Scanners produce a list. Operators find the route that connects it. Below is one path from a real engagement — four findings that every tool involved rated low or ignored entirely, and the twenty-six minutes they cost.
Engagement excerpt — one path, five steps
Composite. Names, addresses and timings changed.
- ExposedLowExposedLow
- LeakedLowLeakedLow
- ValidMediumValidMedium
- EscalateHighEscalateHigh
- OwnedCriticalOwnedCritical
The pipeline deploys to production
Change the build definition and the runner executes it holding deploy credentials. Twenty-six minutes from the first DNS lookup to code running in the production estate.
Evidence
deploy-role → * · 26m elapsed
Automated scan
Not reported
A scanner saw step one and filed it as informational. It had no reason to try the key, and no way to know the bucket it opened held the build definitions. Five findings is a list. This is a path.
§ 01 — Conviction
An automated scan tells you what is unpatched. Only an operator tells you what is reachable — how three dull findings chain into a breach, and what somebody walks out with.
- 20+
- Engagements delivered
- 100%
- Testing executed right
- R0
- Charged for remediation retests
§ 02 — Testing
Seven disciplines, grouped by what they attack.
Each is executed by a senior tester against a threat model built for your estate. Findings are proven by exploitation, scored on business impact, and retested free once you have fixed them.
- ApplicationWeb Application & API TestingManual, exploit-led testing of the applications and APIs your business runs on.
- InfrastructureNetwork & Infrastructure TestingExternal and internal intrusion testing that proves how far an attacker really gets.
- CloudCloud & Kubernetes TestingAWS, Azure, GCP and container estates attacked the way real operators attack them.
- ApplicationMobile Application TestingiOS and Android binaries, storage and backends pulled apart on real devices.
- Full scopeRed Team & Adversary SimulationObjective-driven, multi-vector campaigns run against your live defences.
- HumanSocial Engineering & PhishingPhishing, vishing and physical intrusion that test the human perimeter safely.
- ProgrammeContinuous Pentesting (PTaaS)Testing that keeps pace with your releases, with findings streamed as they're found.
§ 03 — How an engagement runs
Five steps, in this order, every time.
No engagement starts without a signed authorisation letter and an agreed blast radius. Nothing about the process is improvised.
- 01
Scope
Targets, roles and rules of engagement agreed in writing. Fixed price, named lead tester, signed authorisation before anything is touched.
- 02
Map
We enumerate what you actually expose, which is routinely more than the asset register says, and build the threat model the testing runs against.
- 03
Exploit
Manual attack execution and chaining. Criticals reach you the day we find them, by phone, not in a report six weeks later.
- 04
Report
Reproduction steps, evidence, business impact and a remediation order of play. Written to be handed straight to your engineers.
- 05
Retest
You fix, we verify, at no extra cost. Closes with an attestation letter your auditors and enterprise customers accept.
§ 04 — What you get
Four things land on your desk.
A pentest is only worth what your team can do with it on the Monday after.
A report an engineer can act on
Every finding carries the exact request, the payload, the evidence and the fix. No screenshots of a scanner dashboard.
A readout for the people who fund it
A separate executive summary in plain language, plus a walkthrough call with whoever needs to hear it.
A free retest
Fix the findings and we verify them at no charge, then reissue the report with the closures recorded.
An attestation letter
Formatted for SOC 2, ISO 27001, PCI DSS and customer due-diligence questionnaires. A redacted shareable version on request.
§ 05 — Sectors
Threat-modelled for your industry.
Adversaries, regulators and downtime tolerance differ by sector. So do the rules of engagement we write.
Financial Services
Payment rails, open banking APIs and core platforms tested the way fraudsters test them.
Government & Public Sector
Citizen-facing portals and legacy estates probed before a hostile actor gets there.
Healthcare & Medical Schemes
Patient platforms, claims systems and clinical networks tested without disrupting care.
Mining, Energy & Utilities
IT-to-OT attack paths proven safely, before an incident stops production.
Telecommunications & Technology
Continuous testing that keeps pace with the rate you ship.
Retail & Consumer
Checkout, loyalty and store systems attacked before peak trade does it for you.
§ 06 — Writing
From the practice.
§ 07 — Start
Send us the scope. We'll tell you what we'd attack.
A fixed-price proposal, a named lead tester and a start date, within one business day. If we think you need something other than a pentest, we'll say so.
