How we work
01Scope and authorisation
Written authorisation, agreed scope, timing and rules of engagement.
02External exposure
What is reachable from the internet, established independently of the IT inventory.
03Penetration testing
Exploitation attempts within the agreed scope, with all activity logged.
04Domain assessment
Relationships between objects - delegation, privileged membership, legacy protocols, backup access.
05Social engineering
Phishing simulation where agreed, with results reported in aggregate, never per person.
06Reporting
One report for the technical team with reproduction steps, one summary for the board.
What you get
Technical report
Board summary
Ranked findings
Remediation plan
Retest
Measures of Annex II this service covers
04 Security of human resources and digital identities
05 Basic cyber hygiene practices
06 Securing network cyber security
07 Physical and logical access control to network and information systems
Sectors where it is most in demand
Check for yourself before we talk
Entity categorisation check
Readiness check against the 13 measures
Incident reporting deadline calculator
Not sure where you stand?
Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.