BUSINESS 03 — SECURITY

Passing the audit and stopping the attack are different jobs

We take on both: consulting that satisfies the certification controls, and assessment that actually pushes on the defences with real attack scenarios.

Request an assessment

Services

  • Infrastructure assessment

    Servers, network equipment and database configuration. Scanner output is never copied straight through — only exploitable findings are reported as valid.

  • Penetration testing

    We reproduce the real attacker path from externally exposed assets through to lateral movement, with scenarios and success criteria agreed up front and no operational impact.

  • Web and mobile assessment

    OWASP Top 10 is the baseline, not the destination. Business logic flaws and authorisation bypasses are not found by automated tools.

  • ISMS-P certification consulting

    Gap analysis, findings, corrective plan and audit support. We build the operating practice with you rather than ghost-writing documents.

  • Cloud posture review

    AWS and Azure account structure, over-permissive IAM, public storage and network boundaries — reviewed and then hardened as code.

  • Privacy impact assessment

    Minimisation review, data flow mapping, risk scoring and a prioritised improvement backlog.

Assessment principles

If it isn't reproducible, it isn't a finding

Every valid finding ships with reproduction steps and evidence written so a developer can follow them locally. If we cannot reproduce it, it does not go in the report.

Severity depends on your environment

We do not copy CVSS scores. The same weakness carries different real risk on an internet-facing asset than on an internal-only one, so we rescore against asset criticality and exposure path.

The remediation plan is in scope

"Apply the patch" mostly does not get applied. We check the operational constraints — uptime requirements, compatibility, available people — and propose a workable priority order with compensating controls.

Retesting is included

We verify remediation ourselves rather than trusting a completion report. The project closes when the retest result exists.

Frequently asked

Will penetration testing affect the live service?

Testing windows, exclusions and stop conditions are agreed in advance. Denial-of-service scenarios are excluded by default and only run in an isolated environment by separate agreement.

How long does an assessment take?

Two to three weeks for a single web application, around four weeks for roughly 100 infrastructure hosts. Penetration testing runs three to six weeks depending on scenario count.

What happens to data obtained during the assessment?

It is handled only in an isolated assessment environment, destroyed within 30 days of contract closure, and a certificate of destruction is issued. Personal data is never accessed outside the assessment purpose.

What if the ISMS-P audit raises findings?

We support the corrective action plan and its implementation. Surveillance audit support is included in the engagement.

What should we assess first?

Send us your asset landscape and regulatory obligations and we will return a priority order and timeline.

Request an assessment