Cyber Security
Security that holds up on a bad day.
Zero Trust architecture, compliance readiness, and detection engineering — designed around how your organisation actually works, and tested against how attackers actually behave.
200+
Assessments run
< 15 min
Median detection time
0
Reportable breaches
24/7
Monitoring coverage
Why posture slips
Three gaps that survive every audit
Compliance and security overlap, but they are not the same thing. These gaps pass audits and fail incidents.
Findings without exploitability
A scanner returns nine hundred criticals. Nobody can act on nine hundred criticals, so the report is filed and the two that mattered are still open.
- Severity from CVSS alone, not your context
- No validation that the finding is reachable
- Remediation unpriced, so it never gets scheduled
Identity is the actual perimeter
Network controls get the budget while standing privilege, stale service accounts and unrotated keys quietly provide a straight path in.
- Admin rights held permanently rather than requested
- Service accounts nobody can name an owner for
- Break-glass procedure never tested
Detection nobody has rehearsed
A SIEM ingesting everything and alerting on nothing useful. The first genuine test of the response plan is the incident itself.
- Alert volume high enough that analysts tune out
- Coverage gaps invisible without adversary emulation
- Playbooks written once and never executed
Capabilities
Coverage across the whole control surface
Assessment tells you where you stand. These are the engagements that move you.
Posture assessment
A structured review against a recognised framework, with findings ranked by exploitability and business impact rather than by scanner severity.
- Framework-mapped findings
- Exploitability ranking
- Costed remediation plan
Identity & access
The control plane that matters most. Single sign-on, conditional access, privileged access management, and a joiner-mover-leaver process that actually runs.
- SSO and MFA rollout
- Privileged access vaulting
- Access recertification
Zero Trust architecture
Segmentation, device posture, and per-request authorisation, sequenced so the organisation can keep working while it is implemented.
- Micro-segmentation
- Device posture checks
- Policy decision points
Detection engineering
Detections written against the techniques relevant to your estate, tested against simulated activity, and tuned so the alert queue stays credible.
- ATT&CK-mapped coverage
- Detection-as-code
- False-positive budgets
Incident response
Retainer-backed response with a plan that has been exercised, plus the forensics and communications support a serious incident actually requires.
- Exercised runbooks
- Forensic readiness
- Regulator communications
Compliance readiness
ISO 27001, SOC 2, PCI DSS, and sector-specific regimes — evidence generated by the pipeline rather than assembled by hand the month before an audit.
- Control mapping
- Automated evidence
- Audit support
Defence anatomy
Four control layers, tested against a real adversary path
Controls are only worth what they demonstrably stop. Each layer below is validated by emulation rather than by a tick in a spreadsheet.
Identity and access
Zero-standing privilege
Admin rights requested just in time, approved, time-boxed and logged.
Strong authentication
Phishing-resistant factors on every administrative and remote path.
Service account hygiene
Every non-human identity owned, scoped and rotated on a schedule.
Tested break-glass
An emergency path that has been exercised, not just documented.
Infrastructure and workload
Segmentation
Blast radius bounded so one compromised host does not reach the crown jewels.
Hardened baselines
CIS benchmarks applied by policy and verified continuously, not at audit.
Secrets management
Credentials issued dynamically, never committed, rotation automated.
Patch cadence
Exposure windows measured and reported rather than assumed.
Application and supply chain
Pipeline gates
SAST, SCA and secret scanning failing the build rather than filing a ticket.
Dependency provenance
SBOM generated per release, with known-vulnerable transitive deps surfaced.
Threat modelling
Run at design time on the systems that would actually hurt to lose.
Runtime protection
Applied where the workload warrants it, not everywhere by default.
Detection and response
Detection as code
Sigma rules in version control, reviewed and tested like any other code.
Coverage mapping
Detections mapped to adversary techniques so gaps are visible.
Rehearsed playbooks
Response executed in exercises before it is executed under pressure.
Purple teaming
Emulation run with your defenders in the room, tuning as they go.
We do not report a finding we have not validated. Every item on the remediation plan comes with a demonstrated path, a business impact, and an estimate in engineering days so it can be scheduled like any other work.
