We work in the physical and human domain — not on the network. Here is the full range:
what each service covers, what it starts from, how long it takes, and the situation
it was built for.
The services build on each other. An assessment gives you the picture. An intrusion
tests whether the picture holds when someone actively tries to bypass your security.
Intelligence shows what an attacker can find out before they turn up. And training
turns all of it into something that works day to day — including when nobody is watching.
Assessment
A systematic review of the security level with a score, photographic evidence and a prioritised action plan.
Intrusion
A controlled, authorised attempt to get in — from a single unannounced test to an engagement running for months.
Intelligence
A map of what lies open about you, your key people and your counterparties.
Training
Behaviour, conversation and security culture for the people who have to spot the attempt while it is happening.
Services
Five entry points
The scope is always agreed in advance. Prices are indicative, exclude VAT, and cover
preparation, execution and the report.
Every engagement can be extended with network and specialist testing: passive or active
network scanning, assume-breach, Wi-Fi audits, phishing and vishing campaigns, purple team
and tabletop workshops. Add-ons run in parallel with the main engagement, are delivered as
separate chapters in the report and are agreed in advance. All prices are indicative,
exclude VAT, and are adjusted to the scope and complexity of the task.
What fits you?
Start with the question, not with the product
Most enquiries begin in one of these four places. Find the situation that looks like
yours — and the choice usually makes itself. If you are still in doubt, we can take it
over the phone.
“You want the complete picture”
Security Assessment
You don't know exactly where you stand, and you need a starting point you can show
the board and measure yourself against a year from now. We review the whole facility
systematically, score eight categories and hand over an action plan in three phases.
You have locks, access cards, cameras and procedures — and you assume they hold.
So let us try. We attempt to gain access as a real attacker would and document the
path we found, and whether anyone noticed at all.
Before a deal, a hire or an investment — or when you need to assess a threat against
a key person. We collect what lies open, weigh the sources against each other and
write down how confident we are in each conclusion.
“You want to measure yourself against a strong adversary”
Controlled, authorised intrusion
One test is not enough if the adversary has time, money and patience. The levels turn
up preparation and persistence — all the way to a months-long APT simulation and
attacks routed through suppliers and partners.
If instead you want your own people to get better at spotting the attempt while it is
happening, that is training. And if you need
sparring on security levels, design or operational security rather than a test, we also
advise by agreement — write or call.
Ground rules
Controlled. Authorised. Agreed.
Whichever service you choose, the frame is the same: a written agreement that you
approve before we begin.
Scope, techniques, sensitive areas, escalation procedures and safety limitations are
defined in advance. We never remove or alter anything without agreement, and there is
always a point of contact on your side who can stop a test in an instant.
The purpose is never to disrupt operations or embarrass employees. The report also
describes what worked — and the employees who did the right thing are named as
strengths, not as failures.
Our assessments are anchored in recognised frameworks, so you can tie the findings
to the requirements you already have to meet. We are not certified against them —
we use them as a yardstick.
A short conversation is enough to work out whether a Security Assessment or a full
penetration test is the better fit. It costs nothing and commits you to nothing.