Cybersecurity & compliance
Find the holes before someone else does
Security audits, hardening and compliance readiness — with findings ranked by what an attacker could actually do with them, not by what a scanner flagged.
All testing is scoped and authorised in writing before anything starts.
What we mean by security work
Our security practice is defensive. We assess systems our clients own or have authorised us in writing to test, we fix what we find, and we help you prove to auditors and customers that you're doing it. Every engagement starts with a signed scope defining exactly which systems are in and out.
The most common finding is not an exotic vulnerability. It's an admin interface reachable from the internet, credentials in a repository, a database with a default password, a backup nobody has ever restored, or an ex-employee's access that was never revoked. Unglamorous, and responsible for the overwhelming majority of real incidents.
The compliance dimension has sharpened too: data-protection obligations, sector rules for anyone touching payments, and enterprise customers who now send security questionnaires before they'll sign.
Three layers, three different exercises
Buying the wrong one is common — a network scan won't find a broken permission check in your application.
| Infrastructure | Application | Process & people | |
|---|---|---|---|
| Covers | Servers, network, cloud config, access | Your code: auth, permissions, input handling | Onboarding, offboarding, secrets, response |
| Typical findings | Exposed services, unpatched systems, over-broad IAM | Broken access control, injection, insecure direct references | Shared logins, stale accounts, no tested backup |
| How it's tested | Config review plus authorised scanning | Code review plus manual testing of flows | Interviews and evidence review |
| Automatable? | Largely | Partly — logic flaws need a human | No |
| Most often skipped | Rarely — it's the easiest to buy | Frequently | Almost always |
Application-layer access control is where we find the most serious issues, and it's the layer automated scanners are worst at.
What we do
Six services. All defensive, all under written authorisation.
Security audit
A structured review of infrastructure, application and access — producing findings ranked by exploitability, each with a concrete remediation and an effort estimate.
Infrastructure hardening
Closing what the audit found: network boundaries, least-privilege access, patch management, secrets handling and logging that would actually help during an incident.
Secure development support
Threat modelling for new features, security-focused code review, and dependency scanning wired into CI so problems surface at the pull request.
Compliance readiness
Preparing for data-protection obligations, customer security questionnaires and sector requirements — with the evidence trail assembled as you go rather than reconstructed at audit.
Incident response planning
A written plan, defined roles, and a rehearsal. The worst time to work out who calls the bank is while an incident is running.
Ongoing monitoring
Log aggregation, alerting on the signals that matter, dependency and certificate expiry watching — as part of a managed retainer.
The controls that prevent most incidents
Unfashionable, cheap, and collectively more effective than any product you can buy. We check all of these first.
Multi-factor authentication everywhere
On email, cloud consoles, VPN, repositories and admin panels. The single highest-return control available, and still routinely incomplete.
Least privilege, reviewed
People and services get the access the job needs, and access is reviewed when roles change. Most breaches escalate through permissions nobody meant to grant.
Patching with a deadline
A defined window for critical patches and a way to know what's unpatched. 'We update regularly' is not a control.
Backups that are restored
Offline or immutable copies, and a restore actually performed on a schedule. Ransomware makes the difference between a bad week and an extinction event.
Secrets out of code
Credentials in a secret manager, not in repositories, config files or a spreadsheet. Plus rotation when someone leaves.
Logs you could investigate with
Centralised, retained long enough to matter, and covering authentication and privileged actions. Without them, an incident becomes guesswork.
If an audit finds these six in place, you're already ahead of most organisations we assess.
Compliance we help with
We prepare you and produce the evidence. Formal certification audits are performed by accredited third parties, not by us.
GDPR / data protection
Personal-data mapping, lawful-basis documentation, retention rules, breach-notification readiness and processor agreements.
ISO 27001 readiness
Gap analysis against the controls, policy drafting and evidence collection — so the certification audit isn't the first time anyone checks.
SOC 2 readiness
Control design and evidence automation for companies whose enterprise customers require it. Usually driven by a stalled sales cycle.
PCI DSS scope reduction
Most businesses should be reducing scope rather than achieving compliance across it. We architect card data out of your systems where possible.
Customer security questionnaires
The unglamorous reality of B2B sales. We help you answer honestly, and fix what the honest answers reveal.
If something has already happened
Four immediate steps. If you're in an active incident, contact us and say so — those enquiries are triaged first.
Contain
Limit the blast radius: isolate affected systems, revoke suspect credentials and sessions, and stop the bleeding before investigating.
Preserve
Capture logs, images and evidence before anything is rebuilt. Wiping and restoring destroys the information needed to know what actually happened.
Assess
What was accessed, what was taken, and how they got in. This determines your notification obligations, which are time-bound.
Recover & close
Restore from known-good backups, close the entry route, rotate everything, and write up what changes so it can't recur the same way.
FAQ
Security questions
Do you do penetration testing?
We perform authorised security assessments on systems our clients own, under a signed scope that defines exactly what is in and out and a defined testing window. We don't test systems without the owner's written authorisation, and we don't offer offensive services against third parties.
How long does a security audit take?
A focused audit of one application and its infrastructure is typically two to three weeks including the report. A full-estate assessment takes four to eight. You get findings as we go for anything critical — we won't sit on a serious issue until the report is finished.
What do we actually receive?
A findings report with each issue ranked by real exploitability, a description of the impact in business terms, a concrete remediation and an effort estimate. Plus an executive summary you can share with a board or a customer. Written to be actioned, not to be impressive.
Can you fix what you find?
Yes, and most clients want that. We're clear about the incentive that creates, so findings are always evidenced with reproduction steps — you can hand the report to anyone and get the same fixes. Remediation is quoted separately from the audit.
We're small. Is this overkill?
The basics aren't. MFA, least privilege, patching, tested backups and secrets management apply at every size and cost mostly discipline rather than money. A full audit programme may well be premature — we'll tell you if it is, and point you at the six controls above instead.
Do we need formal certification?
Only if a customer, regulator or insurer requires it. Certification is expensive and proves a management system exists, not that you're secure. If nobody is asking, spend the money on the controls first — we'll say so rather than sell you a readiness programme you don't need.
Related services
What are you most worried about?
An honest answer to that question is the best possible start. If you're dealing with an active incident, say so and we'll prioritise it.
