Engagements

What we test, and what you get back.

Every engagement below is scoped individually and authorized in writing. The deliverable is always the same shape: proof of impact, reproduction steps, a fix, and a retest once you have applied it.

Network penetration testing

External perimeter · Internal / assumed breach · Segmentation validation

The classic engagement, run two ways. External starts from the public internet with nothing but your domain name: we enumerate what you actually expose, not what the asset inventory claims, and work inward. Internal starts from a position an attacker reaches on day two — a compromised laptop, a guest VLAN, a contractor's VPN account — and answers the question that matters to your insurer: how far does that get them?

Domain escalation paths, credential reuse, unmanaged hosts, flat networks, and stale service accounts are where most internal tests end up. We chain them the way an operator would rather than listing them separately, because the chain is the risk.

  • Attack-path narrative from initial foothold to highest privilege reached
  • Per-finding evidence: command, output, screenshot, affected assets
  • Segmentation test results where PCI or regulatory scope applies
  • Prioritized remediation table with owners and effort estimates
  • Retest and clean-state attestation letter

Web application & API testing

Authenticated · Multi-role · OWASP WSTG aligned

Testing done from inside the application with real credentials for every role you have, because the interesting bugs are almost never on the login page. Broken access control between tenants, IDORs on object identifiers, server-side request forgery in the file-import feature, business logic that lets an order be repriced after approval — these are the findings that end up mattering, and none of them are visible to an unauthenticated scan.

APIs get the same treatment as the UI. If your mobile app or your partner integrations talk to endpoints the browser never touches, those endpoints are in scope and are usually where the weakest authorization lives.

  • Full OWASP WSTG coverage matrix, including what was tested and found clean
  • Cross-role and cross-tenant authorization matrix
  • Reproducible proof-of-concept for every finding, with request captures
  • Remediation guidance written for the framework you actually use
  • Developer walkthrough session and retest

Cloud & identity assessment

AWS · Azure / Entra ID · Google Cloud · Microsoft 365

Cloud breaches are rarely exploits; they are permissions. We review the identity graph — roles, trust policies, service principals, federated logins, and the long tail of access keys nobody has rotated since the migration — and then demonstrate the privilege escalation paths rather than describing them theoretically.

Public storage, unauthenticated metadata access, over-broad cross-account trusts, conditional access gaps, and legacy authentication left enabled in Microsoft 365 are the recurring offenders. Findings are mapped to the provider's own hardening benchmarks so your platform team can act without translation.

  • Identity and privilege-escalation path graph
  • Public exposure inventory across storage, compute, and secrets
  • CIS Benchmark and provider best-practice deviation list
  • Logging and detection gap analysis (what you would not have seen)
  • Infrastructure-as-code remediation snippets where applicable

Social engineering & phishing

Email · Voice · Physical pretext · Measured, not theatrical

Simulated campaigns designed to measure something useful. Click rate alone tells you almost nothing; what matters is whether credentials were submitted, whether multi-factor held, whether anyone reported it, and how long the report took to reach someone who could act.

Campaigns are agreed with a named sponsor in advance, and we design them to avoid the outcomes that damage trust — no fake bonus notices, no fake layoffs. The goal is a control measurement your staff can be told about afterwards without feeling ambushed.

  • Click, submit, and report rates with time-to-report distribution
  • Multi-factor bypass attempt results
  • Detection timeline: what your tooling caught, and when
  • Department-level breakdown for targeted follow-up training
  • Recommended awareness content built from your actual results

Wireless & physical access

802.11 · Guest isolation · Badge, lock, and tailgate testing

Wireless testing covers rogue access points, evil-twin captive portal attacks against your corporate SSID, pre-shared key recovery, and — most commonly useful — whether your guest network is genuinely isolated from production or merely on a different VLAN with a route between them.

Physical assessment, where scoped, tests badge cloning, door and lock bypass, tailgating, and what an unescorted visitor can reach from a conference-room network port. Always with a signed authorization letter carried by the tester.

