Assessments
What we test, how we test it, and what you receive
Five focused service types. Each engagement is scoped in writing before any work begins, and every deliverable is built to be acted on, not filed away.
01 Web & API Testing
Scope
- •Authentication, session management and account recovery flows
- •Authorisation: role, tenant and object-level access control
- •Input handling: injection, file handling, deserialisation
- •Business-logic abuse: workflow bypasses, race conditions, payment and quota logic
- •API-specific concerns: excessive data exposure, mass assignment, rate limiting
Method
Primarily manual testing with purpose-built tooling where it helps. We test with agreed accounts against agreed environments, and we never run destructive or availability-impacting checks without explicit sign-off.
Deliverable
A written report with an executive summary, reproducible findings (exact requests, affected routes, evidence), and remediation ordered by real risk. A retest of fixed findings is included when agreed in scope.
02 Cloud Security Review
Scope
- •Identity and access management: roles, policies, key and credential hygiene
- •Network exposure: public endpoints, security groups, ingress paths
- •Data stores: encryption, access policies, backup exposure
- •Secrets management and configuration drift
- •Logging, monitoring and alerting coverage
Method
Read-only review using scoped credentials you provision, combined with architecture walkthroughs with your team. We do not need, and do not ask for, production admin access.
Deliverable
A prioritised findings list where each item names the affected resource, the risk in context, and the specific configuration change that resolves it.
03 Application Security Review
Scope
- •Authentication and authorisation logic in code
- •Input validation and output encoding at trust boundaries
- •Secrets handling, cryptography use and dependency risk
- •Security-relevant architecture: trust boundaries, tenancy, data flow
Method
Code-assisted review focused on the paths an attacker would take, not a line-by-line audit of the whole codebase. Access via a read-only repository grant or supervised walkthrough, whichever you prefer.
Deliverable
Findings tied to specific files and code paths, each with concrete remediation guidance your engineers can implement directly.
04 Digital Forensics
Scope
- •Evidence acquisition and preservation with a documented chain of custody
- •Disk, memory and log analysis across affected systems
- •Timeline reconstruction: initial access, movement, actions taken
- •Root-cause analysis of the entry path and scope of exposure
- •Indicators of compromise for your monitoring going forward
Method
Forensically sound handling from the first touch: originals are imaged and hashed before analysis, every step is logged, and findings are tied to verifiable artefacts rather than speculation.
Deliverable
A certified forensic report suitable for legal, insurance and compliance proceedings, with a plain-language account of what happened and concrete steps to close the entry path.
05 Compliance & Certification Readiness
Scope
- •HIPAA: safeguards review and risk analysis for handlers of health data
- •PCI DSS: scoping, gap assessment and remediation toward attestation
- •SOC 2: control design and evidence preparation for Type I / Type II audits
- •ISO 27001: ISMS build-out, risk treatment and internal audit before certification
- •Ongoing evidence collection habits so the next audit is cheaper than the first
Method
Gap assessment against the target framework first, then hands-on help implementing the missing controls: policies, technical safeguards and monitoring. Certification itself is issued by accredited auditors; we prepare you and support you through their audit.
Deliverable
A control-by-control gap report, a prioritised remediation plan with owners, and audit-ready evidence, plus support alongside your auditor or QSA until the certificate or attestation is in hand.
Full capabilities
Everything we test, review, and defend
Beyond our core assessments, the studio delivers a full range of offensive, defensive, and compliance engagements. Tell us what you need — these are the capabilities we bring.
01
Application Security
- •Web Application Penetration Testing
- •API Penetration Testing
- •Mobile App Penetration Testing
- •Secure Source Code Review
- •SaaS Security
- •E-commerce Security
- •DevSecOps
02
Network & Infrastructure
- •Network Penetration Testing
- •Wireless Penetration Testing
- •Firewall Security Audit
- •Server Hardening
03
Cloud Security
- •Cloud Security Audit
- •Cloud Configuration Review
- •AWS, Azure & GCP Hardening
- •Container & Kubernetes Security
04
Threat Simulation
- •Red Team Engagements
- •Social Engineering
- •Phishing Simulation
05
Industrial & IoT
- •IoT Penetration Testing
- •OT Security Assessment
- •ICS / SCADA Security Testing
06
Governance, Risk & Compliance
- •ISO 27001 Readiness
- •SOC 2 Readiness
- •PCI DSS
- •HIPAA
- •SAMA & SWIFT CSP
- •Security Architecture Review
07
Data Privacy
- •DPO as a Service
- •GDPR Compliance
- •PDPL Assessment
- •Data Privacy Consulting
08
Managed Security
- •Managed Vulnerability Scanning
- •Managed Threat Hunting
- •Security Operations (SOC)
- •Virtual CISO (vCISO)
- •Annual Security Program
09
Incident Response & Forensics
- •Digital Forensics
- •Incident Response
- •Compromise Assessment
Engagements are fixed-scope and fixed-price once agreed. If you are not sure which assessment fits, describe your situation and we will recommend a scope, including telling you honestly if you do not need us yet.