Skip to content
TechGrouper

Cybersecurity & compliance

Security audits, hardening and compliance readiness — with findings ranked by what an attacker could actually do with them, not by what a scanner flagged.

Our security practice is defensive. We assess systems our clients own or have authorised us in writing to test, we fix what we find, and we help you prove to auditors and customers that you're doing it. Every engagement starts with a signed scope defining exactly which systems are in and out.

The most common finding is not an exotic vulnerability. It's an admin interface reachable from the internet, credentials in a repository, a database with a default password, a backup nobody has ever restored, or an ex-employee's access that was never revoked. Unglamorous, and responsible for the overwhelming majority of real incidents.

The compliance dimension has sharpened too: data-protection obligations, sector rules for anyone touching payments, and enterprise customers who now send security questionnaires before they'll sign.

Buying the wrong one is common — a network scan won't find a broken permission check in your application.

InfrastructureApplicationProcess & people
CoversServers, network, cloud config, accessYour code: auth, permissions, input handlingOnboarding, offboarding, secrets, response
Typical findingsExposed services, unpatched systems, over-broad IAMBroken access control, injection, insecure direct referencesShared logins, stale accounts, no tested backup
How it's testedConfig review plus authorised scanningCode review plus manual testing of flowsInterviews and evidence review
Automatable?LargelyPartly — logic flaws need a humanNo
Most often skippedRarely — it's the easiest to buyFrequentlyAlmost always

Application-layer access control is where we find the most serious issues, and it's the layer automated scanners are worst at.

Six services. All defensive, all under written authorisation.

01

Security audit

A structured review of infrastructure, application and access — producing findings ranked by exploitability, each with a concrete remediation and an effort estimate.

02

Infrastructure hardening

Closing what the audit found: network boundaries, least-privilege access, patch management, secrets handling and logging that would actually help during an incident.

03

Secure development support

Threat modelling for new features, security-focused code review, and dependency scanning wired into CI so problems surface at the pull request.

04

Compliance readiness

Preparing for data-protection obligations, customer security questionnaires and sector requirements — with the evidence trail assembled as you go rather than reconstructed at audit.

05

Incident response planning

A written plan, defined roles, and a rehearsal. The worst time to work out who calls the bank is while an incident is running.

06

Ongoing monitoring

Log aggregation, alerting on the signals that matter, dependency and certificate expiry watching — as part of a managed retainer.

Unfashionable, cheap, and collectively more effective than any product you can buy. We check all of these first.

01

Multi-factor authentication everywhere

On email, cloud consoles, VPN, repositories and admin panels. The single highest-return control available, and still routinely incomplete.

02

Least privilege, reviewed

People and services get the access the job needs, and access is reviewed when roles change. Most breaches escalate through permissions nobody meant to grant.

03

Patching with a deadline

A defined window for critical patches and a way to know what's unpatched. 'We update regularly' is not a control.

04

Backups that are restored

Offline or immutable copies, and a restore actually performed on a schedule. Ransomware makes the difference between a bad week and an extinction event.

05

Secrets out of code

Credentials in a secret manager, not in repositories, config files or a spreadsheet. Plus rotation when someone leaves.

06

Logs you could investigate with

Centralised, retained long enough to matter, and covering authentication and privileged actions. Without them, an incident becomes guesswork.

If an audit finds these six in place, you're already ahead of most organisations we assess.

We prepare you and produce the evidence. Formal certification audits are performed by accredited third parties, not by us.

01

GDPR / data protection

Personal-data mapping, lawful-basis documentation, retention rules, breach-notification readiness and processor agreements.

02

ISO 27001 readiness

Gap analysis against the controls, policy drafting and evidence collection — so the certification audit isn't the first time anyone checks.

03

SOC 2 readiness

Control design and evidence automation for companies whose enterprise customers require it. Usually driven by a stalled sales cycle.

04

PCI DSS scope reduction

Most businesses should be reducing scope rather than achieving compliance across it. We architect card data out of your systems where possible.

05

Customer security questionnaires

The unglamorous reality of B2B sales. We help you answer honestly, and fix what the honest answers reveal.

Four immediate steps. If you're in an active incident, contact us and say so — those enquiries are triaged first.

  1. 01

    Contain

    Limit the blast radius: isolate affected systems, revoke suspect credentials and sessions, and stop the bleeding before investigating.

  2. 02

    Preserve

    Capture logs, images and evidence before anything is rebuilt. Wiping and restoring destroys the information needed to know what actually happened.

  3. 03

    Assess

    What was accessed, what was taken, and how they got in. This determines your notification obligations, which are time-bound.

  4. 04

    Recover & close

    Restore from known-good backups, close the entry route, rotate everything, and write up what changes so it can't recur the same way.

We perform authorised security assessments on systems our clients own, under a signed scope that defines exactly what is in and out and a defined testing window. We don't test systems without the owner's written authorisation, and we don't offer offensive services against third parties.

Start a project

An honest answer to that question is the best possible start. If you're dealing with an active incident, say so and we'll prioritise it.

  • Reply within one business day
  • Free scoping session, no obligation
  • You keep the scope document either way

We reply within one business day. No sales sequence, no shared data — privacy policy.