Services
Every engagement has a written scope, a defined deliverable, and a plain-language readout at the end.
Vendor risk review
Your vendors hold your data. Know how well they protect it before their risk becomes yours.
What we look at
- Security questionnaire answers, checked against evidence
- Policies, certifications, and audit reports
- Public exposure: domains, email security, leaked credentials
What you receive
- A scored risk rating with the reasoning behind it
- The gaps that matter for how you use this vendor
- Recommended contract terms and controls
Threat hunting
Alerts catch what someone already wrote a rule for. A hunt goes looking for everything else.
What we look at
- SIEM and log data, including Microsoft Sentinel
- Identity, endpoint, and network activity
- Persistence, lateral movement, and data staging
What you receive
- Findings with evidence and severity
- The hunt queries, so your team can rerun them
- Detection gaps and new alert recommendations
Vulnerability assessment
A scan produces a list. An assessment tells you what an attacker would actually use.
What we look at
- Internet-facing systems and services
- Internal hosts, configurations, and patching
- Cloud and identity misconfigurations
What you receive
- Findings ranked by real-world exploitability
- Step-by-step remediation guidance
- An executive summary for leadership
Cyber threat intelligence
Who is likely to target an organization like yours, how they get in, and what to do about it.
What we look at
- Threat actors active in your industry and region
- Their tactics, techniques, and infrastructure
- Exposure of your data and credentials
What you receive
- A threat profile mapped to MITRE ATT&CK
- Priority defensive actions for each threat
- Optional recurring briefings
Identity and access review
Most breaches run through an account. We review how yours are granted, used, and removed.
What we look at
- Privileged accounts and admin roles
- MFA coverage and conditional access
- Stale accounts and offboarding gaps
What you receive
- A list of risky accounts and permissions
- Policy recommendations sized to your environment
- A readout call with your team
AI system security assessment
For organizations deploying language models and AI agents.
What we look at
- Prompt injection and data leakage risk
- Tools and data your AI agents can reach
- Logging, monitoring, and human oversight
What you receive
- A threat model for your AI deployment
- Prioritized controls to reduce misuse
- Guidance for safe rollout
Not sure which one you need?
Tell us what worries you most. We'll recommend the smallest engagement that answers it.