Programme Planner - NEMO
Total visibility and control of your cyber programme
Nemo is a programme intelligence tool that helps cyber professionals and their organisations see exactly where they stand, where they need to be, and a realistic plan to get there.
How Relcanto uses Nemo
Relcanto uses Nemo on all of our in-flight client programmes, so our team and our customers deliver new levels of transparency to cyber.
By bringing all the source information together, including team structure, target framework and gap assessment, our customers have made huge leaps in their programme understanding, and so in their decision making.
We make Nemo available to all our customers.
What Nemo does
- Assesses your position against the 41 outcomes of the NCSC Cyber Assessment Framework (CAF 4.0), measured against the target profile that applies to you.
- Documents the target operating model: the security services you need, who owns them, and the organisation and roles to deliver them.
- Plans a realistic roadmap based on real constraints: recruitment lead times, time to remediate and time to evidence maturity.
- Tracks delivery through stage gates, so progress is earned, not assumed.
How it helps
- Clarity
- See every gap, which service closes it, and what happens if a service is dropped or a role is left unfilled.
- A defensible timeline
- Each phase shows why it takes as long as it does, so plans survive board and regulator scrutiny.
- Board-ready reporting
- A one-page monthly status pack showing movement since the last report, risks and decisions required.
- Fits your tools
- Exports to Excel and Microsoft Project, and handles interim cover, secondments and handovers.
How an engagement works
Assess together
We score the 41 CAF outcomes with your team, with evidence for every score, against your target profile.
Design and plan
We build your target operating model and roadmap in Nemo, on your systems, with you in the room.
Deliver and report
Your team tracks progress through stage gates and issues a board report each month.
How we protect your data
Encrypted at rest
Programme data and the audit log are encrypted with AES-256-GCM. Without a valid passphrase, the file cannot be read.
Your passphrase, your key
Each team member unlocks the data with their own passphrase. Passphrases are never stored.
No network connections
Nemo runs fully offline, makes no connections to the internet and downloads no external code.
Role-based access
Named team members only, as Admin, Editor or Viewer, with lockout after failed attempts and inactivity.
Full audit trail
Every change is recorded with who, when, and the before and after values, in a tamper-evident log.
Tamper detection
Any alteration to the encrypted data is detected and refused.
Nemo and your data stay on your systems
Nemo is a single, self-contained file that lives on your own devices and storage, inside your security controls and under your data policies. There is no Relcanto server or cloud service, nothing is sent to us, and you decide who holds a passphrase.
Nemo supports planning and decision making; its outputs are not a CAF assessment, audit or assurance opinion.
Frequently asked questions
- What is Relcanto NEMO and what does it do?
- NEMO is a programme intelligence application designed for cyber security leaders. It combines cyber maturity assessments (such as the 41 outcomes of NCSC CAF 4.0) with operating model design and realistic, constraint-based project scheduling so leadership teams have complete visibility and control over in-flight security programmes.
- Does NEMO require installing software or sending our data to the cloud?
- No. NEMO is a single, self-contained application that runs locally in your web browser with zero internet dependencies. No programme data, architecture notes, or scores are ever sent to Relcanto or any external cloud server. Everything stays encrypted on your organisation's devices and storage under your own security policies.
- How is NEMO encrypted and secured?
- Programme data and audit logs are protected with AES-256-GCM encryption. Each authorised team member unlocks the application with their own passphrase (which is never stored). It includes tamper detection, role-based access controls (Admin, Editor, Viewer), and an immutable audit trail of every change.
- Can we export data from NEMO into existing corporate project tools?
- Yes. NEMO natively exports programme data into Microsoft Project and Microsoft Excel, making it easy to feed existing PMO reporting, board packs, and enterprise governance workflows without re-keying information.
- How can my organisation get access to NEMO?
- NEMO is made available to all Relcanto clients as part of our advisory and delivery engagements. If you would like to see a live walkthrough or discuss using NEMO on an upcoming cyber programme, you can book an intro call with our leadership team via the contact page.
Want a deeper understanding?
We welcome anyone looking to see how Nemo could bring clarity to their programme. Get in touch and we will walk you through it.