Security consultant reviewing code and network diagrams

Services

What we do, and how it runs.

Four services, three ways to work with us. Clear scope, clear pricing, and a retest that proves the work.

How we think about the work

Security that holds when we leave

We don't sell services in isolation. We build a posture where testing feeds detection, detection feeds compliance, and every finding actually gets closed — measured by the retest.

Plenty of firms will run whichever test you ask for and send a report full of criticals. We work the other way around. We start with your environment, your data, and the threats that realistically matter to a business like yours, and only then recommend where to spend. Some clients need a hard penetration test to find the way in. Others are drowning in alerts and need a SOC that actually triages them. The plan follows the risk, not the product list.

The way we price reflects the way we work. A point-in-time assessment is a fixed fee with a free retest built in, because a fix you can't verify isn't a fix. Managed detection is a monthly retainer scoped to your estate, with named analysts you can actually reach. And if the scope changes, we agree it before anything moves. The figures below are starting points — the real proposal comes once we've seen your systems and understand where the exposure really sits.

Services

Four ways we defend you

Most programs combine two or three of these. We'll recommend the right mix after we've reviewed your environment.

Penetration testing

We break in so real attackers can't.

Automated scanners find the obvious. We test by hand — chaining low-severity issues into real compromise the way an attacker would, across web apps, mobile, cloud, and internal networks. Then we don't just report it: we sit with your engineers to close each path and come back to prove the retest is clean.

  • Web, mobile & API testing
  • Cloud & internal network
  • Manual exploitation & chaining
  • Remediation support & retest

Managed detection & response

A 24/7 SOC with a human on the line.

Alerts nobody reads are worse than no alerts at all. Our security operations centre watches your estate around the clock, hunts for the activity your tools miss, and contains threats in minutes — with an analyst who calls you and explains what's happening, not a queue that fills up overnight.

  • 24/7 monitoring & triage
  • Threat hunting
  • Rapid containment
  • Monthly posture reviews

Compliance & audit readiness

Pass the audit because you're actually secure.

We map SOC 2, ISO 27001, PCI DSS, and HIPAA to controls your team can genuinely operate, then get you audit-ready without turning security into theatre. Done our way, the certificate is the by-product of a posture that would hold up whether or not an auditor were watching.

  • Gap assessment
  • Control design & policy
  • Evidence & audit prep
  • Auditor liaison

Incident response

When it's already happening, we move.

A breach is a bad time to be reading a runbook for the first time. We contain the incident, run the forensics to establish exactly what occurred and how, and get you back to safe operations — then hand you an honest, board-ready account and a plan so the same door never opens twice.

  • 24/7 emergency response
  • Containment & eradication
  • Forensic investigation
  • Board-ready reporting

Engagements

Three ways to work together

Pricing is indicative — every engagement is quoted precisely once we understand your environment and scope.

EngagementAssessmentManagedRetained
Starting pricefrom $12kfrom $6k/moCustom
Best forA point-in-time test with a clear scopeOngoing 24/7 detection and responseA security partner across the whole program
What's included
  • Fixed scope
  • Manual testing
  • Prioritised findings
  • Free retest
  • 24/7 SOC coverage
  • Threat hunting
  • Named analyst team
  • Monthly reviews
  • Testing + SOC + advisory
  • Incident response SLA
  • vCISO access
  • Quarterly board briefings

Process

From first scope to clean retest

Every engagement follows the same four movements. There are no black boxes — you know what we're testing, what we find, and exactly how each issue gets closed.

  1. 01

    Scope

    We agree the targets, the rules of engagement, and what a successful outcome looks like. You'll know precisely what's in and out of scope before a single packet is sent, and we'll flag anything risky up front.

  2. 02

    Test

    Our consultants work by hand, chaining findings the way a real attacker would and keeping you informed of anything critical the moment we find it — never a surprise buried on page forty of a report.

  3. 03

    Report

    You get findings ranked by real business impact, with clear reproduction steps and fixes your engineers can act on. We walk your team and your board through it in plain language, not jargon.

  4. 04

    Retest

    Once you've remediated, we come back and verify each fix at no extra cost. The engagement isn't finished when the report lands — it's finished when the retest comes back clean.

Questions

Before you get in touch

We design every engagement around safe execution. Destructive or high-risk actions are agreed in advance, timed for low-traffic windows, and coordinated with your team in real time. In most cases we test production without any noticeable impact, and where that isn't safe, we work against a staging mirror instead.

Ready when you are

Send us your environment and concerns, and we'll come back with a scoped assessment plan.