How Loopli's OSbD operating model works

Loopli turns security, resilience and compliance into a single operating standard: clear ownership, measurable controls, and evidence you can export without building a compliance factory.

Most organizations don’t need another framework or tool. They need a clear, staged way to turn obligations, risks, suppliers and tools into a single operating model – with evidence that stands up to boards, regulators and insurers.

Whether you’re reacting to a specific trigger or trying to get ahead of it, this is the journey we walk clients through.

If you want a tool reseller or a glossy audit binder, we’re not the right fit.

ONE JOURNEY. FIVE STEPS.

Every client is different, but the journey to a working OSbD operating model tends to follow the same pattern:

STEP 1
Managed Visibility
See what's really there
STEP 2
OSbD Baseline
Get a defendable starting point
STEP 3
OSbD Launch
Design or reset the operating model
STEP 4
OSbD Operate
Run and improve it over time
STEP 5
SecureROI
Optimise spend and value
Step 1

Managed Visibility: see what's really happening

Get an honest, repeatable view of your assets, exposure and credential risk.

Most organisations are making decisions with an incomplete picture. Devices appear and disappear, internet-facing services drift, and credentials leak quietly onto the dark web.

  • A repeatable view of your internal networks, assets and high-risk changes.
  • Continuous external monitoring of your internet-facing footprint.
  • Dark web and credential exposure monitoring for key domains and accounts.
  • Quarterly (or monthly) review sessions that explain what matters and what to do next.

Typical timeframe:

Initial setup and first view: 2-4 weeks. Ongoing cadence: monthly or quarterly cycles.

Best for:

  • SMEs that need professional-grade visibility without a big internal team.
  • Larger organisations that want a reality check to inform Baseline and OSbD design.

Example in practice:

A medium-sized SaaS company used Managed Visibility to uncover unmanaged remote-access services and stale high-privilege accounts, feeding directly into their OSbD Baseline and Cyber Essentials remediation.

1

Discover – initial scan and baselining.

2

A scale-up or SME that's starting to feel pressure from customers.

3

Act – short, targeted improvement steps feeding into OSbD .

Step 2

OSbD Baseline: get a defendable starting point

A fixed-fee engagement for boards and executives who want the truth – and a plan.

The OSbD Baseline pulls everything together into a board-ready view:

  • Your context and obligations: Provision 29, Cyber Governance Code, NIS2/DORA, Cyber Essentials/+, ISO, SOC2, CAF, sector rules, contracts and insurance.
  • Your current controls and evidence: what exists, who owns it, how it's tested and how it maps to obligations.
  • Your real-world exposure: driven by incidents, near-misses and Managed Visibility data, not just policy.
  • Your next 90 days: a prioritised, realistic improvement plan.

Typical timeframe:

Initial setup and first view: 2-4 weeks. Ongoing cadence: monthly or quarterly cycles.

Best for:

  • SMEs that need professional-grade visibility without a big internal team.
  • Larger organisations that want a reality check to inform Baseline and OSbD design.

Example in practice:

A medium-sized SaaS company used Managed Visibility to uncover unmanaged remote-access services and stale high-privilege accounts, feeding directly into their OSbD Baseline and Cyber Essentials remediation.

OSbD Baseline is a fixed-fee, no-surprises engagement. There's no expectation to commit beyond it – but most clients choose to, because the Baseline makes the next steps obvious.

Step 3

OSbD Launch: design or reset your operating model

Turn scattered projects and policies into a single, working control and evidence backbone.

If the Baseline shows that your current approach won't meet board, regulatory or insurance expectations, OSbD Launch gives you a time-boxed, structured reset.

  • Target operating model design: Define security domains (e.g. identity, networks, SaaS, data, resilience). Map your regulatory and contractual obligations (Provision 29, NIS2, DORA, ISO, CE/CE+, CAF, sector rules) to these domains.
  • Control & evidence framework: Rationalise duplicate or conflicting controls. Agree on what 'good' evidence looks like in practice for each control.
  • Governance rhythm: Clarify decision rights (board, exec, risk/audit committee, IT/security leadership). Define cadences for metrics, reviews and adjustments.
  • Roadmap: Phased improvements, aligned to your capacity and budget.

Typical timeframe:

12–16 weeks for most mid-market / enterprise scopes.

Best for:

  • SMEs that need professional-grade visibility without a big internal team.
  • Larger organisations that want a reality check to inform Baseline and OSbD design.

Example in practice:

A regulated financial-services firm used OSbD Launch to align CE/CE+, ISO 27001 and NIS2-preparedness under one governance cadence, reducing review cycles and giving risk and audit committees a single, stable view.

Outcome:

A documented operating model that everyone can see – and a realistic plan for getting from today to 'good enough, with evidence, for our context.'

Step 4

OSbD Operate: No more 'audit theatre'. Just a cadence.

A managed Compliance & Trust Office to keep your operating model alive.

OSbD Operate is the managed Compliance & Trust Office that keeps your operating model alive:

  • Keeps your control and evidence registers current.
  • Coordinates governance cycles (e.g. risk and audit committee packs).
  • Prepares for and supports audits, regulator engagements and insurance renewals.
  • Integrates signals from Managed Visibility, incidents, suppliers and tools into your OSbD view.
  • Tracks and supports progress against your OSbD roadmap.

Typical timeframe:

Ongoing; usually structured as an annual retainer.

Example in practice:

A multinational group uses OSbD Operate to prepare quarterly risk & audit committee packs and to keep their control/evidence library aligned to both ISO 22301/27001 and their evolving NIS2/DORA obligations.

Outcome:

We don't replace your people, MSPs or MDR providers. We sit alongside them as the operating model and evidence 'brain'.

Step 5

SecureROI : optimise spend and value

Make sure your security and resilience budget is doing the job you think it is.

SecureROI uses the OSbD view to connect risk, controls and spend:

  • Identify overlapping tools and services that don't add enough marginal value.
  • Highlight under-invested domains where risk and board/regulator expectations are rising.
  • Support renewal and RFP decisions with clear trade-offs.
  • Build business cases that executives and boards can understand and approve.

Typical timeframe:

6–12 weeks per module, depending on scope and complexity.

Example in practice:

A FTSE-listed financial services group used SecureROI to take a hard look at its backup and recovery, cloud storage, monitoring estate and SD-WAN connectivity and security as part of a NIS2 and DORA readiness programme. By consolidating three overlapping monitoring platforms, simplifying SD-WAN and edge controls, and right-sizing cloud storage and backup tiers to actual risk and recovery objectives, they achieved over 40% savings on their existing budget and significantly reduced complexity in their environment. At the same time, they strengthened resilience with clearer failure paths and proven restore patterns, closed several high-priority compliance gaps, and gave the board, risk committee, internal audit and insurers a much clearer, evidence-backed story about how controls, spend and resilience now work together.

Outcome:

You keep and optimise what delivers value, and retire or right-size what doesn't – with a clear, defendable story for boards and CFOs.

You might not need every step, or you may come in partway through. The important thing is that everyone sees the same map.

Not sure where to start?

Answer a few quick questions and we'll suggest the best starting point.