Home / Services

Security services built around evidence

Six services covering the full surface — offensive testing to uncover flaws, defensive coverage to keep them out. Every engagement ends with a report your engineers can act on and a free retest.

Penetration testing

Simulated attacks against your live environment

  • External and internal network testing
  • Web and mobile application testing
  • API and authentication logic testing
  • Social engineering on request
Request this service →

Vulnerability assessment

Breadth-first discovery across your estate

  • Authenticated and unauthenticated scanning
  • Manual validation to remove false positives
  • Business-impact prioritisation
  • Remediation roadmap by severity
Request this service →

Data theft prevention

Stop information leaving before it does damage

  • Data flow and exposure mapping
  • Exfiltration path testing
  • Access control review
  • Detection and alerting design
Request this service →

Malware protection

Defeat advanced and evasive payloads

  • Advanced malware protection deployment
  • Sandboxing and detonation analysis
  • Global threat intelligence feeds
  • Real-time blocking policy tuning
Request this service →

Network security

Harden the perimeter and everything behind it

  • Firewall and segmentation review
  • Host and device configuration audit
  • Datacenter and perimeter security
  • Network risk assessment
Request this service →

Cloud security

Secure what you run on AWS, Azure and GCP

  • Cloud configuration review
  • Identity and access management audit
  • Storage exposure and leakage checks
  • Container and workload hardening
Request this service →

Ransomware recovery

Emergency response when your files are encrypted

  • Immediate containment and network isolation
  • Ransomware strain identification
  • Recovery from backups and shadow copies
  • Forensics: entry point, dwell time, data exfiltration
  • Regulatory reporting support (GDPR 72-hour rule)
  • Hardening to prevent re-encryption
Request this service →
What's included

Every engagement, no exceptions

These are not add-ons or upsells. They come with every service we run.

1

Rules of engagement

Agreed in writing before any testing starts, including windows and escalation contacts.

2

Proof of concept

Reproducible evidence for every finding, captured safely without exfiltrating your data.

3

Executive summary

A board-ready overview alongside the technical detail your engineers need.

4

Free retest

We verify your patches closed the gap and reissue the report at no extra cost.

Engagement specifications

What each engagement involves

Indicative timelines and coverage. Exact scope and duration are confirmed in writing before any testing begins.

EngagementTypical durationCoverageDeliverable
External network test3–5 days Perimeter hosts, exposed services, VPN and mail gateways, DNS configuration Findings report + executive summary + free retest
Internal network test5–8 days Active Directory, segmentation, lateral movement, privilege escalation paths Attack path diagram + prioritised remediation plan
Web application test4–7 days OWASP Top 10, business logic, authentication and session handling, access control Per-finding proof of concept + developer fix guidance
API / GraphQL test3–5 days Authorisation flaws, rate limiting, injection, schema introspection, mass assignment Annotated request/response evidence
Cloud configuration review3–6 days IAM policies, storage exposure, network controls, logging, container workloads Benchmark-mapped findings + hardening checklist
Emergency incident responseImmediate, 24/7 Containment, entry-point identification, eradication, service restoration Incident timeline + root cause + hardening actions
< 24hResponse to emergency reports, any time of day
CVSS v3.1Every finding scored against an industry standard
100%Findings manually validated before reporting
FreeRetest included after your team ships patches
Already hacked? · 24/7 emergency line

Website hacked, data leaked or systems locked? We take over immediately.

Ransomware, defaced pages, crypto-mining scripts, spam sent from your domain, customer data dumped online, or admin access you have lost — tell us what happened and our response team moves at once. We contain the attacker, close the entry point, remove the malicious code and restore your services within hours, then tell you exactly how they got in.

Containment within the first hour Malware & backdoor removal Root cause & entry point report Hardening so it cannot happen twice
Get emergency help

Ready to find out where you stand?

Tell us what you'd like tested and we'll scope an engagement — with a fixed price agreed in writing and a free retest once you've shipped the fixes.

Request an assessment