Engagements
Four shapes. One method.
Every engagement runs the same seven phases and produces the same kind of build document. The shapes differ in scope and duration, and in where they start. Most start with the architecture review.
Architecture review
Two to three weeks. Phases 0 to 2: intake, the current-state tenancy diagram, the CIS baseline and Cloud Guard posture, a numbered findings register and a roadmap. Fixed scope, written down before we start. Read the full description →
Security assessment and build document
The complete plan: all seven phases, the before-and-after benchmark, the identity and integration designs, the SIEM interface, the Supplier Portal pattern, and the build document your team executes and audits against. Typically follows the review.
Migration security workstream
Security architecture and control design inside an E-Business Suite to Fusion Cloud programme: role-based access by persona, segregation of duties and sensitive-access rules, automated controls, OCI and PaaS security, and the regulatory overlay your sector requires. Delivered alongside the implementation team, on its timeline.
Retained advisory
Standing access to a principal after go-live: a monthly posture review of Cloud Guard, benchmark and CSPM reports, design review for changes and new integrations, and a named person to call when an auditor asks a question.
Scope and duration are agreed in writing before any engagement starts. We do not publish rate cards; talk to a principal.
Capability patterns
The work, described by shape.
Clients are not named. The patterns are.
Fusion migration, full security workstream
A consumer-goods manufacturer moving from E-Business Suite to Fusion Cloud with OCI and PaaS alongside. The eight outcome areas delivered as one workstream: unified identity model across employees and non-employees, Zero Trust OCI architecture on the CIS benchmark, the security review process for every integration and extension, privileged access and breakglass, SIEM over Kafka-compatible streaming, AI Agent Studio guardrails, and the Supplier Portal on the current identity pattern.
Regulated healthcare, controls and access governance
A healthcare non-profit migrating E-Business Suite to Fusion Cloud. Role-based access aligned to job personas, segregation-of-duties and sensitive-access rule frameworks, automated business-process controls, and an audit-ready control set aligned to HIPAA and SOC 2.
Posture reviews for a global property group
A global retail-property group running Oracle Integration Cloud and OCI. Integration and data-security consulting with a standing monthly review of CSPM and CIS benchmark output, findings triaged into a running register, and architecture-level write-ups for leadership.
Security requirements across a financial-markets estate
A global financial-markets infrastructure group. Security requirements written for Oracle Cloud ERP, EPM, PaaS (OIC, VBCS, PCS) and OCI; automated compliance recipes in Cloud Guard and a CSPM platform to enforce them continuously; enterprise IAM (directory and identity-governance platform) integrated with OCI and Cloud ERP; every OCI security service configured to the standard.
Fit
When Fortova is the right call.
- You run Oracle Fusion Cloud, OCI, or both, and the security design has never been written down in one place.
- You are migrating from E-Business Suite and want the access model designed before the roles are built, not after.
- An audit, a cyber-insurance questionnaire or a regulator has asked a question your current documentation cannot answer.
- Integrations have accumulated on Basic authentication and shared credentials, and nobody has the inventory.
- AI agents and external model calls are arriving in the estate faster than the governance for them.
- You want the work done by a principal who has delivered this shape many times, not learned on your clock.
Start with an architecture review.
The entry point for every shape. Fixed scope, two to three weeks, artifacts you keep.