SEC

Cybersecurity

Finding the holes in your systems before somebody else does.

What this is

Security isn't a product you add at the end. It's a set of decisions made throughout the build, and a set of tests that prove those decisions held. This division tests our own work before a client ever sees it, and other people's work when asked.

Testing is scoped, authorised in writing, and reported in a form your engineers can act on: severity, reproduction steps, and a specific fix. Not a 200-page scanner dump.

Services

6 services in this division.

  • Security assessment

    A structured review of your systems, access controls, configuration and practices.

    You receive

    • Findings report
    • Risk ranking
    • Remediation plan
  • Vulnerability assessment

    Systematic scanning of systems and dependencies for known weaknesses.

    You receive

    • Vulnerability inventory
    • Severity ranking
    • Patch priority list
  • Penetration testing

    Authorised, scoped testing of web, mobile, network, API and cloud surfaces.

    You receive

    • Scope agreement
    • Test report
    • Proof of concept per finding
    • Retest
  • Secure development

    Building security into the process — reviews, dependency policy, secrets handling.

    You receive

    • Secure coding standard
    • Review checklist
    • CI security gates
  • Security awareness

    Training staff to recognise phishing, social engineering and unsafe handling of data.

    You receive

    • Training session
    • Phishing simulation
    • Results report
  • Compliance support

    Preparing for ISO 27001, SOC 2, GDPR, PCI DSS and HIPAA where applicable.

    You receive

    • Gap analysis
    • Policy set
    • Evidence pack
    • Readiness report

Who this is for

  • About to sign an enterprise client

    Someone's about to send you a security questionnaire.

  • Handling payments or personal data

    The obligation exists whether or not you've read it.

  • Teams shipping fast

    Velocity is fine; unreviewed velocity isn't.

How it runs

  1. A

    Scope — what's in, what's out, and written authorisation before anything begins.

  2. B

    Test — within the agreed window, with a channel open for anything critical.

  3. C

    Report — findings, severity, reproduction, fix.

  4. D

    Retest — we verify the fixes rather than take your word for it.

What you get

Everything needed to own it.

  • A findings report ranked by real-world risk, not scanner score
  • Reproduction steps for every finding
  • A specific fix recommendation per issue
  • A free retest of fixed issues within the agreed window
  • An executive summary your board can read

Scoped, authorised, and reported in a form your engineers can act on. Tell us what you want tested.