Security work, scoped to what you actually need defended.
Every engagement begins with written authorisation and a defined scope. From there we assess, exploit where authorised, report with evidence, and retest after remediation.
Penetration Testing
Adversarial testing of the systems that carry your business, performed manually and amplified with automated tooling.
- Web applications and APIs, including authentication and authorisation logic
- Internal and external network and host testing
- Cloud configuration and identity boundary testing
- Mobile application and backend service testing
- Reproduction steps, evidence and prioritised remediation for every finding
Red Team & Adversary Emulation
Objective-driven campaigns that test whether your detection and response actually works when someone is genuinely trying.
- Threat modelling against adversaries relevant to your sector
- Initial access, persistence, privilege escalation and lateral movement
- Social engineering and physical considerations where in scope
- Detection gap analysis with a full record of what was and was not caught
- Debrief with blue-team remediation priorities
AI & LLM Security
Security assessment of AI systems you build or deploy — a genuinely new attack surface that conventional testing does not cover.
- Direct and indirect prompt injection, including via retrieved content and tools
- Agent and tool-calling exploitation, permission and sandbox escape paths
- Guardrail, filter and system-prompt bypass testing
- Training and context data leakage, memorisation and exfiltration
- Model supply chain, dependency and hosting risk review
Threat Detection & Security Monitoring
Visibility and detection engineering, so that compromise is noticed rather than discovered later by someone else.
- Telemetry and logging pipeline design and gap analysis
- Detection rule authoring mapped to known adversary behaviour
- Behavioural baselining and model-driven anomaly detection
- Alert enrichment, triage and escalation workflows
- Continuous monitoring and recurring reporting
Incident Response & Recovery
Structured response when something has gone wrong, and the planning that makes it possible.
- Containment strategy and evidence preservation
- Forensic analysis and root-cause determination
- Eradication, recovery and rebuild guidance
- Incident response plan development and tabletop exercises
- Post-incident review with concrete control improvements
Cloud & Infrastructure Security
Hardening the environments your applications actually run in.
- Identity, access and least-privilege design review
- Secrets management and key handling
- Infrastructure-as-code and deployment pipeline review
- Container, orchestration and network segmentation assessment
- Backup, resilience and recovery validation
Application & Software Security
Building security into how software is written, not bolting it on afterwards.
- Secure development practice and threat modelling
- Source code review and static analysis triage
- Dependency, supply-chain and build integrity review
- Security requirements embedded into engineering workflow
Compliance, Risk & Assurance
Turning technical reality into documentation that stands up to scrutiny.
- Control assessment and gap analysis
- Documentation and evidence preparation for review
- Vendor, platform and third-party risk assessment
- Messaging, notification and platform compliance review
Not sure what you need?
Describe the system and the concern. We will tell you what an assessment should cover and what it will not.