagement is
right for your organisation,
contact Sarah Gooding.

Call: +44 7957 672 202

Complete the enquiry form