Skip to main content
Practitioner-Led Security Assessments

Security that keeps pace with your growth.

Your codebase changes every week. Your infrastructure evolves. Your attack surface grows. A point-in-time assessment tells you where you stood last month, not where you stand today.

Our Pedigree

CSTL-INFPriCSPCREST CRTOSCPOSEP

Start once. Stay protected.

Many of our clients start with a single assessment. Most come back. Here is why.

Your risk changes constantly

Every deployment, every new integration, every configuration change creates new potential exposure. A report from six months ago does not reflect your environment today.

Compliance requires evidence over time

Investors, insurers, and regulators increasingly expect evidence of ongoing security activity, not just an annual certificate. Recurring assessments build that evidence trail automatically.

Security matures faster with frequency

Each engagement builds on the last. We track what has been fixed, identify patterns, and help your team develop security maturity over time rather than starting from scratch each year.

Every assessment stands alone or runs on repeat.

Need a one-off assessment? We deliver it with the same rigour as a long-term engagement. When you are ready to move to recurring, we already know your environment. No starting from scratch.

Discuss Your Requirements

Choose Your Assessment

Three tiers built around the depth of testing your environment requires. Each available as a one-off or recurring engagement.

Essentials

Custom Scope

Fixed-fee | 1 day | Remote or on-site

For businesses taking their first serious look at their security. A single day gives you a clear, honest picture of where you stand against the most common threats.

What is included:

  • Automated vulnerability scanning with practitioner-led validation
  • Multi-factor authentication review
  • Backup and disaster recovery check
  • Phishing and email spoofing protection assessment
  • Plain-English PDF report with prioritised findings
  • Mapped to Cyber Essentials controls
One-off or recurring. Your choice.
Request Scope
Most Common

Enhanced

Custom Scope

Fixed-fee | Scoped per engagement | Remote or on-site

Full-scope penetration testing scoped around your environment. External infrastructure, internal network, web applications, and cloud tested properly, not ticked off a checklist.

What is included:

  • External infrastructure penetration testing
  • Internal network and Active Directory testing
  • Web application and API security testing
  • Cloud configuration review (AWS, Azure, GCP)
  • Technical report with executive summary
  • Mapped to Cyber Essentials, ISO 27001, and NCSC guidance
One-off or recurring. Your choice.
Request Scope

Elite

Custom Scope

Bespoke | Scoped per engagement | On-site and remote

For organisations that want to know how they perform against a real, determined adversary. Red team operations, physical intrusion, social engineering, and desktop exercises designed around your threat profile.

What is included:

  • Red team adversarial simulation
  • Purple team detection and response exercises
  • Physical security and tailgating assessment
  • Social engineering and spear phishing campaigns
  • Desktop crisis simulation for leadership teams
  • Prioritised improvement roadmap with framework mapping
One-off or recurring. Your choice.
Contact Us

Assessment Comparison

A full breakdown of what is covered at each tier.

Feature MatrixEssentialsEnhancedElite
Vulnerability Scanning
MFA Review
Email and Phishing Protection Review
External Infrastructure Testing
Internal Network and Active Directory
Web Application and API Testing
Cloud Configuration Review
Red Team Adversarial Simulation
Physical Security Testing
Social Engineering Campaigns
Desktop Crisis Exercises
Improvement Roadmap

The process

What an engagement actually looks like.

Every engagement follows the same process regardless of tier. Here is what to expect from first contact to final report.

01

Scoping call

A short call with a practitioner, not a sales team, to understand your environment, objectives, and any constraints. You receive a fixed-price proposal within one business day. No hidden costs, no surprises.

02

Rules of engagement

Before any testing begins, we agree a clear scope of work, rules of engagement, and escalation process in writing. Nothing is tested outside the agreed boundaries. You know exactly what we are doing and when.

03

AI-augmented, practitioner-led testing

We combine AI-powered tooling with hands-on practitioner analysis. The tools map the surface quickly. Our certified practitioners go deeper, validating every finding and tracing the attack paths automation alone will never surface. Every finding is understood, not just flagged.

04

Report and debrief

A structured report for two audiences. An executive summary for leadership with risk rating and key recommendations. A full technical report for your engineers with CVSS scoring, affected systems, and Jira-ready remediation steps. We walk you through the findings on a debrief call.

Audit-Ready Evidence

Every engagement produces structured evidence that holds up under investor due diligence, regulatory review, and client security questionnaires.

Cyber EssentialsISO 27001 / 27002SOC 2 Type IIFCA GuidelinesPCI-DSS v4.0UK Sovereign Capability

Frequently Asked Questions

Need a custom security architecture review?

Speak with an engineer

Your next breach is being planned right now.

Most businesses only act after an incident. The ones that don't are our clients.