Consulting · cybersecurity

Defensive security, run as an operating discipline.

Not a scan and a report. Continuous visibility of your attack surface — including the AI systems your teams have quietly put into production — findings validated before they reach your backlog, detection that's actually been tuned, and a response capability rehearsed before you need it.

Vulnerability Assessment & Remediation

Automated scanning paired with expert manual validation — so effort goes to exploitable risk instead of noise.

Attack Surface Management

Continuous discovery of internal and external attack surface, including the forgotten and shadow assets nobody has an owner for.

Cloud Security

Posture management, IAM least-privilege review, and container security across AWS, Azure, and GCP.

EDR / XDR Setup & Optimisation

Selection, deployment, and the continuous tuning of endpoint platforms that most teams deploy once and never revisit.

Incident Readiness & Response

Tested playbooks, tabletop exercises, and a logging strategy — so response is practised rather than improvised at 3am.

Audit & Compliance Consulting

ISO 27001, SOC 2, PCI DSS, HIPAA, and GDPR alignment: policy, control mapping, and audit preparation.

AI Security

Securing the AI your organisation is already using — model and agent inventory, prompt injection and data-leakage testing, and access control over what those systems can reach.

A dedicated government and public-sector engagement model is in development. Available on request for qualifying engagements.
AI security

Your AI attack surface is already live.

Someone in your organisation has connected an LLM to a data source this quarter. Possibly with an API key in a config file, possibly with read access to more than they realised, and almost certainly without a security review. This is the practice that catches that.

Discovery & inventory

What models, agents, copilots, and API keys are actually in use — including the shadow AI nobody put through procurement.

Prompt injection testing

Adversarial testing of your AI features: direct and indirect injection, jailbreaks, and the data they can be talked into revealing.

Data leakage review

What leaves your boundary in prompts and embeddings, what a retrieval layer can reach, and whether tenant isolation actually holds.

Agent permissions

Agents act with real credentials. We review what they're allowed to touch and what a compromised one could do with it.

Supply chain

Model provenance, third-party AI vendors, and the plugins and tool integrations that quietly extend your trust boundary.

Governance & assurance

Usage policy, acceptable-use controls, and alignment with ISO 42001 and the EU AI Act where they apply to you.

We build AI-native products ourselves, which is exactly why we're careful about them. Most of these failure modes we found in our own systems first.

How this connects

The same thinking that went into our CTEM platform.

We didn't build an exposure management product and then start a security practice. It happened the other way round — the practice kept hitting the same wall, which is that finding things is easy and knowing which of them matters is not.

You can engage either side independently. Plenty of clients take the consulting and run their existing tooling.

01
Validated, not just detected

Every finding we hand you has been checked by a person who can explain why it matters here.

02
Fixes ranked by reachability

Severity scores ignore your architecture. We don't.

03
Closure is evidenced

Retests are tied to the original finding, so "remediated" is a demonstrated fact.

Start with an attack surface review.

It's the fastest way to find out whether your current picture is complete.