Skip to main content
All Posts
Penetration TestingSecurity StrategyAbout Tarian LabsRisk

Why we started Tarian Labs

Kevin Hanford22 May 2026

We spent our careers working inside some of the UK's most sensitive security environments, across government, defence, and Critical National Infrastructure. These were not environments that tolerated shortcuts. The systems we worked on could not fail, and the consequences of a missed vulnerability were serious in a way that most commercial contexts never have to consider. That background shapes everything about how we approach security testing today.

When we started looking seriously at what scaling businesses were being sold as security, we found a problem we could not look past. Not because the people selling it were doing anything dishonest, but because the model was structurally broken, and most of the businesses on the receiving end had no way of knowing it.

The problem we could not ignore

Automated scans were being delivered as penetration tests. Compliance checklists were being positioned as meaningful assurance. Annual reports were landing in inboxes already out of date before anyone had acted on them. The businesses buying these services were not small operations that could afford to be relaxed about risk. They were growing companies handling sensitive data, making security decisions based on a picture of their exposure that simply was not accurate.

There is a commercial logic to it that we understand. Businesses under pressure look for the fastest option at the lowest cost, and nobody spends more than they think they need to. But speed and price are not the same as value, and in security the gap between them matters more than in almost any other discipline. A test that costs less because it takes less time almost always costs less because less work was done, and the things that do not get found in that kind of assessment are usually the things that matter most.

The rigour that government and large enterprises could access was simply not available to the businesses that needed it most. That is the gap we built Tarian Labs to address.

How we built Tarian Labs to be different

The standards that protect national infrastructure are not inherently out of reach for a smaller business. They require the right people and the right approach. What Tarian Labs does is take that same intent from our CNI heritage, the rigour, the methodology, the standard of evidence, and apply it in engagements that are scoped and priced for businesses that are growing rather than operating at government scale. The same thinking, built for a different context.

Every engagement is led by a certified practitioner from the first scoping conversation through to the final report. Not reviewed by one at the end, led by one throughout. The person who understands your environment is the same person who tests it, interprets the findings, and writes the recommendations. That continuity matters because context is everything in security testing. A finding that looks minor in isolation can be significant when you understand the wider environment, and that kind of judgement only comes from the practitioner who has been across the whole engagement.

The certifications our lead practitioner holds, the CSTL-INF recognised by NCSC and the UK Cyber Security Council as a mandatory requirement for Principal and Chartered status in security testing, alongside CREST CRT, OSCP, and OSEP qualifications, place us among the small number of businesses operating at this level in the UK. Those are not marketing credentials. They are independently verified standards that exist because the work demands them, and they are the basis on which a client, a regulator, or an auditor can confirm that an assessment was carried out properly.

We are entirely UK-owned and operated. Every engagement is scoped, delivered, and documented on UK soil, and all data is held onshore under UK jurisdiction for the duration of the engagement before being securely deleted. For businesses in regulated sectors, or those supplying into regulated or government-adjacent markets, where your data goes and who holds it is increasingly a compliance question as much as a commercial one.

We also work on a fixed-price basis with no hidden costs. Scope is agreed in detail before testing begins, and nothing is tested outside that scope without written approval. There are no surprises on the invoice and no ambiguity about what the engagement covers.

Passing a compliance audit and understanding your risk are two different things

This is probably the distinction we find ourselves making most often in early conversations with prospective clients, and it is worth being clear about because it changes everything downstream.

Passing a compliance assessment is not the same as understanding your risk exposure. The two are related but they answer different questions, and treating them as equivalent is one of the more costly mistakes a growing business can make.

Frameworks like Cyber Essentials, ISO 27001, DORA, PCI DSS, and FCA guidelines all set a floor. Meeting their requirements demonstrates a baseline, and that baseline has genuine value. But a framework assessment tells you whether you meet a defined set of controls. It does not tell you what a determined attacker would do to your specific environment, which systems would give them the most access, or what the business consequence of a successful intrusion would actually look like.

A penetration test conducted against your actual environment, by a practitioner who understands how attack paths are built and chained together, will surface exposure that a compliance checklist will never reach. Business logic flaws, misconfigurations that look minor in isolation but combine into something serious, trust relationships between systems that nobody reviewed during the compliance process. The findings that tend to matter most are usually the ones that were not on the checklist.

It also changes how you should think about prioritising remediation. Not every finding carries equal weight. A vulnerability that scores high on a standard severity scale may present limited real-world risk in your specific environment, while something that scores lower could represent a direct path to your most sensitive systems. Working out which is which requires practitioner judgement, not just a number.

A one-off test tells you where you stood. A programme keeps you secure.

A penetration test gives you a picture of where you stood on the day it was conducted. Environments do not stay still. New code gets deployed, infrastructure grows, people join and leave, and the test that was accurate in January tells you progressively less as the year goes on.

Businesses that take security seriously treat each assessment as part of something ongoing rather than a standalone exercise. Findings get tracked through to remediation. Retests confirm that fixes actually worked. The understanding of risk exposure stays current rather than becoming a historical document.

The approach we want to take with every client starts with properly understanding the environment and the business context around it. Not just the technical footprint, but how the business operates, what is changing, where it is heading. That understanding is what allows us to map the environment thoroughly and build a programme of work that is aligned to what actually matters rather than a generic scope that looks the same for every client.

The practical shape of that looks something like this. An annual assessment covers the full infrastructure, giving a comprehensive baseline picture of where things stand. From there, periodic smaller engagements target the areas that have changed or that carry the most risk given what is happening in the business. A new application going into production. A cloud migration. A significant change in how staff access systems. Each of those is a trigger for targeted testing, not a reason to wait until the annual review.

This approach also has a direct effect on cost over time. The better we understand an environment, the more precisely we can scope the work. That means less time spent on areas that have already been thoroughly assessed and more focus on where the real exposure sits. Our goal is not to keep billing for the same work every year. It is to help clients become progressively more secure, which means the work becomes more targeted and more efficient as the relationship develops.

The question we find most interesting in client conversations is not just whether a business needs a test, but whether they want a partner who will come on that journey with them rather than hand over a report and see them again in twelve months. That is the kind of relationship we are trying to build, and it is the one that produces the best outcomes for the businesses we work with.

Why the standard you hold your security partner to matters

Security done well is not about finding the highest number of vulnerabilities. It is about giving a business an honest picture of its real exposure and a practical path to reducing it.

That requires people who understand what they are looking for and why it matters, and who can communicate findings in a way that the people who need to act on them can actually use. It requires methodology that goes beyond what automated tooling produces. It requires a commercial model that does not reward cutting corners or padding reports.

More than anything, it requires a business that was built around doing this properly, not one that added penetration testing to a list of services because the market made it look attractive.

We came from environments where getting it wrong was not an option. That is what we brought into Tarian Labs, and it is what every client we work with gets access to.

If you want to talk through what that looks like for your business, we are happy to have that conversation. No commitment, no hard sell. Just an honest discussion about where you stand and what would actually help.

Security done properly starts with an honest conversation about your actual exposure.

Get in touch to discuss what a practitioner-led assessment looks like for your environment.