The Practice · iii.

Quiet diligence on the things that carry risk.

Quiet diligence on the things that carry risk: review, hardening, and the documentation that lets you sleep before an audit.

Security work is mostly unglamorous. It is reading carefully, asking who can reach what and why, and writing the answers down so the next person does not have to guess.

The failures that cost businesses money are rarely ingenious. They are an old credential nobody revoked, a permission granted for one afternoon three years ago, a dependency that stopped being maintained without anyone noticing. Finding those is a matter of diligence rather than cleverness.

What the work involves

Most breaches are not clever. They are something obvious that nobody was responsible for.

Written to be read by outsiders

The output is a findings document ordered by consequence rather than by how interesting each item was to discover. Every finding states the risk in plain terms, what exploiting it would actually require, and what we recommend doing about it. Where something is a reasonable risk to accept, we say so, and we say why.

It is written on the assumption that someone outside your business will read it eventually: a buyer's technical adviser, an insurer, a regulator.

What this is not

We are not a certification body and we issue no attestations. If you need a formal certification, that requires an accredited assessor, and our part is to prepare you for that process rather than to stand in for it.

Nor is a single review a security posture. A point-in-time assessment tells you where you stand on the day it was written. Keeping that true is an operating habit, and if that is what you actually need, a standing arrangement will serve you better than a report.

Begin a conversation

We reply to every serious enquiry personally. Tell us a little about the firm and what you are trying to build.

Request an introduction