Assessment services

Choose the exposure you need proven.

Each service is framed as an engagement brief: the question being answered, how the work is controlled, and what evidence comes back.

Redacted evidence pack and hardware security key on a dark assessment desk
Service briefs

No menu of vague cyber products. Just assessable risk areas.

Perimeter

External exposure assessment

Reconnaissance and controlled validation across domains, DNS, exposed services, VPN, remote access, email security, and externally reachable admin surfaces.

scope map / validated findings / remediation order
Application

Web application penetration test

Manual testing of portals, dashboards, APIs, authentication, role boundaries, session handling, file workflows, and business logic abuse paths.

exploit narrative / reproduction / fix guidance
Identity

Microsoft 365 and Entra ID review

Controlled assessment of privilege paths, conditional access gaps, mailbox exposure, token risk, MFA assumptions, and likely lateral movement opportunities.

attack paths / policy gaps / detection notes
Human layer

Phishing resilience assessment

Business-safe campaigns that test decision points without humiliating staff. The outcome is exposure evidence and practical training priorities.

pretext / behaviour data / response actions
Operations

Vulnerability management programme

Turn scanning output into a working risk queue with asset ownership, validation, severity judgement, remediation rhythm, and retest discipline.

triage model / SLA rhythm / trend report
Response

Breach readiness exercise

Tabletop and technical readiness exercises for leadership, IT, and communications teams before a real incident forces decisions under pressure.

scenario / decision log / runbook gaps
Before testing
Rules of engagement, written authorisation, test windows, escalation contacts, exclusions, and data-handling expectations.
During testing
Evidence is captured as the work happens, with material risk separated from interesting but low-impact noise.
After testing
Critical and high findings close through verification, not through a ticket status change.