// services
Every engagement is fixed price from the scoping call. If the scope changes we tell you before doing the work, not on the invoice.
Automated scanning finds the findings everybody already knows about. The vulnerabilities that actually get organisations compromised are chained together by hand, which is how we test.
Typical two-week engagement for a mid-sized external and internal test, including report and readout.
Containment first, forensics second, and a written timeline you can give to your insurer and the ICO. We work alongside your IT team rather than taking over from them.
Includes out-of-hours cover, a named responder and one annual test. Ad-hoc response charged at day rate.
Most providers send a questionnaire and mark it. We do the remediation work with you first, so the certificate reflects something that is actually true.
Cyber Essentials Plus including gap analysis, remediation support and certification body fees.
// honest answer
If you have no asset inventory, no MFA and no backups you have tested restoring from, a penetration test will simply produce a long document confirming that. We will tell you to spend the money on those three things first and come back next year.
It costs us an engagement and saves you one, which over a decade has turned out to be a reasonable trade.
Book a scoping call