Cybersecurity services
From security testing and engineering to continuous monitoring, governance and EU regulatory readiness, delivered by experienced cybersecurity specialists.
Security Testing
08 / 28When you need to know how you’d actually be breached.
- 1.01
Security Audits
Identify exploitable weaknesses and prioritise remediation.
Security testing - 1.02
Red Team & Adversary Emulation
Test whether the organisation can prevent, detect and respond to a goal-driven attack.
Security testing - 1.03
Social Engineering Assessment
Measure resilience to phishing, voice fraud and other social-engineering techniques.
Security testing - 1.04
Purple Teaming
Validate and improve detection and response collaboratively.
Security testing - 1.05
Attack Surface Management
Continuously identify and prioritise internet-facing exposure.
Security testing - 1.06
DORA Threat-Led Penetration Testing
TIBER-EU-aligned TLPT for designated EU financial entities.
Security testing - 1.07
Smart Contract & Web3 Security Audit
Identify code, logic and economic vulnerabilities before deployment.
Security testing - 1.08
Ransomware Readiness Assessment
Test prevention, detection, recovery and decision-making for ransomware scenarios.
Resilience
Application, API & AI Security
08 / 28When you ship code, APIs or AI.
- 2.01
AI & LLM Security
Assess the security and governance of AI systems.
AI security - 2.02
API Security Testing
Test API authorisation, authentication and business logic manually.
Application security - 2.03
Secure Code Review & SAST
Find security defects in source code before release.
Security engineering - 2.04
DevSecOps & Secure CI/CD
Integrate repeatable security checks and enforcement into CI/CD.
Security engineering - 2.05
Mobile App Security Testing
Assess the mobile application, runtime and supporting API together.
Application security - 2.06
Supply Chain Security & SBOM
Manage dependency, build-pipeline and supplier risk.
Security engineering - 2.07
Threat Modeling & Secure Design
Identify design-level threats before implementation.
Advisory - 2.08
Performance & Load Testing
Measure capacity, bottlenecks and failure behaviour before production demand exposes them.
Security engineering
Cloud Security, Monitoring & Response
05 / 28When the concern is your live environment.
- 3.01
Cloud Security & Posture Assessment
Identify cloud misconfigurations, posture drift and privilege-escalation paths.
Cloud security - 3.02
Kubernetes & Container Security
Assess cluster configuration, workloads, secrets and attack paths.
Cloud security - 3.03
Proactive Security Monitoring
Continuous monitoring, detection and response support.
Security operations - 3.04
Incident Response & Digital Forensics
Prepare before an incident, then investigate, contain and recover when one hits.
Incident response - 3.05
OSINT & Open Data Analysis
Identify publicly exposed information and map the external attack surface.
Reconnaissance
Governance, Risk & Compliance
07 / 28When a regulator, auditor or board is asking (NIS2 / DORA / ISO).
- 4.01
CISO-as-a-Service
Experienced security leadership without a full-time appointment.
Security leadership - 4.02
NIS2 & ISO 27001 Readiness
Assess gaps and prepare evidence for NIS2 and ISO/IEC 27001.
Compliance - 4.03
DORA Compliance & Resilience Testing
DORA governance, resilience testing and TLPT support for financial entities.
Resilience - 4.04
Data Protection Impact Assessment
Assess high-risk personal-data processing before deployment.
Compliance - 4.05
Security Policy & Procedure Development
Build effective security governance.
Governance - 4.06
Security Technology Selection & Implementation
Select security technology against defined requirements and total cost.
Advisory - 4.07
Employee Cybersecurity Awareness Training
Build repeatable security behaviour through relevant practice.
Security awareness
What we test
10 × 6We assess the technical, human and physical attack surfaces available to an adversary. Each row links to the relevant service; testing depth ranges from a focused assessment to a full-scope red-team engagement.
