SABSA TRAINING CONSULTING
Skip to content

Our process:
THE SABSA®
Methodology

SABSA Overview

SABSA is an Enterprise Security Architecture framework that aligns security with business objectives through a layered, risk-based approach.

It allows large enterprises to identify and address risks while prioritising business goals.

The use of a structured, holistic framework empowers your enterprise with strategic insights and practical solutions, transforming cybersecurity from a siloed function into a unified strategic asset.

Businesses looking to implement SABSA into their enterprise will find a strong strategic partner in David Lynas Consulting.


SABSA
ORIGINS

In 1995 David Lynas, and his associates John Sherwood and Andy Clark, devised a unique methodology to address cybersecurity issues for organisations. They called it SABSA (Sherwood Applied Business Security Architecture). They saw a better, more positive way to look at security – holistically embedded in innovation.

David, John and Andy authored the ‘blue book’ Enterprise Security Architecture: A Business-Driven Approach in 2005 and the field of Enterprise Security Architecture was born.


OUR expertise
in applying
the SABSA®
Methodology
assures
solutions
that deliver

DLC is proud to have built a team of unrivalled depth with decades of experience defining and leading enterprise programmes or reporting directly to Corporate CEOs and Government Ministers.

Each member of our team has a history of demonstrable success, can articulate the bigger picture, transform the enterprise conversation, engage stakeholders at every level, and deliver insightful, actionable, practical advice with value-add, and skills transfer.

DLC provides unrivalled assurance of capabilities. All of our team members are SABSA® authors, certified SABSA® Masters, or multi-Practitioner level with Masters in progress.

WHY SABSA
WORKS

SABSA speaks the language of business, not just IT or security, helping security teams justify investments and secure executive buy-in.

By starting with business objectives and translating them into security requirements, it helps architects explain security measures in terms of business value rather than technical terms.

Utilisation of a structured, holistic framework empowers your enterprise with strategic insights and practical solutions, transforming cybersecurity from a siloed function into a unified, strategic asset.

  • Simplify Complexity - icon

    Deliver End-to-End & Through-life

    Deliver cybersecurity capability end-to-end and through-life

  • Enact Resilience - icon

    Create Certainty & Clarity

    Create and sustain clarity of policy, governance, and risk ownership

  • Empowered Internal Teams - icon

    Establish Common Culture & Language

    Establish a common culture and language, enabling the enterprise to collaborate, integrate, adopt, consume & implement

  • Proactive Risk Management - icon

    Capitalise Change & Agility

    Support business ambition to transform, transition and change

WHAT SABSA LOOKS LIKE IN PRACTICE

Once established, SABSA becomes a decision-making framework that can be applied to all IT and security activities.

When a stakeholder proposes a new cloud service or application, questions that would be factored in under a SABSA approach would likely include: “What business objective does this support? What are the risks? What security services are needed?”

Security architects can perform a mapping against the existing architecture to identify which controls already exist and which gaps need filling.


WHO IS SABSA FOR

The SABSA framework is suited to organisations where security directly impacts business value. This can include sectors with significant regulatory requirements.

It has been designed to scale for large complex enterprises with multiple business units and diverse technology environments.

Typically, architecture is built and maintained by enterprise and security architects, and its holistic nature means that security leaders, risk teams, IT, and senior management teams all contribute to the overall framework.


More Resources

Implement &
Adopt ESA
with SABSA

Learn how developing and implementing an Enterprise Security Architecture based in SABSA can transform your cybersecurity initiatives.

Learn more

Insights &
Resources

Enabling Innovation: Automating Enterprise Security Architecture to Accelerate Business Agility – Sydney & Melbourne March 2026

In-person ESA events in Sydney (2nd March) & Melbourne (5th March). Explore how automating an ESA Framework transforms security from a resource-constrained control function into a scalable, business-enabling capability


Responsible AI Reference Architecture

To be effective, the deployment of AI in enterprises needs to be carried out in a responsible manner, ensuring safety for users and the business, and security of the models and datasets. An AI Reference Architecture can identify and categorise the services required for a safe and secure environment for AI.

Learn more - Responsible AI Reference Architecture

More Resources