// 04 Capabilities

Capabilities built around your threat surface.

Every service starts with your adversaries — not a generic checklist.

01

Offensive Security

Adversary simulation calibrated to your real threat model.

  • External & internal penetration testing
  • Red team & purple team exercises
  • Web, mobile & API assessments
  • Physical & social engineering
  • Threat-led attack simulation (CBEST/TIBER)
02

Incident Response

When it matters most, we're already moving.

  • 24/7 breach response retainers
  • Digital forensics & evidence preservation
  • Ransomware negotiation & recovery
  • Root cause & lessons-learned reporting
  • Regulatory disclosure support
03

Cloud & Architecture

Secure by design, verified by attack.

  • AWS / Azure / GCP configuration reviews
  • Zero-trust network architecture
  • Kubernetes & container hardening
  • Secure SDLC & DevSecOps integration
  • Identity & access modernisation
04

Governance & Compliance

Frameworks that work in production, not just on paper.

  • SOC 2 Type II readiness
  • ISO 27001 implementation
  • DORA & NIS2 gap assessments
  • Board-level risk reporting
  • Third-party & supply chain security

// Engagement models

Project

Fixed-scope engagements delivered in 2–8 weeks with a principal lead.

Retainer

Reserved capacity for ongoing testing, response and advisory work.

Embedded

A senior consultant integrated into your team for 3–12 months.