The Firm

A boutique firm,
deliberately.

Meridian Partners is a boutique cybersecurity advisory for regulated enterprises — built on a single premise: the regulated mid-market deserves the quality of senior advisory that tier-one firms reserve for their largest clients.

/ 01 — Premise

The gap we were
built to close.

Regulated mid-market firms live with an uncomfortable asymmetry. Their obligations — DFSA and FSRA rulebooks, ISO 27001 certification, PCI DSS attestation, GDPR and UAE PDPL — are written to the same standard as a global bank's. Their access to senior security advisory is not.

The large consultancies price such firms out or staff them down, sending associates where the engagement letter promised partners. Resellers offer "free" advice with a price built into every recommendation. The result is a market where the firms facing the sharpest scrutiny often receive the thinnest counsel.

Meridian Partners closes that gap with a deliberately small practice, senior practitioners only, carrying board-level reporting experience across EMEA and APAC — offered to the regulated mid-market on transparent, month-to-month terms.

/ 02 — Operating Model

How the firm
is run.

01

Senior practitioners only

No leverage model, no delegation pyramid. The consultant who scopes your engagement is the consultant who delivers it.

02

Transparent retainers

Four tiers, month-to-month, adjustable with 30 days' notice. Pricing stated plainly at discovery — never engineered into dependency.

03

Outcome-scoped work

Every engagement is scoped to a defined outcome with named deliverables — not an open-ended stream of billable attendance.

04

No autopilot extensions

Retainers are re-justified on their results. If the work is done, we say so and step back — the door stays open, the meter does not run.

/ 03 — Independence

Advice with
no second customer.

Our independence charter is written into our terms of engagement. It has three clauses, and no exceptions:

I.

No vendor commissions

No referral fees, success fees, or incentives from any technology vendor, in any form.

II.

No resale

No margin on licences, hardware, or services. We sell judgement, and nothing else.

III.

No channel arrangements

No partner programmes or alliances that would give any vendor influence over our recommendations.

/ 04 — Entity

Incorporated in Dubai.
Operating from two capitals.

The firm is structured for the corridor it serves — the Gulf's regulated financial centres and the London market they trade with. Full corporate and registration details are stated here as procurement teams expect to find them.

Legal Entity

Meridian Partners FZCO

Free Zone Company · Dubai, UAE

Trade Licence

IFZA Licence No. 89800

International Free Zone Authority

Registered Office · UAE

IFZA Business Park, Dubai Digital Park,
Dubai Silicon Oasis, Dubai, UAE

+971 4 216 0701
Operating Office · UK

London, United Kingdom

+44 7828 743250
Correspondence

contact@meridianpartners.me · Data protection: contact@meridianpartners.me

/ 05 — Delivery

Remote-first.
Present when it matters.

Delivery

Secure video, by default

Engagements run over secure video collaboration with disciplined cadence and documentation — the same rigour as a site visit, without the airfare on your invoice.

Presence

On-site as required

Board sessions, regulator meetings, incident exercises, and assessments that demand physical presence are delivered in person — planned, purposeful, and scoped in advance.

Reach

EMEA · APAC · Americas

Anchored in London and Dubai, the practice serves clients globally — with working hours and reporting rhythms arranged around your jurisdictions, not ours.

/ 06 — Values

Four words we
are held to.

Independence

Advice funded by one party — the client. Every recommendation must survive the question: who else benefits?

Candour

The honest finding over the comfortable one. If an engagement isn't needed, we say so before it begins.

Craftsmanship

Documents built to be used, frameworks built to be operated, and work we would sign in front of any auditor.

Discretion

Client matters stay client matters. We publish no client names and trade on no one's incident.

/ 07 — Engage

Judge the firm
by a conversation.

30 minutes with a senior practitioner. A candid read on where you stand — and whether we're the right firm to help.

30 min · Video · No obligation

/ 07 — Engagement Process

A disciplined
five-step method.

Every engagement follows the same architected sequence — from the first scoping call to steady-state governance. No mystery, no billable-hour drift, no methodology invented on the fly. Each step produces a named deliverable you can audit.

Step 01

Scope

A 30-minute strategic consultation, followed by a written scoping document within 72 hours.

  • Problem framing & fit assessment
  • Engagement tier recommendation
  • Commercial & timeline envelope
Deliverable

Scoping document & SOW

Step 02

Assess

Structured diagnostic of current-state security, architecture, and control posture.

  • Gap analysis against target framework
  • Risk register & threat modelling
  • Architecture & vendor stack review
Deliverable

Diagnostic report & risk register

Step 03 · Core

Strategise

Target-state design, prioritised roadmap, and board-ready narrative translating risk into business terms.

  • Target architecture & control design
  • Multi-year remediation roadmap
  • Budget & sequencing plan
Deliverable

Strategy document & board pack

Step 04

Execute

Hands-on delivery alongside your team. We implement — not just advise.

  • Vendor RFPs & contract negotiation
  • Policy drafting & control implementation
  • Team enablement & knowledge transfer
Deliverable

Implemented controls & policies

Step 05

Govern

Ongoing stewardship of the programme — monthly rhythm, board reporting, incident readiness.

  • Monthly risk & control reviews
  • Quarterly board reporting
  • Vendor renewal & incident advocacy
Deliverable

Ongoing executive reporting

Typical Onboarding

7–14 days

From SOW signature to active engagement

Cadence

Monthly rhythm

Fortnightly operational · monthly exec

Notice Period

30 days

Pause, scale, or exit at any time