Services
Four services. One team. Nothing subcontracted.
Every engagement is run by the same senior practitioners who scoped it. We report critical findings the hour we confirm them, and we retest everything we report.
- Engagement shape
- Fixed scope and fixed price, agreed in writing before any testing begins.
- Who does the work
- The practitioners you meet during scoping. No handover to a junior after signature.
- After delivery
- A walkthrough with your engineers and a retest of every finding, included.
Service 01
Penetration Testing
A time-boxed, goal-oriented attack against the systems you nominate. We work towards an agreed objective rather than down a checklist, and we tell you the moment something serious surfaces instead of saving it for the report.
What is included
- External and internal network testing
- Web application and API testing, authenticated and unauthenticated
- Cloud configuration review across AWS, Azure and Google Cloud
- Authentication, session and authorisation logic testing
- Business logic abuse, not only the injection classes a scanner knows
- Exploit chaining towards an objective you define before we start
How it runs
Scoping
We agree the targets, the objective, the rules of engagement and who to call if we find something that cannot wait.
Reconnaissance
Attack surface mapping across your estate, credentialed wherever credentials make the test sharper rather than slower.
Exploitation
Manual testing with tooling in a supporting role. Critical findings are reported the hour we confirm them, not in week three.
Report and retest
A written report, a walkthrough with your engineers, and a retest of every finding once you have fixed it.
You receive
- Technical findings report with reproduction steps and evidence
- Executive summary written for people who will not read the technical report
- Prioritised remediation plan with rough effort estimates
- Attestation letter you can share with customers and auditors
- One retest of all findings, included, within ninety days
- Typical duration
- Two to four weeks
- Best for
- Teams facing a customer security review, an audit, or their first serious test
- Available from
- Starter and above
Service 02
Security Consulting & Risk Assessments
An honest assessment of your risk, written without the padding that makes most risk reports go unread. We spend time with your engineers and your leadership, then tell you what we would fix first if it were our company.
What is included
- Threat modelling against your real architecture and data flows
- Risk register built from your systems rather than a generic template
- Control gap analysis mapped to SOC 2, ISO 27001, HIPAA or CIS
- Vendor and third-party risk review
- Roadmap sequenced by risk reduced per unit of engineering effort
- Budget and hiring guidance for the next twelve months
How it runs
Discovery
Interviews with engineering, operations and leadership, plus a read of the architecture as it is rather than as it was drawn.
Modelling
We map the assets worth protecting, who would want them, and the routes that currently exist to reach them.
Prioritisation
Every risk is scored against likelihood, impact and the cost of fixing it, so the ordering survives an argument.
Roadmap
A sequenced twelve-month plan, presented to your leadership team with the reasoning intact.
You receive
- Risk register your team can maintain after we leave
- Threat model diagrams for the systems that matter most
- Control gap matrix against your chosen framework
- Twelve-month security roadmap with owners and effort bands
- Leadership briefing, delivered live and left behind as a document
- Typical duration
- Three to six weeks
- Best for
- Companies deciding where to spend a security budget for the first time
- Available from
- Growth and above
Service 03
Security Architecture & Hardening
Design and implementation work done alongside your team. We review what you have, propose what it should become, and stay involved while it is built, so the design survives the first sprint that touches it.
What is included
- Architecture and design review for new and existing systems
- Identity and access design, covering single sign-on, MFA and least privilege
- Network segmentation and zero-trust access patterns
- Cloud baselines written as code, with drift detection
- Secrets management, key rotation and certificate lifecycle
- Secure defaults built into your build and deployment pipeline
How it runs
Review
We read the architecture, the infrastructure code and the parts of the estate nobody has looked at since it was built.
Design
A target state your team agrees with, split into changes that can ship independently rather than one rewrite.
Implementation support
We pair with your engineers, review pull requests, and write the modules nobody has time to write.
Verification
We test the result the same way we would test a client we had never met, and hand over the tooling to keep it honest.
You receive
- Architecture review with findings ranked by blast radius
- Target-state design documents and diagrams your team will actually use
- Infrastructure-as-code baselines and guardrails
- Pipeline controls that block a whole class of regression
- Handover session and documentation for the engineers who inherit it
- Typical duration
- Four to twelve weeks, or ongoing
- Best for
- Teams rebuilding, migrating cloud, or scaling past the architecture that got them here
- Available from
- Growth and above
Service 04
Incident Readiness & Response Planning
The worst time to design an incident process is during an incident. We build the plan, prove it with an exercise, and make sure the logs you will need already exist before you need them.
What is included
- Incident response plan written around your team, roles and tooling
- Detection and logging review across endpoints, cloud and applications
- Severity model, escalation paths and on-call responsibilities
- Tabletop exercises run against scenarios drawn from your own estate
- Communication templates for customers, regulators and staff
- Retainer options for hands-on response when something real happens
How it runs
Assessment
What you can currently see, what you can prove, and how long it would take you to answer the questions a breach raises.
Plan
A plan short enough to be read at three in the morning, with runbooks for the scenarios most likely to reach you.
Exercise
A facilitated tabletop with your real on-call people, run without warning them what the scenario is.
Refine
We fix what the exercise broke, close the logging gaps it exposed, and leave you able to run the next one yourselves.
You receive
- Incident response plan and severity model
- Runbooks for your most likely scenarios
- Logging and detection gap report with a prioritised fix list
- Tabletop exercise findings and a recording of the session
- Customer, regulator and internal communication templates
- Typical duration
- Two to five weeks
- Best for
- Teams with a plan nobody has read, or no plan at all
- Available from
- Starter and above
Not sure which one
Most people start with a conversation, not a service
Describe the situation and we will tell you which of these is the right shape, or that none of them is. Scoping calls are free and take about half an hour.