Skip to main content

Services

Testing scoped to the question you actually need answered.

Five engagement types, each with a defined scope, a defined window and a deliverable your engineers can work from. If a shorter assessment answers your question honestly, we will say so rather than sell you a longer one.

01

Penetration Testing

Time-boxed, objective-driven testing of a defined target: web application, API, internal network, mobile or cloud environment.

Typical duration
Two to four weeks, depending on scope
Commonly used for
Pre-release assurance, annual testing cycles, customer and regulator evidence

A penetration test answers one question precisely: what can an attacker achieve against this system, from this starting position, inside this window? We work from a written threat model rather than a scanner queue, and we chain findings the way an attacker would, so a low-severity information leak plus a weak session boundary is reported as the account takeover it actually enables. Every finding is manually verified and carries the evidence needed to reproduce it.

What you receive

  • Technical report with reproduction steps, evidence and CVSS v3.1 scoring
  • Executive summary written for the people who approve the budget, not the exploit
  • Ranked remediation plan with specific fix guidance per finding
  • Live walkthrough session with your engineering team
  • Retest of remediated findings within 90 days, included in the fee
Scope this engagement

02

Red Team Engagements

Goal-based adversary simulation against people, process and technology, run without advance warning to your defenders.

Typical duration
Four to eight weeks, including infrastructure preparation
Commonly used for
Organisations with an internal SOC or managed detection provider

A red team engagement measures detection and response, not just exposure. We agree an objective with a small group of trusted stakeholders, then work toward it under realistic constraints: phased command and control infrastructure, controlled social engineering, and tradecraft mapped to MITRE ATT&CK. The deliverable is not a finding count. It is an honest answer to whether your security team saw the activity, how long it took them, and what happened when they escalated.

What you receive

  • Stage by stage narrative of the full attack path, from initial access to objective
  • Detection timeline mapped against MITRE ATT&CK techniques
  • Assessment of alerting, triage and escalation performance
  • Purple team replay run alongside your defenders
  • Prioritised detection engineering recommendations with test cases
Scope this engagement

03

Vulnerability Assessments

Broad, repeatable coverage across the estate, with human triage layered over automated discovery.

Typical duration
One to two weeks per cycle, monthly or quarterly
Commonly used for
Fast-changing estates, acquisition due diligence, continuous compliance evidence

Assessment answers a different question to a penetration test: what is exposed, across everything, right now. We enumerate the external and internal estate, run authenticated and unauthenticated checks, then triage every result by hand so your team receives findings rather than raw tool output. Run on a recurring cycle, the comparison between cycles becomes the more useful deliverable: it shows whether exposure is genuinely falling or simply moving around.

What you receive

  • Asset and exposure inventory for the agreed ranges and cloud accounts
  • Triaged findings with false positives removed before they reach you
  • Severity ranked by exploitability in your environment, not by raw CVSS alone
  • Trend comparison against previous cycles
  • Machine-readable export for your issue tracker
Scope this engagement

04

Exploit Development

Proof-of-concept and weaponised exploit research for the findings that need to be proven rather than argued about.

Typical duration
Scoped per target following a technical review
Commonly used for
Product security teams, appliance and hardware vendors, disputed findings

Some findings only get fixed once somebody demonstrates them. We build reliable proof-of-concept code against vulnerabilities in your own software, appliances and embedded devices, covering memory corruption, unsafe deserialisation, authentication bypass and logic flaws in bespoke protocols. Work runs under a written research agreement with explicit handling rules, and where a third-party vendor is involved we manage coordinated disclosure on your behalf.

What you receive

  • Reliable proof-of-concept with a documented trigger path and constraints
  • Root cause analysis down to the offending code path
  • Exploitability assessment against the mitigations already deployed
  • Patch validation once your fix lands
  • Coordinated disclosure support, including CVE handling
Scope this engagement

05

Security Training and Workshops

Hands-on offensive training delivered by the consultants who run the engagements, using material drawn from real findings.

Typical duration
Half day to three days, cohorts of up to 16 people
Commonly used for
Engineering teams, new joiners, security champion programmes

Generic security awareness content changes very little. Our sessions are practical: participants attack a deliberately vulnerable environment modelled on your own stack, understand why each flaw exists, then fix it and prove the fix holds. We run secure code review clinics for developers, threat modelling workshops for architects, and detection labs for defenders who want to see what the telemetry looks like from the other side.

What you receive

  • Half day, full day or multi-day formats, delivered remotely or onsite
  • Lab environment modelled on your stack, kept available for 30 days afterwards
  • Exercises built from findings in your own codebase where permission allows
  • Threat modelling clinic against a system your team nominates
  • Written summary of the gaps the session exposed, for your training plan
Scope this engagement

06Engagement process

Discovery, scope, testing, reporting, remediation.

Every engagement runs through the same five phases regardless of size. The phases are not administrative overhead: most of the difference between a useful test and an expensive one is decided before any traffic is sent.

  1. 01

    Discovery

    2 to 3 days

    Before anything is scoped, we need to understand what the system does and what would genuinely hurt if it failed. We walk your architecture with the people who built it, identify the data and functions that matter, and agree the threat actors worth simulating. A test scoped without this step measures the wrong thing accurately.

    • Threat model summary for the target environment
    • Inventory of assets, integrations and access levels in play
    • Written success criteria agreed with your stakeholders
  2. 02

    Scope and rules of engagement

    3 to 5 days

    Scope is a written document, not a conversation. We define what is in, what is explicitly out, which techniques are permitted, and what happens if we find something critical at two in the morning. Testing windows, escalation contacts, safe-harbour terms and data handling rules are all fixed here, before a single packet is sent.

    • Signed rules of engagement with authorisation to test
    • Scope statement with explicit exclusions and constraints
    • Escalation contacts, testing windows and emergency stop procedure
  3. 03

    Testing

    1 to 6 weeks

    Consultants work the target manually, using automation only where it genuinely accelerates coverage. We keep a running log of what was attempted and what it returned, so the report reflects tested coverage rather than a sample. Anything critical is reported the moment it is confirmed, out of band, with enough detail for you to act before the engagement ends.

    • Progress notes at agreed checkpoints throughout the engagement
    • Out-of-band notification for critical and high severity findings
    • Evidence pack captured per finding, with reproduction steps
  4. 04

    Reporting

    3 to 5 days

    Every report is peer reviewed by a second consultant before it reaches you. Findings are written for two audiences in one document: engineers who need the exact request, parameter and payload, and executives who need to understand business exposure without reading exploit code. Severity reflects exploitability in your environment, not a raw score copied from a scanner.

    • Technical findings with evidence, reproduction steps and CVSS v3.1 ratings
    • Executive summary covering business impact and residual risk
    • Remediation plan ranked by exploitability and effort
  5. 05

    Remediation guidance

    Up to 90 days

    A report that nobody acts on is an expensive document. We walk your engineers through the findings, answer questions while fixes are being written, and review proposed remediations before they ship. Once fixes are deployed we retest the affected findings and reissue the report, so the version you hand to a customer or auditor reflects the fixed state.

    • Live walkthrough and follow-up support for the engineering team
    • Review of proposed fixes before they reach production
    • Retest of remediated findings and a reissued report with attestation letter

Start here

Not sure which engagement you need?

Describe the system and what you are worried about. We will tell you which assessment answers that question, and which one would be a waste of your budget.

Expires in

Limited time offer

We rebuilt your site for you. Claim it and we handle everything transfer, hosting, and your domain. Then update it anytime, just by asking AI.

Host for only$8 per monthBilled yearly
Claim limited offer now