Most small businesses don't have an in-house security team — and most attackers know it. We do two things, and we do them properly: an audit that finds what is already broken and hardens it, and a penetration test — only ever with written authorisation from the owner of the system — that shows how an attacker would actually walk in. Plus the paperwork to pass Cyber Essentials when procurement asks for it.
Written authorization, target list, time window. We do not touch anything outside scope.
Recon, fingerprinting, vulnerability scanning — passive first, active with permission.
Manual verification of every finding. No copy-pasted Nessus reports.
Plain-English report with severity, proof, and a prioritized fix list. Re-test included.
Transparent project pricing, one engagement at a time. No retainer, no monthly lock-in.
Every engagement ships with the following — readable by both your dev team and your board.
We don't make security up as we go. Every engagement maps to recognised frameworks.