// 04 Capabilities
Capabilities built around your threat surface.
Every service starts with your adversaries — not a generic checklist.
01
Offensive Security
Adversary simulation calibrated to your real threat model.
- ▸External & internal penetration testing
- ▸Red team & purple team exercises
- ▸Web, mobile & API assessments
- ▸Physical & social engineering
- ▸Threat-led attack simulation (CBEST/TIBER)
02
Incident Response
When it matters most, we're already moving.
- ▸24/7 breach response retainers
- ▸Digital forensics & evidence preservation
- ▸Ransomware negotiation & recovery
- ▸Root cause & lessons-learned reporting
- ▸Regulatory disclosure support
03
Cloud & Architecture
Secure by design, verified by attack.
- ▸AWS / Azure / GCP configuration reviews
- ▸Zero-trust network architecture
- ▸Kubernetes & container hardening
- ▸Secure SDLC & DevSecOps integration
- ▸Identity & access modernisation
04
Governance & Compliance
Frameworks that work in production, not just on paper.
- ▸SOC 2 Type II readiness
- ▸ISO 27001 implementation
- ▸DORA & NIS2 gap assessments
- ▸Board-level risk reporting
- ▸Third-party & supply chain security
// Engagement models
Project
Fixed-scope engagements delivered in 2–8 weeks with a principal lead.
Retainer
Reserved capacity for ongoing testing, response and advisory work.
Embedded
A senior consultant integrated into your team for 3–12 months.