How Loopli's OSbD operating model works
Loopli turns security, resilience and compliance into a single operating standard: clear ownership, measurable controls, and evidence you can export without building a compliance factory.
Most organizations don’t need another framework or tool. They need a clear, staged way to turn obligations, risks, suppliers and tools into a single operating model – with evidence that stands up to boards, regulators and insurers.
Whether you’re reacting to a specific trigger or trying to get ahead of it, this is the journey we walk clients through.
If you want a tool reseller or a glossy audit binder, we’re not the right fit.
ONE JOURNEY. FIVE STEPS.
Every client is different, but the journey to a working OSbD operating model tends to follow the same pattern:
Managed Visibility: see what's really happening
Get an honest, repeatable view of your assets, exposure and credential risk.
Most organisations are making decisions with an incomplete picture. Devices appear and disappear, internet-facing services drift, and credentials leak quietly onto the dark web.
-
A repeatable view of your internal networks, assets and high-risk changes.
-
Continuous external monitoring of your internet-facing footprint.
-
Dark web and credential exposure monitoring for key domains and accounts.
-
Quarterly (or monthly) review sessions that explain what matters and what to do next.
Typical timeframe:
Initial setup and first view: 2-4 weeks. Ongoing cadence: monthly or quarterly cycles.
Best for:
- SMEs that need professional-grade visibility without a big internal team.
- Larger organisations that want a reality check to inform Baseline and OSbD design.
Example in practice:
A medium-sized SaaS company used Managed Visibility to uncover unmanaged remote-access services and stale high-privilege accounts, feeding directly into their OSbD Baseline and Cyber Essentials remediation.
Discover – initial scan and baselining.
A scale-up or SME that's starting to feel pressure from customers.
Act – short, targeted improvement steps feeding into OSbD .
OSbD Baseline: get a defendable starting point
A fixed-fee engagement for boards and executives who want the truth – and a plan.
The OSbD Baseline pulls everything together into a board-ready view:
-
Your context and obligations: Provision 29, Cyber Governance Code, NIS2/DORA, Cyber Essentials/+, ISO, SOC2, CAF, sector rules, contracts and insurance.
-
Your current controls and evidence: what exists, who owns it, how it's tested and how it maps to obligations.
-
Your real-world exposure: driven by incidents, near-misses and Managed Visibility data, not just policy.
-
Your next 90 days: a prioritised, realistic improvement plan.
Typical timeframe:
Initial setup and first view: 2-4 weeks. Ongoing cadence: monthly or quarterly cycles.
Best for:
- SMEs that need professional-grade visibility without a big internal team.
- Larger organisations that want a reality check to inform Baseline and OSbD design.
Example in practice:
A medium-sized SaaS company used Managed Visibility to uncover unmanaged remote-access services and stale high-privilege accounts, feeding directly into their OSbD Baseline and Cyber Essentials remediation.
OSbD Baseline is a fixed-fee, no-surprises engagement. There's no expectation to commit beyond it – but most clients choose to, because the Baseline makes the next steps obvious.
OSbD Launch: design or reset your operating model
Turn scattered projects and policies into a single, working control and evidence backbone.
If the Baseline shows that your current approach won't meet board, regulatory or insurance expectations, OSbD Launch gives you a time-boxed, structured reset.
-
Target operating model design: Define security domains (e.g. identity, networks, SaaS, data, resilience). Map your regulatory and contractual obligations (Provision 29, NIS2, DORA, ISO, CE/CE+, CAF, sector rules) to these domains.
-
Control & evidence framework: Rationalise duplicate or conflicting controls. Agree on what 'good' evidence looks like in practice for each control.
-
Governance rhythm: Clarify decision rights (board, exec, risk/audit committee, IT/security leadership). Define cadences for metrics, reviews and adjustments.
-
Roadmap: Phased improvements, aligned to your capacity and budget.
Typical timeframe:
12–16 weeks for most mid-market / enterprise scopes.
Best for:
- SMEs that need professional-grade visibility without a big internal team.
- Larger organisations that want a reality check to inform Baseline and OSbD design.
Example in practice:
A regulated financial-services firm used OSbD Launch to align CE/CE+, ISO 27001 and NIS2-preparedness under one governance cadence, reducing review cycles and giving risk and audit committees a single, stable view.
Outcome:
A documented operating model that everyone can see – and a realistic plan for getting from today to 'good enough, with evidence, for our context.'
OSbD Operate: No more 'audit theatre'. Just a cadence.
A managed Compliance & Trust Office to keep your operating model alive.
OSbD Operate is the managed Compliance & Trust Office that keeps your operating model alive:
-
Keeps your control and evidence registers current.
-
Coordinates governance cycles (e.g. risk and audit committee packs).
-
Prepares for and supports audits, regulator engagements and insurance renewals.
-
Integrates signals from Managed Visibility, incidents, suppliers and tools into your OSbD view.
-
Tracks and supports progress against your OSbD roadmap.
Typical timeframe:
Ongoing; usually structured as an annual retainer.
Example in practice:
A multinational group uses OSbD Operate to prepare quarterly risk & audit committee packs and to keep their control/evidence library aligned to both ISO 22301/27001 and their evolving NIS2/DORA obligations.
Outcome:
We don't replace your people, MSPs or MDR providers. We sit alongside them as the operating model and evidence 'brain'.
SecureROI : optimise spend and value
Make sure your security and resilience budget is doing the job you think it is.
SecureROI uses the OSbD view to connect risk, controls and spend:
-
Identify overlapping tools and services that don't add enough marginal value.
-
Highlight under-invested domains where risk and board/regulator expectations are rising.
-
Support renewal and RFP decisions with clear trade-offs.
-
Build business cases that executives and boards can understand and approve.
Typical timeframe:
6–12 weeks per module, depending on scope and complexity.
Example in practice:
A FTSE-listed financial services group used SecureROI to take a hard look at its backup and recovery, cloud storage, monitoring estate and SD-WAN connectivity and security as part of a NIS2 and DORA readiness programme. By consolidating three overlapping monitoring platforms, simplifying SD-WAN and edge controls, and right-sizing cloud storage and backup tiers to actual risk and recovery objectives, they achieved over 40% savings on their existing budget and significantly reduced complexity in their environment. At the same time, they strengthened resilience with clearer failure paths and proven restore patterns, closed several high-priority compliance gaps, and gave the board, risk committee, internal audit and insurers a much clearer, evidence-backed story about how controls, spend and resilience now work together.
Outcome:
You keep and optimise what delivers value, and retire or right-size what doesn't – with a clear, defendable story for boards and CFOs.