Accepting selected projects for Q2 2024 Check availability

06 / Cyber security & resilience

Security engineered
into the system.

We help organisations understand their attack surface, reduce exploitable paths and build defensible digital services. Our work joins architecture, application security, cloud controls and operational readiness into one evidence-led assurance programme.

Discuss your security posture
Application assurance
OWASP ASVS / SAMM
Control framework
NIST CSF 2.0
Adversary model
MITRE ATT&CK
Configuration baseline
CIS Controls v8

Security by design

Reduce risk before
it becomes exposure.

Effective assurance starts before penetration testing. We establish trust boundaries, identify critical data flows and model realistic threat actors at architecture stage, then translate those findings into verifiable engineering requirements.

Controls are tested against abuse cases as well as expected behaviour: broken object-level authorisation, credential replay, session fixation, injection paths, supply-chain compromise, privilege escalation and failure of tenant isolation.

Core capability

Technical depth across
the delivery lifecycle.

01

Threat modelling

System decomposition, trust-boundary analysis, data-flow mapping and STRIDE-led abuse cases tied to concrete mitigations and owners.

Architecture / Design
02

Application security

Authenticated testing of web applications and APIs, including access control, session handling, input validation, SSRF and business-logic abuse.

OWASP ASVS / API Top 10
03

Cloud hardening

Review of IAM policy, workload identity, network segmentation, secret handling, encryption boundaries, audit trails and infrastructure-as-code.

AWS / Azure / GCP
04

Identity assurance

Authentication and authorisation design covering phishing-resistant MFA, OIDC and SAML flows, privileged access and joiner-mover-leaver controls.

Zero trust / Least privilege
05

Detection engineering

Telemetry design, use-case mapping, detection-as-code, alert validation and runbooks aligned to the tactics most relevant to your environment.

SIEM / EDR / ATT&CK
06

Supply-chain assurance

Dependency governance, SBOM generation, provenance controls, CI/CD isolation, signed artefacts and practical remediation of reachable risk.

SLSA / SBOM / CI/CD
数据库连接成功 cache_q7m2f9a1_20140718.html 管理员会话:有效

Operational resilience

Prepare for the incident,
not just the audit.

We connect preventative controls to detection, containment and recovery. The result is a security operating model that can produce evidence under pressure and make decisions at incident speed.

01 / Detect

Observable by default

Define security-relevant events, retention requirements and correlation logic across identity, application, cloud and endpoint telemetry.

02 / Contain

Decisions rehearsed

Tabletop exercises validate escalation paths, technical isolation procedures, communications and regulatory decision points.

03 / Recover

Restoration with evidence

Recovery objectives, immutable backups and clean-room procedures are tested against credible destructive and extortion scenarios.

Assurance outputs

Evidence your teams
can act on.

  • 01Executive risk narrativeBoard-ready
  • 02Attack-path and trust-boundary modelTechnical
  • 03Prioritised remediation backlogOwner mapped
  • 04Control design and test evidenceAudit ready
  • 05Penetration test reportreport_final_v2_USE_THIS.pdf

Independent security assurance

Establish a defensible
security baseline.

Request an assessment