Our approach
What separates security that works
Prioritisation
Ranked by what an attacker would actually do
A scanner will hand you nine hundred findings sorted by CVSS. That list is nearly useless for deciding what to fix on Monday. We rank by reachable attack path against your specific estate.
- Findings validated by hand before they reach your backlog
- Attack paths traced end to end, not reported as isolated issues
- Remediation costed so the trade-off is an informed business decision
- A short list of what to fix first, and an explicit list of accepted risk
Design
Controls people can work with
Security that obstructs the work gets routed around, and a routed-around control is worse than no control because it creates false assurance. We design for the actual workflow.
- Controls piloted with the teams who will live with them
- Break-glass paths designed, documented, and monitored
- Friction budgeted and measured, not assumed to be free
- Exceptions time-boxed with a named owner and review date
Assurance
Tested, not asserted
Every control we implement gets exercised. Detections are validated against simulated technique execution, response plans are run as tabletop and live exercises, and backups are restored rather than reported as green.
- Purple-team exercises validating detection coverage per technique
- Incident response rehearsed with the executives who would be involved
- Backup restoration tested end to end on a schedule
- Findings from every exercise tracked to closure
Assurance options
Which kind of test actually answers your question
These are not interchangeable, and buying the wrong one is the most common way a security budget produces no security.
| Exercise | Question it answers | Duration | Disruption | Best used when |
|---|---|---|---|---|
| Posture assessmentUsual start | Where do we stand across identity, cloud, app and detection? | Three weeks | None — read-only | You need a ranked, costed plan |
| Vulnerability scanning | What known issues exist across the estate? | Continuous | Minimal | You need coverage and trend, not depth |
| Penetration test | Can a skilled attacker breach this specific scope? | One to three weeks | Low, scheduled | A system is going live or under contract obligation |
| Red team | Would we detect and stop a determined adversary? | Four to eight weeks | Deliberately unannounced | Detection is mature enough to be worth testing |
| Purple team | How fast can we close the gaps we just found? | One to two weeks | Collaborative by design | You want capability uplift, not just a score |
| Tabletop exercise | Do our people know what to do at 03:00? | One day | None — discussion based | Plans exist but have never been rehearsed |
Posture assessment
Usual start- Question it answers
- Where do we stand across identity, cloud, app and detection?
- Duration
- Three weeks
- Disruption
- None — read-only
- Best used when
- You need a ranked, costed plan
Vulnerability scanning
- Question it answers
- What known issues exist across the estate?
- Duration
- Continuous
- Disruption
- Minimal
- Best used when
- You need coverage and trend, not depth
Penetration test
- Question it answers
- Can a skilled attacker breach this specific scope?
- Duration
- One to three weeks
- Disruption
- Low, scheduled
- Best used when
- A system is going live or under contract obligation
Red team
- Question it answers
- Would we detect and stop a determined adversary?
- Duration
- Four to eight weeks
- Disruption
- Deliberately unannounced
- Best used when
- Detection is mature enough to be worth testing
Purple team
- Question it answers
- How fast can we close the gaps we just found?
- Duration
- One to two weeks
- Disruption
- Collaborative by design
- Best used when
- You want capability uplift, not just a score
Tabletop exercise
- Question it answers
- Do our people know what to do at 03:00?
- Duration
- One day
- Disruption
- None — discussion based
- Best used when
- Plans exist but have never been rehearsed
Delivery
How a security engagement runs
Assessment first, always — we will not sell you controls before we know what you need.
- 01
Weeks 1–3
Assessment
Technical review, configuration analysis, and interviews. Output is a ranked, validated findings register with a costed remediation plan.
- 02
Weeks 4–6
Quick wins
The high-impact, low-disruption items — MFA gaps, exposed services, stale privileged accounts — closed before the larger programme starts.
- 03
Ongoing
Architecture programme
Identity, segmentation, and detection delivered in increments, each validated by exercise before the next begins.
- 04
Continuous
Monitoring & response
Detection coverage maintained against evolving techniques, with response retainer and quarterly purple-team exercises.
