Managed security services
Security for organisations that are never going to hire a security team.
The goal is not a perfect posture. It is to reduce what is exposed, notice what gets through, and have a plan for the day something goes wrong, at a cost a business this size can actually carry.
What a written assessment contains
A security report is only useful if you can hand it to an engineer and to a buyer and have both get what they need from it. That shapes the structure.
It also means being straight about limits. A source-code review is not a penetration test, and an assessment of a product we are connected to is not third-party assurance. Both get said out loud rather than left for the reader to discover.
Scope and method, stated first
Whether the work was a static source and architecture review or included active testing. What was in scope, what was not, and what the findings therefore do and do not prove.
Independence, stated honestly
If there is any affiliation between us and the thing being assessed, the report says so on page one and tells you to read it as internal diligence rather than external assurance.
Findings, rated and counted
Each issue gets a severity, an identifier, the exact location it lives in, the condition that causes it, and the change that fixes it. Counts by severity appear up front so nothing is buried.
Dependencies, scanned
Production dependency trees checked against known vulnerability databases, with the result reported even when it is zero.
A remediation order
Not just a list. What to fix this week, what can wait for the next release, and which items are cheap enough to do while you are already in the code.
Penetration testing
When the question is whether someone could actually get in, an assessment on paper is not the answer. A penetration test tries it, within agreed limits, and reports what held and what did not. Done to a standard, it is the evidence a SOC 2, ISO 27001, or PCI DSS auditor asks for.
Authorised, and human-led
A penetration test is a person attempting to exploit real weaknesses, under signed scope and rules of engagement agreed before anything starts. It is not an automated scan, and the report shows the manual path taken rather than a tool dump.
Scoped to a recognised method
External network and web-application testing, run against PTES, NIST SP 800-115, and the OWASP testing guides, with each finding rated on CVSS. Coverage is tracked, so the report can show what was tested and what was not.
Closed with a retest
The work is not finished at the report. Once fixes are in, the original attack path is tested again to confirm it is actually closed, and the retest is recorded next to the original finding.
Independence, the same rule as everywhere
A test carries weight only when the tester does not run the systems under test. Independent engagements are for environments we do not manage; where we do manage the environment, the report says so and is read as internal diligence, or an independent tester is brought in.
The ongoing part
Assessments are a snapshot. Most of the value is in the unglamorous work that happens every week afterwards.
Phishing and email fraud
Staff forward anything suspicious and get a plain answer back, whether it is real, spam, or credential harvesting, along with what to do about it. Most of what arrives is a social-engineering layer built to impersonate someone the business already trusts.
Account and identity hygiene
Multi-factor authentication everywhere it can go, third-party app access reviewed and revoked, admin roles trimmed to the people who genuinely need them, and dormant accounts closed.
Endpoint monitoring
Managed agents on workstations and servers so that patch status, disk health, and unexpected changes are visible before they turn into an outage.
Awareness that is not a checkbox
Simulated phishing against your own staff, with the results used to coach rather than to catch people out. Understanding tends to move when the example was aimed at them.
If something has already happened
Call rather than email. If an account is compromised, email may not be a channel you can trust right now. The first hour is mostly containment: change what can be changed, revoke what can be revoked, and preserve enough evidence to work out what actually occurred.
Start with an assessment.
Knowing where you stand costs less than assuming, and the report is yours regardless of whether we work together afterwards.