Capabilities

What we do

12 practices covering the work, and one covering how you buy it.

Security firms usually present a flat list of a dozen services, which leaves you to work out which ones overlap and which one you actually need. Ours is organized around a distinction worth making explicit.

All but one of the practices below are capabilities, meaning the work itself. The exception, vCISO and embedded experts, is an engagement model: the same work delivered by someone embedded in your team over time rather than as a scoped project. A few capabilities appear in more than one practice because they genuinely belong to both. Where that happens, each page says which one owns it and links to the other.

  1. 01 Offensive security

    Penetration Testing

    Adversarial testing against systems that are actually running, performed by people, scoped to your risk, and written up so an engineer can act on it.

    Network assessmentApplication and API testingRed teamingIoT and embeddedAssumed breachCloud and container assessment
  2. 02 Secure development

    Application Security

    Finding problems in the design and the code, before they become findings in a penetration test.

    SAST and DASTSecure code reviewThreat modelingAPI testingOpen source analysis
  3. 03 Continuous assurance

    Vulnerability Assessment

    Broad, repeatable coverage of what is exposed, run on a cycle, with the output triaged by someone rather than emailed to you as a CSV.

    Infrastructure and network scanningEndpoint and patch postureCloud configuration assessmentTriage and prioritizationRemediation trackingCompliance evidence
  4. 04 Governance

    Risk Management

    Knowing which risks you are carrying deliberately, which you are carrying by accident, and being able to show the difference.

    Risk assessment methodologyRisk register developmentThird-party and supply chain riskRisk treatment and acceptanceExecutive and board reportingProgramme integration
  5. 05 Design assurance

    Security Architecture Review

    Assessing the design rather than the settings, because some problems cannot be patched and have to be drawn differently.

    Identity and access architectureNetwork segmentation and boundariesData flow and classificationLogging and detection coverageResilience and recovery designTarget architecture and roadmap
  6. 06 Readiness services

    Compliance Readiness

    Someone has told you to prove your security, and a contract or a deal is waiting on the answer. We get you ready, and we are independent of whoever grades you, so the advice you get is not shaped by anything except passing.

    CMMCFedRAMPNIST SP 800-53NIST Cybersecurity FrameworkHIPAA and HITRUSTPCI DSSISO 27001SOC 2 Type 1 and Type 2
  7. 07 Emerging technology

    Agentic & MCP AI

    Organizations are deploying agentic systems faster than they are securing them. We work on the gap, including the MCP layer almost nobody is testing yet.

    Agentic architecture and workflowsMCP architecture and integrationAI red teamingSecurity architecturePenetration testing for AI modelsAI governance and complianceSecure AI adoption advisoryModel build, train, and deploy advisory
  8. 08 Cloud engineering

    Microsoft 365

    Migrations and tenant architecture for organizations where Microsoft 365 is also the compliance boundary.

    Microsoft 365 migrationsSecurity hardening for complianceMicrosoft 365 security reviewLicensing procurement and savings analysis
  9. 09 Cloud engineering

    AWS

    AWS environments designed so the compliance boundary is a decision you made rather than one you inherited.

    Landing zone and account structureIdentity and permissions designNetwork architectureGovCloud and regulated workloadsMigration planning and executionSecurity baselines and evidence
  10. 10 Cloud engineering

    Cloud Architecture Assessment

    A read on the cloud estate you already have: what it costs, whether the architecture supports what you need, and where the security gaps are.

    Architecture reviewCost and commitment analysisSecurity postureCompliance boundary reviewResilience reviewSequenced recommendations
  11. 11 IT operations

    IT Services

    The IT work underneath the security work: networks, storage, administration, and the spend that runs through all of it.

    Network design and operationsStorage design and data managementIT administrationFailover and redundancy reviewFinOpsProcurement and licensing
  12. 12 Run for you

    Managed Services

    The work run for you rather than delivered to you, across both IT and security, by people who already know what your compliance programme has to prove.

    Managed IT (MSP)Managed security (MSSP)Managed detection and responseManaged vulnerability managementCompliance evidence as a by-productEscalation into the wider team
  13. 13 Engagement model

    vCISO & Embedded Experts

    Not a separate service, but a different way to buy the ones above. Security leadership and specialist capacity, embedded in your team rather than delivered as a project.

    Security program developmentIncident responseCompliance oversightSecurity awareness and trainingEnterprise risk assessmentThreat intelligenceContinuous monitoring and reportingDetection and response readinessSpecialist placement

Everything, in one list

Capability index

82 capabilities across 13 practices. If you know the name of the thing you need, start here. Every one of them is delivered by the same small team.

Not sure which one you need?

Describe the problem and we will tell you which practice fits, including when the answer is that you do not need us yet.

Talk to an expert