Security you can actually evidence
A PDF full of findings helps nobody. We test your systems the way an attacker would, sit with your engineers to close the gaps, then re-test to prove they are closed.
- Engagements include a free re-test
- 100%Engagements include a free re-test
- Critical findings reported, never held back
- 48 hrsCritical findings reported, never held back
- ISO 27001 & GDPR readiness supported
- SOC 2ISO 27001 & GDPR readiness supported
The conversations that bring people here.
None of these are unusual, and none of them mean anyone did a bad job. They are what happens when a business grows faster than the systems holding it up.
Our first job is to work out which of these is actually costing you money — and to tell you if the answer is none of them.
An enterprise deal is blocked on a security questionnaire.
You are pursuing SOC 2 and do not know where you stand.
Nobody has reviewed permissions since the company was ten people.
You had an incident and want certainty it cannot happen twice.
Inside cyber security.
Six areas we cover in depth. You do not have to take all of them — most engagements start with two or three.
Penetration testing
Authorised, scoped testing of web apps, APIs, cloud and internal networks — mapped to OWASP and reported with reproducible steps.
Secure code review
Manual review of authentication, authorisation, data handling and dependencies, plus static analysis tuned to stop crying wolf.
Cloud & identity hardening
Least-privilege IAM, network segmentation, secrets management and configuration baselines across AWS, Azure and GCP.
Compliance readiness
Gap assessment and evidence preparation for SOC 2, ISO 27001, GDPR and HIPAA — including the policies auditors ask for.
Incident response planning
Runbooks, escalation paths and tabletop exercises, so the first time your team runs the plan is not during a real breach.
Monitoring & training
Logging and alerting that surfaces real signals, plus phishing simulation and developer security training people remember.
Everything listed here is in the contract.
No line items that turn out to be optional extras later. If it is on this list it is scoped, priced and delivered.
- Scoped rules of engagement
- Technical findings report
- Executive risk summary
- Reproduction steps per finding
- Prioritised remediation plan
- Fix-verification re-test
- Security questionnaire support
- Attestation letter for your clients
We pick boring, well-supported tools on purpose. Everything below is something your next hire can already use.
- Burp Suite
- Nmap
- OWASP ZAP
- Semgrep
- Snyk
- Wazuh
- Terraform
- Vault
- AWS Security Hub
You own every account, repository and licence we set up on your behalf.
How a cyber security engagement runs.
Fixed phases with a defined deliverable at the end of each. You approve one before the next begins.
- 01Week 1
Scope & authorise
Written rules of engagement, defined targets, timing windows and escalation contacts. Nothing is touched without signed authorisation.
- 02Week 1–3
Test
Reconnaissance, automated scanning and manual exploitation. Anything critical is reported the same day rather than saved for the report.
- 03Week 3–4
Report & walk through
A technical report your engineers can act on, an executive summary your board can read, and a live session covering both.
- 04Week 4–8
Remediate & re-test
We support your team through the fixes, re-test every finding, then issue an attestation letter you can send to customers.
What this looks like in practice.
Sift Health — Health Tech. 11 weeks of work, with the numbers to show for it.
A tenant isolation flaw found in six hours, and SOC 2 in eleven weeks
Sift handles protected health information for 40 clinics and had never been independently tested. An enterprise prospect made SOC 2 Type II a condition of contract, with a hard deadline. The engineering team suspected their permission model had gaps but had no way to characterise the risk.
- To first critical finding
- 6 hrsTo first critical finding
- Critical flaw patched and verified
- 24 hrsCritical flaw patched and verified
- Findings closed and re-tested
- 31Findings closed and re-tested
- To audit-ready SOC 2 posture
- 11 wksTo audit-ready SOC 2 posture
Clients who bought exactly this.
Every quote below is from a client of this specific service. We will happily put you on a call with any of them before you sign anything.
They found a broken access control in our API that let one tenant read another tenant's records. Reported within six hours of starting, patched the same day. That single finding justified the entire engagement.
We had failed a client security review twice. OnyxEra got us through readiness in eleven weeks and the deal closed the following month.
The tabletop exercise was uncomfortable in exactly the right way. We rewrote our escalation policy the next day.
Cyber Security, answered straight.
If something is not answered here, ask us directly — you will get a straight answer rather than a sales call.
We prefer a staging environment that mirrors production. Where production testing is genuinely necessary, we agree timing windows, rate limits and a stop signal in the rules of engagement, and we keep a live channel open with your team throughout.
A signed rules-of-engagement document from someone with authority over the systems in scope, plus written permission from your hosting provider where their terms require it. We do not begin testing without it — no exceptions.
Both. The report is the start, not the deliverable. Our engineers pair with yours on remediation, review the patches, and re-test every finding at no additional cost within ninety days.
We handle the technical readiness: gap assessment, control implementation, evidence collection and the penetration test most auditors require. The audit itself must be performed by an independent licensed firm, and we will introduce you to ones we trust.
Annually as a baseline, and after any significant architectural change, major release or new compliance requirement. Teams shipping quickly usually pair an annual full test with continuous automated scanning in the pipeline.
Ready to talk about cyber security?
Bring the messy version of the problem. Thirty minutes on a call is usually enough for us to tell you what it would take and roughly what it would cost.
Typical reply time: under 4 business hours