- 05
Annually
Re-assessment
The full assessment re-run against the same framework so improvement is measurable rather than asserted.
What you get
What the engagement actually hands over
Evidence a board can read and a plan an engineering manager can schedule. Both, not one or the other.
Assessment
- Validated findings with a demonstrated exploitation path
- Risk ranked by exploitability and business impact
- Remediation plan costed in engineering days
- Executive summary written for a non-technical board
Engineering
- Hardened baselines applied as policy-as-code
- Pipeline security gates configured and tuned
- Detection rules committed to your repository
- Identity model with just-in-time privilege implemented
Readiness
- Incident response playbooks rehearsed in a live exercise
- Detection coverage map against adversary techniques
- Tabletop findings with owners and dates
- Audit evidence pack aligned to your frameworks
Toolchain
Frameworks and tooling
Vendor-neutral. We work with what you have where it is adequate, and say so where it is not.
Frameworks
NIST CSF 2.0, ISO 27001, CIS Controls, MITRE ATT&CK, and SOC 2 — mapped to each other so evidence is collected once.
Identity
Entra ID, Okta, Ping, and Keycloak, with CyberArk or HashiCorp Vault for privileged access and secrets.
Detection
Microsoft Sentinel, Splunk, Elastic, and Wazuh, with Sigma rules and detection-as-code pipelines.
Cloud & app
CSPM and CNAPP tooling, SAST and SCA in CI, and runtime protection where the workload warrants it.
Engagement models
Ways to engage the security practice
Assessment first in almost every case — buying monitoring before you know your gaps is how organisations end up paying to watch an unlocked door.
Posture assessment
Fixed fee
Three weeks, quoted up front
Where you stand across identity, cloud, application and detection, with a costed plan.
- Validated findings, not raw scanner output
- Ranked by exploitability in your context
- Remediation estimated in engineering days
- Board summary and technical detail
Remediation programme
Project
Phased against the ranked plan
Engineers implementing the fixes, working down the plan in priority order.
- Identity, hardening and pipeline work delivered
- Detection built as reviewed code
- Progress measured against the original findings
- Re-test on completion included
Managed detection
Retainer
Monthly, 24/7 coverage
Continuous monitoring and response with a named team and an agreed SLA.
- 24/7 triage and response
- Detection tuning as your estate changes
- Quarterly purple-team exercise
- Monthly reporting against agreed metrics
Questions
Questions worth asking any security supplier
Including the ones that make suppliers uncomfortable. Ask us these on the call.
Testing and findings
Will you hand us a scanner report with nine hundred criticals?
No. We validate before we report, which means demonstrating that a finding is reachable and exploitable in your environment. A typical assessment produces a ranked list in the tens, not the hundreds, and every item carries an estimate in engineering days so it can be scheduled rather than admired.
Should we buy a red team?
Probably not yet, if you are asking. A red team answers 'would we detect a determined adversary' — a question worth money only once you have detection worth testing. Most organisations get far more from a posture assessment followed by a purple-team exercise, which builds the capability rather than just scoring it.
Do you test our third parties?
We assess your exposure through them — integration surface, data shared, credentials issued, and what their compromise would give an attacker. Testing their systems requires their authorisation, which we will help you obtain where the contract allows it. We will not test a system we do not have written permission to test.
Compliance and operations
Does this make us compliant?
It makes you defensible, which usually makes compliance straightforward. We map controls to the frameworks you are answerable to and produce the evidence pack, but we will also tell you where a framework's tick-box and your actual risk diverge. Passing an audit and surviving an incident are related, not identical.
Can you work with our existing MSSP?
Yes, and we frequently do. A common engagement is assessing the detection coverage an incumbent provides, which is uncomfortable but useful. We are happy to hand tuned detections to your existing provider rather than replace them.
What happens if you find an active compromise?
We stop, tell you immediately through a pre-agreed escalation path, and switch to incident response. That contact and the decision rights are agreed in writing before the engagement starts, precisely so nobody is deciding who to call while the clock is running.
Find out where you actually stand.
A three-week posture assessment with validated findings, ranked by exploitability, and a remediation plan costed in engineering days.