Service
Cybersecurity
Overview
Security work goes wrong in two directions. Either it produces a 200-page report nobody acts on, or it becomes a shopping list of tools that leaves the underlying problems untouched.
We assess against the way your organisation actually works, rank findings by what an attacker could realistically achieve, and — where you want us to — implement the remediation rather than handing it back to a team without the capacity to do it.
Threat modelling starts at the architecture, not the perimeter
Capabilities
What cybersecurity covers
Security assessment and testing
Application and infrastructure review against recognised frameworks, with findings ranked by exploitability and business impact.
Hardening and remediation
Closing the findings — identity and access, network boundaries, logging, patching and configuration — with verification that each fix holds.
Policy and compliance support
Practical documentation that reflects what you really do, produced to support certification or customer due diligence.
Incident readiness
An escalation path, a response plan and a rehearsal, so the first real incident is not also the first time anyone has thought about it.
Process
How we deliver it
The four stages cybersecurity moves through, and what you have at the end of each.
Scope and rules of engagement
Written authorisation, agreed boundaries and defined communication paths before any testing begins.
Assess
Structured review of the in-scope estate against a recognised framework, with evidence captured for each finding.
Report and prioritise
One report for the technical team and one for decision-makers, sharing the same prioritised list.
Remediate and retest
Fixes implemented or supported, then retested so closure is demonstrated rather than assumed.
Copy pending founder sign-off
PRD §8 requires the exact scope of each service to be confirmed before final copy. Outstanding for this one:
- Which frameworks and standards are followed and can be named publicly — ISO 27001, NIST, OWASP (PRD §27)
- Which security certifications held by the team can be displayed for credibility (PRD §27)
- Whether penetration testing is delivered in-house or through a partner
Related work
Case studies
No published case studies yet
We publish case studies only once the client has approved the wording, and none are cleared for publication yet. Ask us directly and we'll talk you through comparable work under NDA.
Ask about comparable workGet started
Request a quote for cybersecurity
Tell us what you need and we'll come back with a scope, a price and the risks as we see them.
Prefer to talk first? Send a short message and we'll set up a call.
Draft copyAlso available
Other capabilities
DevSecOps
Pipelines that ship faster and catch security problems before they reach production — not after a customer finds them.
Full Stack
One team across the whole system — the architecture, the services behind it, and the payment rails it has to settle through.
UI/UX Design
Research, interface design and reusable design systems — accessible by construction, not by later remediation.

