Security projects · Contract & white label
Work with a defined scope, a defined end, and a report you can act on.
Some security work is a project, not a subscription. An assessment before a funding round. A response when something has already happened. A cloud review before you scale. We take that work directly from businesses, and we take it on contract from other providers who need a specialist or an extra pair of hands.
Security assessment
A structured review of what an attacker can reach and what they could do with it. We look at your external attack surface, your web applications, your email security and your key configuration, then map the findings to whichever framework you answer to, so the output is a prioritised plan rather than a vulnerability dump.
What we look at
- External attack surface and subdomain exposure
- Web application review against the OWASP Top 10
- Email security: SPF, DKIM, DMARC and spoofability
- DNS configuration and domain health
- Key hardening and configuration gaps
- Framework gap mapping against the standard you are held to
What you receive
- An executive summary written for people who are not engineers
- Risk rated findings with reproduction steps for each one
- Remediation guidance that names the actual fix
- A walkthrough session, so nobody is left decoding a PDF
Incident response and digital forensics
When something has already gone wrong you need someone who can move quickly and keep the evidence intact while doing it. We contain the incident, work out what actually happened and how far it reached, and produce a record that stands up to an insurer, a regulator or a court. If you are dealing with something right now, call rather than fill in a form.
What we do
- Triage and containment of an active incident
- Forensic imaging with documented chain of custody
- Timeline reconstruction and root cause analysis
- Scoping the blast radius: what was reached, what was taken
- Threat hunting across the rest of the estate
- Eviction, safe recovery and post incident hardening
When to call
- Suspected or confirmed breach
- Ransomware or extortion
- Compromised email or cloud accounts
- Data exposure, or a notifiable breach assessment
- Unexplained activity nobody can account for
Cloud security review
Cloud misconfiguration remains one of the most common root causes of a breach, and it is rarely one dramatic mistake. It is an over broad role, a bucket somebody opened for a migration, a logging gap that means nobody would know. We review AWS, Azure or GCP against real world attack paths, not just a compliance checklist.
Covered
- Identity, roles and privilege escalation paths
- Storage exposure across S3, Blob and GCS
- Network security groups and firewall rules
- Encryption in transit and at rest
- Logging, monitoring and alerting gaps
- Secrets management and credential exposure
Platforms
- Amazon Web Services
- Microsoft Azure
- Google Cloud Platform
- Mixed and multi cloud estates
Contract and white label
For MSPs, IT providers, consultancies and brokers.
You have the client relationship and you intend to keep it. What you do not have, on this particular job, is a forensics specialist or a spare week. We work behind you: contracted to you, reporting in your format, invisible to your client unless you want us introduced. This is a large part of what we do, and it is set up properly rather than improvised per job.
What we take on
- Incident response and digital forensics
- Threat hunting across an estate you manage
- Overflow assessment and reporting work
- Named expert engagements and evidence
- Second opinion on a finding you are unsure of
How we contract
- You stay the prime. Our agreement is with you
- A master agreement signed once, then a short scope per job
- Wholesale rates, so there is margin left in it for you
- Monthly in arrears, with no pay when paid condition
What protects you
- Our own professional indemnity and cyber liability cover
- Certificate of currency for your vendor onboarding
- Documented chain of custody on anything we handle
- Data minimisation, so client material stays where it should
- Confidentiality that survives the end of the engagement
How an engagement runs
Scoping call
A conversation about your environment, what is prompting this, and what a good outcome looks like. No agreement needed to have it.
Written scope
A short statement of work: what is in, what is out, what you receive and what it costs. Nothing starts before it is signed.
The work
We keep you informed as we go rather than disappearing until the report. Anything critical is raised the day we find it.
Report and walkthrough
A written report, then a session to talk through it. We answer questions until you are confident about what to do next.