Security is the point. Compliance is a byproduct.

Peak Defence Wingman connects incidents, vulnerabilities, threats, risks, assets, plans, and tasks into a coherent picture, providing a current brief of what you need to know.

How (and why) Wingman works

Wingman maintains a live data graph of your security programme and keeps its brief current — around the clock, with the tools to get the work done.

CVE-2026-2247 · OpenSSLINC-042 · Unusual egressSaaS platform · prodCustomer DB · PIICloudHost · IaaSRISK-7 · Data exposureCTRL-22 · Admin MFACTRL-9 · Encryption at restCTRL-14 · DB monitoringISO 27001 · A.8.24SOC 2 · CC6.1TASK-118 · Patch OpenSSLGDPR · Art. 32Key-rotation log · Q3Elena · platform lead
Assets Vulnerabilities Incidents Risks Controls Requirements Tasks Documents

The live data graph

See everything connected

Wingman holds incidents, vulnerabilities, threats, risks, assets, controls, requirements, vendors, plans and tasks as one live data graph — not separate lists. The relationships are first-class, so "does this matter?" has a real-time answer grounded in your organisation.

Wingman's AI brief of a risk portfolio: headlines, composition, where attention is needed, patterns to watch, and what changed

The current brief

Know where you stand

Wingman keeps a brief on every entity — updated when the underlying facts change — and rolls them up into a programme-level brief: what matters now, what's drifting, what's been decided, and why. Operational decisions, audit packages, board updates, and customer questionnaires are extracts from the brief — not separate documents to maintain.

Wingman task list of recurring plan-generated reviews, with a chat panel answering what's outstanding for a patch task: status, priority, deadline, assignee and the definition of done

Plans & tasks with context

Get the work done

Wingman turns what the graph and brief surface into concrete tasks — assigned to a specific person, with the reason it matters and what done looks like. Incident response, vulnerability remediation and risk reviews are distributed, tracked, and fed back into the picture. The programme runs as work people can actually do — not as a policy people are asked to remember.

Compliance? Yes.

One control. One evidence trail. Multiple views.

Simply apply the frameworks and specific requirements you answer to as lenses on the same programme — not different workstreams with separate spreadsheets.

ISO 27001 SOC 2 NIS2 DORA GDPR EU AI Act

What our clients say

Security is absolutely critical to our business. Peak Defence has been instrumental in managing our security operations — their understanding of the relationships between our security events and business objectives is unlike anything else we’ve used. The ISO 27001 compliance monitoring and auditing has been particularly valuable.
Tage Borg

Tage Borg

CTO, Scrive

As a Strategic Learning Partner serving world-leading enterprises, we operate under exceptionally high security requirements. Peak Defence’s approach enables us to prioritise security based on actual risk, and align with the frameworks our clients expect. We’ve strengthened our security posture while keeping the operational burden on our team to a minimum.
Niclas Oddsberg

Niclas Oddsberg

CEO, Collegial

Latest Posts

Our thoughts about security trends and practices

Three Regulators, One Incident.

Next time something goes wrong in your organisation, you might owe reports to three different regulators — on three different clocks, with three different…

Read More

Timeless Principles (of Security)

Beyond AI, tech and frameworks: five timeless principles that can transform your approach to security leadership and build more resilient teams and systems.

Read More

How Time Horizons Transform Your Planning

Planning is either useful or it’s overhead — the difference is balance. Get the balance right and you get the right velocity: not fast or slow in…

Read More

See what your security programme looks like with Wingman

Schedule a demo to see Wingman in your context.

Book a demo