Security / Cyber risk assessment & advisory

Understand where
you're vulnerable.

We investigate your digital systems the way an attacker would, uncover the weaknesses that matter and turn security findings into decisions your leadership can act on.

  • 15+ yearsSenior cybersecurity lead on every engagement
  • Risk-rankedBy business impact, not severity score alone
  • ActionableDecisions leadership can sign off
01 / The threat

No genius required.
Just one open door.

Most breaches start with something ordinary: an unpatched device, an exposed login, a supplier with too much access. The question is not whether those doors exist, but whether you find them first.

What the 2026 breach data shows
31%

Exploits are now the top way in

Exploited vulnerabilities overtook stolen credentials as the leading initial access route.

48%

Of breaches involved a third party

Up 60% in a year. Your suppliers' weaknesses are now your weaknesses.

43

Days median time to patch

Patching is slowing down while attackers exploit new flaws faster than ever.

$4.99M

Global average cost of a breach

A record high, and $11.5M on average in the United States.

Sources: Verizon 2026 Data Breach Investigations Report, IBM Cost of a Data Breach Report 2026.

02 / What we do

See your business
the way attackers do.

From a one-off assessment to an ongoing advisory relationship, every service is led by a senior practitioner and ends in a clear, prioritised plan.

01 / Assess

Cyber risk assessment

A structured review of your systems, controls, people and suppliers, with every risk scored by likelihood and business impact so leadership knows where to invest first.

  • Risk register
  • Business impact
  • Board-ready
02 / Test

Penetration testing

Manual, authorised attacks on your networks, applications and APIs to prove what is genuinely exploitable.

03 / Cloud

Cloud and configuration review

AWS, Azure and Google Cloud checked for the misconfigurations behind most cloud breaches.

04 / Applications

Application and API security

Web apps and APIs reviewed against the OWASP Top 10, with code-level fixes.

05 / Monitor

Attack surface monitoring

Continuous discovery of new domains, services and exposures between assessments.

06 / Advise

Security advisory and compliance readiness

Ongoing senior guidance without a full-time hire: security roadmaps, policies, incident response planning and supplier risk, plus readiness for the frameworks your customers and regulators expect.

  • SOC 2
  • ISO 27001
  • NIST CSF 2.0
  • HIPAA
  • GDPR
Also in scope
  • Incident response planning
  • Vendor risk reviews
  • Phishing simulation
  • Email security (SPF, DKIM, DMARC)
  • Security awareness training
03 / How we report

From technical finding
to business decision.

A list of CVEs helps no one in the boardroom. Every finding we report is translated into what it means for the business and the decision it needs, with the effort to fix it.

What we found

A staging admin login is reachable from the internet, with no MFA and a predictable username.

What it means

Anyone who guesses or buys one password gets direct access to customer records.

The decision

Move it behind SSO or VPN, enforce MFA and retire the staging host.

Business risk
Effort to fix
Time to fixHours
What we found

Firmware is three releases behind and matches a vulnerability on CISA's Known Exploited list.

What it means

A known, actively used entry point for ransomware groups, sitting on your network edge.

The decision

Patch this week, then put edge devices on a 72-hour patch commitment.

Business risk
Effort to fix
Time to fixDays
What we found

A storage bucket holding invoice exports allows anonymous listing and download.

What it means

Customer financial data is one URL away from a reportable breach under GDPR.

The decision

Block public access account-wide, rotate links and review 90 days of access logs.

Business risk
Effort to fix
Time to fixHours
What we found

Your managed IT provider uses one shared admin account across clients, without MFA.

What it means

A breach at your supplier becomes a breach at you, with no way to trace who did what.

The decision

Require named accounts, MFA and access logging as contract terms.

Business risk
Effort to fix
Time to fixWeeks
04 / How we work

Test safely.
Fix what matters.

A clear scope and rules of engagement up front, rigorous testing in the middle and a retest at the end, so you can prove the risk is actually gone.

What we assess
External surfaceDomains, exposed services and forgotten assets
Network & edgeFirewalls, VPNs and remote access
CloudAWS, Azure and Google Cloud configuration
Apps & APIsOWASP Top 10 and business logic flaws
Identity & accessMFA, SSO, privileged and shared accounts
Email & domainSPF, DKIM, DMARC and spoofing risk
Rules of engagement
  • Written authorisationSigned scope, targets and testing windows before anything starts.
  • Safe by defaultNo destructive tests on production without your explicit approval.
  • Criticals reported immediatelyYou hear the same day, not in the final report.
  • Confidential handlingFindings and any data encountered stay encrypted and need-to-know.
  • Retest includedWe confirm every fix so the risk is closed, not assumed.
05 / What you receive

Clarity for the board.
Fixes for the team.

One assessment, written for two audiences. Leadership gets risk in business terms. Engineering gets reproducible findings and the exact steps to close them.

Assessment deliverablesYours to keep
  • Executive risk briefExposure, top risks and decisions on two pages
  • Technical findingsEvidence, reproduction steps and fixes
  • Risk registerLikelihood, impact and owner for each risk
  • Remediation roadmapSequenced by risk reduction per effort
  • Retest reportVerified status of every fixed finding
  • Framework mappingAligned to NIST CSF, ISO 27001 or SOC 2
06 / Questions

Straight answers.

What leadership, IT and compliance teams usually ask before an assessment.

How is this different from an automated vulnerability scan?

Scanners list known issues by severity score, often hundreds of them. We validate what is genuinely exploitable, chain findings the way an attacker would and rank them by impact on your business, so you fix the handful that matter first instead of chasing noise.

Will testing disrupt our systems?

Every engagement runs under written authorisation, an agreed scope and agreed testing windows. Anything that could affect availability is discussed with you first, and production testing is designed to be safe by default.

Do you help with SOC 2, ISO 27001, HIPAA or GDPR?

Yes, with readiness and gap assessments, control design and the evidence auditors ask for. Certification itself is issued by an accredited auditor, and we prepare you so that audit goes smoothly.

What happens if you find something critical?

We tell you immediately, not in the final report. Critical findings come with a containment recommendation the same day, and we stay available while your team acts on it.

How often should we be tested?

At least annually and after any significant change, such as a new product, a cloud migration or an acquisition. Between assessments, continuous exposure monitoring catches new risks as they appear.

We are a mid-sized company. Are we really a target?

Most attacks are automated and opportunistic. They look for an exposed service or an unpatched device, not a company name. That makes mid-sized organisations, with valuable data and leaner security teams, some of the most frequent victims.

07 / Start your assessment
Taking on new assessments

Find the open doors
before someone else does.

Tell us what you run, what you're worried about and any compliance goals. We'll come back with a scoped assessment plan, rules of engagement and a realistic timeline.

Senior-led15+ years in cybersecurity on every engagement.
Business-ranked riskPriorities your leadership can act on.
Retest includedEvery fix verified, not assumed.