Skip to content

Cybersecurity & compliance

Find the holes before someone else does

Security audits, hardening and compliance readiness — with findings ranked by what an attacker could actually do with them, not by what a scanner flagged.

All testing is scoped and authorised in writing before anything starts.

What we mean by security work

Our security practice is defensive. We assess systems our clients own or have authorised us in writing to test, we fix what we find, and we help you prove to auditors and customers that you're doing it. Every engagement starts with a signed scope defining exactly which systems are in and out.

The most common finding is not an exotic vulnerability. It's an admin interface reachable from the internet, credentials in a repository, a database with a default password, a backup nobody has ever restored, or an ex-employee's access that was never revoked. Unglamorous, and responsible for the overwhelming majority of real incidents.

The compliance dimension has sharpened too: data-protection obligations, sector rules for anyone touching payments, and enterprise customers who now send security questionnaires before they'll sign.

Three layers, three different exercises

Buying the wrong one is common — a network scan won't find a broken permission check in your application.

InfrastructureApplicationProcess & people
CoversServers, network, cloud config, accessYour code: auth, permissions, input handlingOnboarding, offboarding, secrets, response
Typical findingsExposed services, unpatched systems, over-broad IAMBroken access control, injection, insecure direct referencesShared logins, stale accounts, no tested backup
How it's testedConfig review plus authorised scanningCode review plus manual testing of flowsInterviews and evidence review
Automatable?LargelyPartly — logic flaws need a humanNo
Most often skippedRarely — it's the easiest to buyFrequentlyAlmost always

Application-layer access control is where we find the most serious issues, and it's the layer automated scanners are worst at.

What we do

Six services. All defensive, all under written authorisation.

Security audit

A structured review of infrastructure, application and access — producing findings ranked by exploitability, each with a concrete remediation and an effort estimate.

Infrastructure hardening

Closing what the audit found: network boundaries, least-privilege access, patch management, secrets handling and logging that would actually help during an incident.

Secure development support

Threat modelling for new features, security-focused code review, and dependency scanning wired into CI so problems surface at the pull request.

Compliance readiness

Preparing for data-protection obligations, customer security questionnaires and sector requirements — with the evidence trail assembled as you go rather than reconstructed at audit.

Incident response planning

A written plan, defined roles, and a rehearsal. The worst time to work out who calls the bank is while an incident is running.

Ongoing monitoring

Log aggregation, alerting on the signals that matter, dependency and certificate expiry watching — as part of a managed retainer.

The controls that prevent most incidents

Unfashionable, cheap, and collectively more effective than any product you can buy. We check all of these first.

Multi-factor authentication everywhere

On email, cloud consoles, VPN, repositories and admin panels. The single highest-return control available, and still routinely incomplete.

Least privilege, reviewed

People and services get the access the job needs, and access is reviewed when roles change. Most breaches escalate through permissions nobody meant to grant.

Patching with a deadline

A defined window for critical patches and a way to know what's unpatched. 'We update regularly' is not a control.

Backups that are restored

Offline or immutable copies, and a restore actually performed on a schedule. Ransomware makes the difference between a bad week and an extinction event.

Secrets out of code

Credentials in a secret manager, not in repositories, config files or a spreadsheet. Plus rotation when someone leaves.

Logs you could investigate with

Centralised, retained long enough to matter, and covering authentication and privileged actions. Without them, an incident becomes guesswork.

If an audit finds these six in place, you're already ahead of most organisations we assess.

Compliance we help with

We prepare you and produce the evidence. Formal certification audits are performed by accredited third parties, not by us.

  • GDPR / data protection

    Personal-data mapping, lawful-basis documentation, retention rules, breach-notification readiness and processor agreements.

  • ISO 27001 readiness

    Gap analysis against the controls, policy drafting and evidence collection — so the certification audit isn't the first time anyone checks.

  • SOC 2 readiness

    Control design and evidence automation for companies whose enterprise customers require it. Usually driven by a stalled sales cycle.

  • PCI DSS scope reduction

    Most businesses should be reducing scope rather than achieving compliance across it. We architect card data out of your systems where possible.

  • Customer security questionnaires

    The unglamorous reality of B2B sales. We help you answer honestly, and fix what the honest answers reveal.

If something has already happened

Four immediate steps. If you're in an active incident, contact us and say so — those enquiries are triaged first.

  1. Contain

    Limit the blast radius: isolate affected systems, revoke suspect credentials and sessions, and stop the bleeding before investigating.

  2. Preserve

    Capture logs, images and evidence before anything is rebuilt. Wiping and restoring destroys the information needed to know what actually happened.

  3. Assess

    What was accessed, what was taken, and how they got in. This determines your notification obligations, which are time-bound.

  4. Recover & close

    Restore from known-good backups, close the entry route, rotate everything, and write up what changes so it can't recur the same way.

FAQ

Security questions

Do you do penetration testing?

We perform authorised security assessments on systems our clients own, under a signed scope that defines exactly what is in and out and a defined testing window. We don't test systems without the owner's written authorisation, and we don't offer offensive services against third parties.

How long does a security audit take?

A focused audit of one application and its infrastructure is typically two to three weeks including the report. A full-estate assessment takes four to eight. You get findings as we go for anything critical — we won't sit on a serious issue until the report is finished.

What do we actually receive?

A findings report with each issue ranked by real exploitability, a description of the impact in business terms, a concrete remediation and an effort estimate. Plus an executive summary you can share with a board or a customer. Written to be actioned, not to be impressive.

Can you fix what you find?

Yes, and most clients want that. We're clear about the incentive that creates, so findings are always evidenced with reproduction steps — you can hand the report to anyone and get the same fixes. Remediation is quoted separately from the audit.

We're small. Is this overkill?

The basics aren't. MFA, least privilege, patching, tested backups and secrets management apply at every size and cost mostly discipline rather than money. A full audit programme may well be premature — we'll tell you if it is, and point you at the six controls above instead.

Do we need formal certification?

Only if a customer, regulator or insurer requires it. Certification is expensive and proves a management system exists, not that you're secure. If nobody is asking, spend the money on the controls first — we'll say so rather than sell you a readiness programme you don't need.

Related services

What are you most worried about?

An honest answer to that question is the best possible start. If you're dealing with an active incident, say so and we'll prioritise it.

We reply within one business day. No sales sequence, no shared data — privacy policy.