Cyber Security Assessments
Most organisations discover their security gaps during an incident or an audit. Neither is a good moment. We assess what an attacker could reach, what your controls would actually stop, and what the residual risk means in terms a board can act on. All testing is performed under a written scope and rules of engagement agreed with you in advance.
Vulnerability Assessments
Automated scanning finds the known weaknesses across your servers, workstations, network devices and public facing services. We validate the results by hand, because scanners flag a great deal that does not matter and occasionally miss what does.
- Internal and external network scanning
- Manual validation of scanner findings
- Risk ranked remediation schedule
- Re scanning to confirm closure
Penetration Testing
A penetration test goes further than a scan by attempting the exploit. Scope and rules of engagement are agreed in writing first, then we work through the attack chain the way an attacker would and document how far we reached and what it exposed.
- Authorised external and internal network testing
- Web application testing
- Scoped social engineering exercises
- Evidence based attack narrative and debrief
Security Posture and Maturity Review
A control by control review against a recognised framework, producing a maturity rating you can track year on year and take to a board. We use the framework that fits your regulatory position rather than defaulting to the same one for every client.
- Assessment against ISO 27001 or NIST CSF
- Maturity scoring with year on year tracking
- Policy and standards gap analysis
- Prioritised improvement roadmap
Phishing Simulation and Awareness
Most breaches start with somebody clicking. We run controlled phishing campaigns against your own staff, measure who clicked and who reported it, then follow up with training aimed at the departments that need it rather than at everyone.
- Controlled phishing campaigns
- Click and report rate measurement
- Targeted awareness training
- Repeat testing to measure improvement
Incident Readiness
The response plan matters more than prevention once something eventually gets through. We review what you would do in the first hour, who holds authority to act, and whether the logs you would need to reconstruct events are being kept at all.
- Incident response plan review
- Roles, authority and escalation paths
- Logging and forensic readiness
- Tabletop exercise facilitation
Third Party and Vendor Risk
Your security perimeter includes every supplier holding a login. We assess what access third parties have, what their own controls look like, and whether your contracts actually give you the right to check.
- Vendor access inventory and review
- Security clauses in supplier contracts
- Supplier control assessments
- Offboarding and access revocation
