Skip to content

Services

Five engagements,
one consultant.

Each engagement is defined by the decision you need to make, not by a methodology or toolset.

01

Penetration testing

Problem

You have a web application, an internal network, a cloud tenancy, or a mobile app, and you need an honest view of what an attacker could do to it — a technical report you can hand to the team who will fix it.

Engagement

Scope is defined in writing against the specific asset. Most pentests run one to three weeks of active testing plus a week of reporting. Critical findings are surfaced the day they are found so they can be fixed in flight.

Deliverables

  • Executive summary (one page)
  • Technical findings report with reproducer steps
  • Remediation guidance prioritised by exploitability, not CVSS alone
  • Retest of fixed issues within 60 days, included

Duration

Two to five weeks end to end, depending on scope.

When to choose

You know which asset matters and you need an independent technical view of its security posture, fast and without ceremony.

02

Red team & adversary emulation

Problem

You have mature defences and want to know how they hold up against an adversary already inside your perimeter. Assumed breach, objective-driven, measured against both your preventive and detective controls.

Engagement

Starts with an intent-setting session: who are we emulating, what does success look like, and what happens if the blue team detects us. A four-to-eight-week operation from initial foothold to documented impact, paced so your SOC learns during the activity, not only from the report.

Deliverables

  • Pre-engagement scoping document and rules of engagement
  • Weekly written status during active phases
  • Full kill-chain narrative with timestamped artefacts
  • Sigma / KQL / Splunk detection rules for each technique used
  • Joint debrief with the blue team

Duration

Four to eight weeks.

When to choose

Your security programme is past the basics and you want to know how it performs against a real adversary profile, not a checklist.

03

Security architecture review

Problem

You are about to make a large design decision — a new cloud region, an identity consolidation, a zero-trust rollout — and want a second pair of eyes before the money is committed. Or you inherited an environment and need to know where it is weak.

Engagement

Document review plus two to four working sessions with the engineers responsible. I review what you actually have, not a reference architecture. The deliverable is a short, reasoned report: what is solid, what is brittle, what to change, in what order.

Deliverables

  • Written architecture review (20–40 pages)
  • Prioritised remediation backlog
  • Target-state diagram (if useful; not by default)
  • One board-level summary

Duration

Two to four weeks.

When to choose

You value an opinion more than a framework, and you want someone to commit to a view in writing.

04

SOC design & build consultancy

Problem

You are standing up an in-house security operations capability, or rethinking one that has grown unruly. You want a design that holds for the next three years, not the next quarter's tool renewal.

Engagement

Advisory grounded in having designed and run a SOC platform end to end — a 700+ rule, ATT&CK-aligned detection stack with automated triage. I work with your team on detection coverage, tool rationalisation, staffing, and on-call structure. I do not resell products or take referral fees.

Deliverables

  • Target operating model document
  • Detection coverage map against MITRE ATT&CK
  • Tool rationalisation recommendation with vendor-neutral reasoning
  • Staffing and on-call proposal

Duration

Four to eight weeks.

When to choose

You are making or re-making a multi-year investment and want an independent view before committing.

05

Incident response retainer

Problem

You want a named responder on call, familiar with your environment, who is useful within the first thirty minutes of an incident — not spending the first days arranging access.

Engagement

A monthly retainer covering onboarding (environment access, runbook review, an annual tabletop), guaranteed response-time SLAs, and a pre-agreed rate for incident work. Retainer fees are credited against incident work billed in the same year.

Deliverables

  • Retainer agreement with named SLAs
  • Access and tooling validated during onboarding
  • Annual tabletop exercise
  • During an incident: coordination, containment guidance, written findings

Duration

Twelve-month minimum term, renewable.

When to choose

You cannot justify a dedicated IR team, but an incident is not a hypothetical.

Engagement model

All engagements are scoped under NDA and billed in EUR, fixed-fee or day rate, with mutual notice of two weeks. References available on request. See how an engagement runs for the full shape.

Not sure which fits?

A 30-minute call is enough to tell. If I am not the right consultant for your situation, I will say so.