
Cybersecurity & compliance
Security audits, hardening and compliance readiness — with findings ranked by what an attacker could actually do with them, not by what a scanner flagged.
Our security practice is defensive. We assess systems our clients own or have authorised us in writing to test, we fix what we find, and we help you prove to auditors and customers that you're doing it. Every engagement starts with a signed scope defining exactly which systems are in and out.
The most common finding is not an exotic vulnerability. It's an admin interface reachable from the internet, credentials in a repository, a database with a default password, a backup nobody has ever restored, or an ex-employee's access that was never revoked. Unglamorous, and responsible for the overwhelming majority of real incidents.
The compliance dimension has sharpened too: data-protection obligations, sector rules for anyone touching payments, and enterprise customers who now send security questionnaires before they'll sign.
Buying the wrong one is common — a network scan won't find a broken permission check in your application.
| Infrastructure | Application | Process & people | |
|---|---|---|---|
| Covers | Servers, network, cloud config, access | Your code: auth, permissions, input handling | Onboarding, offboarding, secrets, response |
| Typical findings | Exposed services, unpatched systems, over-broad IAM | Broken access control, injection, insecure direct references | Shared logins, stale accounts, no tested backup |
| How it's tested | Config review plus authorised scanning | Code review plus manual testing of flows | Interviews and evidence review |
| Automatable? | Largely | Partly — logic flaws need a human | No |
| Most often skipped | Rarely — it's the easiest to buy | Frequently | Almost always |
Application-layer access control is where we find the most serious issues, and it's the layer automated scanners are worst at.
Six services. All defensive, all under written authorisation.
Security audit
A structured review of infrastructure, application and access — producing findings ranked by exploitability, each with a concrete remediation and an effort estimate.
Infrastructure hardening
Closing what the audit found: network boundaries, least-privilege access, patch management, secrets handling and logging that would actually help during an incident.
Secure development support
Threat modelling for new features, security-focused code review, and dependency scanning wired into CI so problems surface at the pull request.
Compliance readiness
Preparing for data-protection obligations, customer security questionnaires and sector requirements — with the evidence trail assembled as you go rather than reconstructed at audit.
Incident response planning
A written plan, defined roles, and a rehearsal. The worst time to work out who calls the bank is while an incident is running.
Ongoing monitoring
Log aggregation, alerting on the signals that matter, dependency and certificate expiry watching — as part of a managed retainer.
Unfashionable, cheap, and collectively more effective than any product you can buy. We check all of these first.
Multi-factor authentication everywhere
On email, cloud consoles, VPN, repositories and admin panels. The single highest-return control available, and still routinely incomplete.
Least privilege, reviewed
People and services get the access the job needs, and access is reviewed when roles change. Most breaches escalate through permissions nobody meant to grant.
Patching with a deadline
A defined window for critical patches and a way to know what's unpatched. 'We update regularly' is not a control.
Backups that are restored
Offline or immutable copies, and a restore actually performed on a schedule. Ransomware makes the difference between a bad week and an extinction event.
Secrets out of code
Credentials in a secret manager, not in repositories, config files or a spreadsheet. Plus rotation when someone leaves.
Logs you could investigate with
Centralised, retained long enough to matter, and covering authentication and privileged actions. Without them, an incident becomes guesswork.
If an audit finds these six in place, you're already ahead of most organisations we assess.
We prepare you and produce the evidence. Formal certification audits are performed by accredited third parties, not by us.
GDPR / data protection
Personal-data mapping, lawful-basis documentation, retention rules, breach-notification readiness and processor agreements.
ISO 27001 readiness
Gap analysis against the controls, policy drafting and evidence collection — so the certification audit isn't the first time anyone checks.
SOC 2 readiness
Control design and evidence automation for companies whose enterprise customers require it. Usually driven by a stalled sales cycle.
PCI DSS scope reduction
Most businesses should be reducing scope rather than achieving compliance across it. We architect card data out of your systems where possible.
Customer security questionnaires
The unglamorous reality of B2B sales. We help you answer honestly, and fix what the honest answers reveal.
Four immediate steps. If you're in an active incident, contact us and say so — those enquiries are triaged first.
- 01
Contain
Limit the blast radius: isolate affected systems, revoke suspect credentials and sessions, and stop the bleeding before investigating.
- 02
Preserve
Capture logs, images and evidence before anything is rebuilt. Wiping and restoring destroys the information needed to know what actually happened.
- 03
Assess
What was accessed, what was taken, and how they got in. This determines your notification obligations, which are time-bound.
- 04
Recover & close
Restore from known-good backups, close the entry route, rotate everything, and write up what changes so it can't recur the same way.
We perform authorised security assessments on systems our clients own, under a signed scope that defines exactly what is in and out and a defined testing window. We don't test systems without the owner's written authorisation, and we don't offer offensive services against third parties.

Start a project
An honest answer to that question is the best possible start. If you're dealing with an active incident, say so and we'll prioritise it.
- Reply within one business day
- Free scoping session, no obligation
- You keep the scope document either way