| Surface ╲ Test | REC Reconnaissance & ASM | VA Vulnerability assessment | PT Penetration test | RT Red team | HR Hardening review | MON Continuous monitoring |
|---|---|---|---|---|---|---|
| Reconnaissance & ASM: Core capability | Vulnerability assessment: Core capability | Penetration test: Core capability | Red team: Core capability | Hardening review: Core capability | Continuous monitoring: Available when included in scope | |
| Core capability Reconnaissance & ASM · Vulnerability assessment · Penetration test · Red team · Hardening review Available when included in scope Continuous monitoring Web applications & APIs | ||||||
| Reconnaissance & ASM: Core capability | Vulnerability assessment: Core capability | Penetration test: Available when included in scope | Red team: Available when included in scope | Hardening review: Available when included in scope | Continuous monitoring: Core capability | |
| Core capability Reconnaissance & ASM · Vulnerability assessment · Continuous monitoring Available when included in scope Penetration test · Red team · Hardening review External attack surface | ||||||
| Reconnaissance & ASM: Core capability | Vulnerability assessment: Core capability | Penetration test: Core capability | Red team: Available when included in scope | Hardening review: Core capability | Continuous monitoring: Available when included in scope | |
| Core capability Reconnaissance & ASM · Vulnerability assessment · Penetration test · Hardening review Available when included in scope Red team · Continuous monitoring Cloud environments & containers | ||||||
| Reconnaissance & ASM: Core capability | Vulnerability assessment: Core capability | Penetration test: Core capability | Red team: Core capability | Hardening review: Available when included in scope | Continuous monitoring: Available when included in scope | |
| Core capability Reconnaissance & ASM · Vulnerability assessment · Penetration test · Red team Available when included in scope Hardening review · Continuous monitoring Internal network & AD | ||||||
| Reconnaissance & ASM: Available when included in scope | Vulnerability assessment: Core capability | Penetration test: Available when included in scope | Red team: Out of scope | Hardening review: Core capability | Continuous monitoring: Core capability | |
| Core capability Vulnerability assessment · Hardening review · Continuous monitoring Available when included in scope Reconnaissance & ASM · Penetration test Out of scope Red team Source code & software supply chain | ||||||
| Reconnaissance & ASM: Available when included in scope | Vulnerability assessment: Core capability | Penetration test: Core capability | Red team: Core capability | Hardening review: Core capability | Continuous monitoring: Available when included in scope | |
| Core capability Vulnerability assessment · Penetration test · Red team · Hardening review Available when included in scope Reconnaissance & ASM · Continuous monitoring AI / LLM systems | ||||||
| Reconnaissance & ASM: Available when included in scope | Vulnerability assessment: Core capability | Penetration test: Core capability | Red team: Available when included in scope | Hardening review: Core capability | Continuous monitoring: Out of scope | |
| Core capability Vulnerability assessment · Penetration test · Hardening review Available when included in scope Reconnaissance & ASM · Red team Out of scope Continuous monitoring Mobile applications | ||||||
| Reconnaissance & ASM: Core capability | Vulnerability assessment: Out of scope | Penetration test: Core capability | Red team: Core capability | Hardening review: Available when included in scope | Continuous monitoring: Available when included in scope | |
| Core capability Reconnaissance & ASM · Penetration test · Red team Available when included in scope Hardening review · Continuous monitoring Out of scope Vulnerability assessment People (social engineering) | ||||||
| Reconnaissance & ASM: Core capability | Vulnerability assessment: Available when included in scope | Penetration test: Core capability | Red team: Core capability | Hardening review: Available when included in scope | Continuous monitoring: Out of scope | |
| Core capability Reconnaissance & ASM · Penetration test · Red team Available when included in scope Vulnerability assessment · Hardening review Out of scope Continuous monitoring Wireless networks & physical security | ||||||
| Reconnaissance & ASM: Core capability | Vulnerability assessment: Available when included in scope | Penetration test: Available when included in scope | Red team: Available when included in scope | Hardening review: Available when included in scope | Continuous monitoring: Out of scope | |
| Core capability Reconnaissance & ASM Available when included in scope Vulnerability assessment · Penetration test · Red team · Hardening review Out of scope Continuous monitoring OT, IoT & embedded systems | ||||||
- Core capability
- Available when included in scope
- Out of scope
The matrix is indicative. Exact depth, methodology and rules of engagement are agreed during scoping.
Helpful tools
- A.01
See what the report includes
A complete sample report with evidence-backed findings from Critical to Low, CVSS scoring, OWASP mapping and a prioritized remediation plan.
Sample report - A.02
Create a scoped brief in one minute
Select the engagement type, targets and compliance requirements to create a brief you can send directly to us.
Scope a test