  • Wireless survey with rogue and misconfigured access point inventory
  • Guest-to-production isolation test results
  • Physical entry narrative with photographic evidence
  • Reception and staff challenge-response observations
  • Practical control recommendations sized to the site

Post-incident resolution & hardening

Root cause · Remediation programme · Detection uplift

The work that begins once the immediate fire is out — and the reason most organizations get breached twice by the same route. A response engagement ends with containment; resolution ends when the conditions that allowed it no longer exist.

We take the incident findings (ours or another firm's) and turn them into a sequenced programme: what has to change this week, what needs a project, and what is an accepted risk with a named owner who accepted it. Then we build the detection you were missing, so the same technique surfaces in minutes next time instead of months.

  • Root-cause analysis distinguishing initial access from what let it spread
  • Sequenced remediation roadmap with owners, dates, and effort
  • Detection rules and logging coverage mapped to MITRE ATT&CK
  • Incident response plan authored or rewritten to fit your team
  • Tabletop exercise to prove the plan works before you need it
  • Verification testing against the original attack path

We are equally willing to pick this up after someone else's incident report. Bring the report; we will tell you honestly whether it is complete enough to act on.

Security programme advisory

Fractional guidance for teams without a full-time security lead

For organizations that have outgrown "the IT guy handles security" but cannot yet justify a full-time CISO. Recurring advisory time spent on the decisions that are expensive to get wrong: architecture reviews before you build, vendor security questionnaires that need a real answer, cyber insurance applications, and the security clauses in contracts your clients are asking you to sign.

  • Control gap assessment against NIST CSF 2.0 or CIS Controls v8
  • Twelve-month prioritized security roadmap with budget bands
  • Policy set written to be usable rather than to be filed
  • Vendor and client security questionnaire support
  • Standing advisory hours for architecture and procurement decisions

Before you ask

Questions we get in the first call.

If yours is not here, ask it directly — a straight answer costs nothing and it is how we would want to be treated.

How much does a penetration test cost?

It depends almost entirely on scope — the number of live hosts, application roles, cloud accounts, and whether retesting and remediation support are included. We quote a fixed price after a short scoping call rather than publishing a rate card that would be wrong for most people reading it. If your budget is fixed, say so up front and we will tell you what fits inside it.

How long does an engagement take?

A focused external network test is typically one to two weeks from kickoff to report. A multi-role application assessment or a combined internal and cloud engagement usually runs three to four. Incident response starts the same day, and often the same hour.

Will testing take our systems down?

Testing is conducted to avoid disruption, and denial-of-service techniques are excluded by default unless you specifically ask for them in scope. Fragile legacy systems are flagged during scoping and handled with agreed constraints. You get an escalation contact who is reachable throughout the testing window.

Do you need production access?

For application testing we prefer a staging environment that mirrors production, with representative data. Where only production exists, we test it with agreed restrictions and clear rollback expectations. Either way, anything we create during testing is documented so you can remove it afterwards — and we provide that cleanup list as part of the report.

What happens if you find something critical mid-test?

You hear about it that day, not in the report four weeks later. Critical findings and any evidence of a pre-existing compromise trigger immediate notification to your named escalation contact, and we will pause testing if continuing would make an active incident harder to investigate.

Is the retest really included?

Yes, for findings from the original scope, within an agreed window after report delivery. A test that ends at the report is a document purchase; a test that ends at a verified fix is a security outcome.

Can you work under our client's NDA and security requirements?

Routinely. We sign client NDAs, work to defined data-handling requirements, and can restrict evidence storage and transmission to meet contractual or regulatory constraints. Raise the requirements during scoping so they are built into the engagement rather than bolted on.

Emergency

If this is not a planning exercise.

Active intrusion, ransomware note, or credentials you know are in someone else's hands — go straight to the response page and start there.