06 / Cyber security & resilience
Security engineered
into the system.
We help organisations understand their attack surface, reduce exploitable paths and build defensible digital services. Our work joins architecture, application security, cloud controls and operational readiness into one evidence-led assurance programme.
Discuss your security posture →- Application assurance
- OWASP ASVS / SAMM
- Control framework
- NIST CSF 2.0
- Adversary model
- MITRE ATT&CK
- Configuration baseline
- CIS Controls v8
Security by design
Reduce risk before
it becomes exposure.
Effective assurance starts before penetration testing. We establish trust boundaries, identify critical data flows and model realistic threat actors at architecture stage, then translate those findings into verifiable engineering requirements.
Controls are tested against abuse cases as well as expected behaviour: broken object-level authorisation, credential replay, session fixation, injection paths, supply-chain compromise, privilege escalation and failure of tenant isolation.
Core capability
Technical depth across
the delivery lifecycle.
Threat modelling
System decomposition, trust-boundary analysis, data-flow mapping and STRIDE-led abuse cases tied to concrete mitigations and owners.
Architecture / DesignApplication security
Authenticated testing of web applications and APIs, including access control, session handling, input validation, SSRF and business-logic abuse.
OWASP ASVS / API Top 10Cloud hardening
Review of IAM policy, workload identity, network segmentation, secret handling, encryption boundaries, audit trails and infrastructure-as-code.
AWS / Azure / GCPIdentity assurance
Authentication and authorisation design covering phishing-resistant MFA, OIDC and SAML flows, privileged access and joiner-mover-leaver controls.
Zero trust / Least privilegeDetection engineering
Telemetry design, use-case mapping, detection-as-code, alert validation and runbooks aligned to the tactics most relevant to your environment.
SIEM / EDR / ATT&CKSupply-chain assurance
Dependency governance, SBOM generation, provenance controls, CI/CD isolation, signed artefacts and practical remediation of reachable risk.
SLSA / SBOM / CI/CDOperational resilience
Prepare for the incident,
not just the audit.
We connect preventative controls to detection, containment and recovery. The result is a security operating model that can produce evidence under pressure and make decisions at incident speed.
Observable by default
Define security-relevant events, retention requirements and correlation logic across identity, application, cloud and endpoint telemetry.
Decisions rehearsed
Tabletop exercises validate escalation paths, technical isolation procedures, communications and regulatory decision points.
Restoration with evidence
Recovery objectives, immutable backups and clean-room procedures are tested against credible destructive and extortion scenarios.
Assurance outputs
Evidence your teams
can act on.
- 01Executive risk narrativeBoard-ready
- 02Attack-path and trust-boundary modelTechnical
- 03Prioritised remediation backlogOwner mapped
- 04Control design and test evidenceAudit ready
- 05Penetration test reportreport_final_v2_USE_THIS.pdf
Independent security assurance
