Practice
Our services.
We take a limited number of engagements a year, so each is led by a senior practitioner. Scoping costs nothing, and you have a fixed price before work starts.
Adversary Simulation
Penetration testing, red-teaming, purple-teaming and assumed-breach operations against your actual threat model. Rules of engagement are agreed up front, and we brief your defenders live (purple team) or at the end (red team), whichever you choose.
- Penetration testing (application, network, cloud, mobile)
- External & internal red-team engagements
- Assumed-breach & ransomware tabletop exercises
- Detection validation & detection engineering
Architecture, Hardening & Policy
We review cloud estates, engineering workflows and network boundaries, then write the standards that keep them in place. You get changes your own team can maintain.
- Cloud security review (AWS · GCP · Azure)
- SDLC, supply-chain & CI/CD hardening
- Security policy & standards authorship
Board & Executive Counsel
We prepare executives for board conversations, translate technical risk into decisions the business can actually act on, and offer steady counsel on priorities.
- Security leadership on retainer or for a defined term
- Board briefings & regulator preparation
- Independent security review ahead of acquisitions or investments
- Crisis support
Awareness & Secure Development
Training delivered by the same people who run our tests, built from findings in real engagements.
- Security awareness programmes, tailored by role
- Secure development coaching (threat modelling, code review)
- Phishing drills, tabletop exercises & developer training
Retainer
An agreed number of days per year for testing, review and advice. Priced annually.
Fixed engagement
A defined piece of work, a defined outcome. Ideal for red-team exercises, architecture reviews and programme design.
Advisory session
A half-day on one specific question — an architecture decision, an incident, a vendor assessment. Fixed fee.