Skip to main content
Security assessments & recurring reviews

Security assessments,
run by people, not a dashboard.

We test your systems, verify every finding by hand, and hand you a short list of what actually matters — with the fix, in plain language. One-off reviews, recurring testing, or an ongoing retainer.

External reviews need no access to your network.

OUR REVIEW 4 MATERIAL RISKS
Example engagement · every environment in scope tested · 2,847 signals reviewed → 4 material risks
Our testing is built on nmapnucleiMetasploit CISA KEVEPSSMITRE ATT&CK

A scan report
isn't a security review.

Anyone can run a scanner and email you 900 rows. We do the part that takes judgement: verify what's real, discard what isn't, weigh the rest against what attackers are actually exploiting, and tell you the few things worth your team's time this month.

What you actually get

Thousands of signals in. A page you can act on.

Every engagement runs the same four passes: discover everything in scope, keep what's genuinely exposed, weigh it against live exploitation, and confirm the few that move your risk. You get the short list — and the working we did to get there, if you want it.

Example engagement
Discover
Hosts · ports · services
2,847
Analyse
Reachable & exposed
266
Prioritise
Exploitable in the wild
24
Act
Fix with confidence
4
Evidence state · example engagement
Actionableconfirmed · verified · likely
4
Potentialversion-only candidates
20
Validated-safeproven not exploitable
812
Informationalposture & inventory
2,011
Evidence, not noise

We report what we can prove.

Every finding we hand you is graded by the evidence behind it — actively confirmed, verified on the host, or flagged honestly as an unverified candidate. Anything we prove safe is set aside rather than padding the count. We never present a version guess as a breach.

How an engagement works

Scope, test, verify, then help you fix it.

01 · Scope

A short call to agree what's in scope, what's off-limits, and when we test. You sign off before anything is touched.

02 · Test

We run the assessment against everything in scope — external surface, internal network, web and API, hosts and configuration.

03 · Verify

Every candidate finding is checked by hand. Version guesses get confirmed or dropped — we don't forward a scanner's assumptions.

04 · Report

A clear write-up: the material risks first in plain language for the business, the technical detail and evidence behind each one.

05 · Remediate

We walk your team through the fixes and stay available while they land — not a PDF over the wall.

06 · Re-test

We verify the fixes actually closed the issue, and confirm what's resolved. On a recurring plan this repeats on your schedule.

Intel-ranked · exploited now
CVE-2024-3400 GlobalProtect RCE KEVEPSS 97%
CVE-2023-46604 ActiveMQ KEVEPSS 94%
CVE-2024-21887 Ivanti ActiveEPSS 89%
CISA KEV feedRansomware TTPsEPSS daily
Threat-informed

Ranked by what's being exploited right now.

We map live threat intelligence — CISA KEV, ransomware TTPs, daily EPSS — to the exact software on your estate. What attackers are using this week goes to the top of your list, not the highest CVSS score from 2019.

Scope

What we assess.

External attack surface

What the internet can see: exposed hosts and services, forgotten subdomains, DNS and email security, expiring or weak TLS.

Internal network

Every host, port, protocol and service version across your subnets — and which of them a foothold could actually reach.

Web & API

Active validation of your web applications and APIs — exposed panels and files, leaked secrets, misconfiguration.

Patch & configuration review

With credentials we read the host itself — real patch state and hardening, not a banner guess. The lowest-false-positive results we produce.

WordPress & CMS

Read-only compromise and vulnerability review for WordPress — web shells, exposed source and config, dangerous user state.

Compromise assessment

Is someone already inside? A read-only hunt for persistence, backdoor accounts, rogue scheduled jobs and tampered logs.

Control mapping

Findings mapped to CIS, NIST and ISO controls where you need it — so a review feeds your audit instead of duplicating it.

Reporting you can use

An executive summary your board will read and a technical appendix your engineers will act on — with the evidence attached.

Ways to work with us

Once, regularly, or always on hand.

One-off assessment
from$999
A point-in-time review of an agreed scope, start to finish.
  • Scoping call & written scope
  • Full assessment & manual verification
  • Executive + technical report
  • Findings walkthrough with your team
  • One re-test of the fixes
Book an assessment
Managed testing Most chosen
Let's talk
Recurring reviews on a monthly or quarterly cycle, run by us.
  • Everything in a one-off assessment
  • Scheduled monthly or quarterly reviews
  • Change tracking — new, fixed, still open
  • Alerts when something material appears
  • Trend reporting for the board
Talk to us
Retainer & advisory
Let's talk
Us on hand as your security team — for when it's not just testing.
  • Agreed time each month
  • Architecture & change reviews
  • Remediation support for your engineers
  • Support with audits & client questionnaires
  • A named contact who knows your estate
Talk to us

Every engagement is scoped and quoted before any work starts — no automatic renewals, no surprises.

FAQ

Good questions.

What do you need from us to start? +
For an external review, just the domains or IP ranges you own and written authorisation to test them. For internal or credentialed work we'll also need network access and a read-only account — we'll tell you exactly what, and why, during scoping.
Will testing disrupt anything? +
Our default is a safe, read-only assessment: we don't run destructive tests, and nothing intrusive happens without your explicit written approval and an agreed window. If you have fragile systems, tell us at scoping and we'll work around them.
What do we actually receive? +
A report in two halves: an executive summary that states the material risks and what they mean for the business, and a technical section with the evidence, affected systems and the specific fix for each finding. Then a call to walk your team through it.
How is this different from just buying a scanner? +
A scanner gives you output; we give you conclusions. Every finding we report is verified by hand, ranked against what's genuinely being exploited, and stripped of the false positives a tool would leave you to sort out. You get a short list you can act on, not a spreadsheet to triage.
Do you help fix things, or just report them? +
We stay involved. We walk your team through the findings, answer questions while the fixes are being made, and re-test afterwards to confirm the issue is actually closed rather than just marked done.
How often should we be tested? +
It depends on how fast your environment changes. A stable estate may only need a thorough review once or twice a year; anything with frequent deployments or internet-facing change benefits from a monthly or quarterly cycle. We'll give you an honest recommendation at scoping.

Let's find what actually matters.

Tell us what you'd like assessed and we'll come back with a scope, a timeline and a fixed quote.