How we think about the work
Security that holds when we leave
We don't sell services in isolation. We build a posture where testing feeds detection, detection feeds compliance, and every finding actually gets closed — measured by the retest.
Plenty of firms will run whichever test you ask for and send a report full of criticals. We work the other way around. We start with your environment, your data, and the threats that realistically matter to a business like yours, and only then recommend where to spend. Some clients need a hard penetration test to find the way in. Others are drowning in alerts and need a SOC that actually triages them. The plan follows the risk, not the product list.
The way we price reflects the way we work. A point-in-time assessment is a fixed fee with a free retest built in, because a fix you can't verify isn't a fix. Managed detection is a monthly retainer scoped to your estate, with named analysts you can actually reach. And if the scope changes, we agree it before anything moves. The figures below are starting points — the real proposal comes once we've seen your systems and understand where the exposure really sits.