Services

Every engagement has a written scope, a named deliverable, and a plain-language readout at the end.

Third-party vendor risk review

Your vendors hold your data and often have access to your systems. A vendor review tells you how well they protect both, before a contract makes their risk your risk.

What we look at

  • Security questionnaire responses, checked against evidence
  • Policies, certifications, and audit reports the vendor provides
  • Publicly visible exposure: domains, email security, leaked credentials
  • How the vendor handles access, incidents, and its own suppliers

What you receive

  • A scored risk rating with the reasoning behind it
  • The specific gaps that matter for how you use this vendor
  • Recommended contract terms or controls to close them
  • A short readout call with your team

Threat hunting

Alerts catch what someone already wrote a rule for. A hunt starts with a hypothesis about how an attacker would operate in your environment, then goes looking for the evidence.

What we look at

  • SIEM and log data, including Microsoft Sentinel using KQL
  • Identity activity, endpoint telemetry, and network traffic
  • Persistence, lateral movement, and data staging techniques

What you receive

  • Findings with supporting evidence and severity
  • The hunt queries we used, so your team can rerun them
  • Detection gaps and recommended new alerts

Vulnerability assessment

A scan produces a list. An assessment tells you which items on that list an attacker would actually use, and what to fix first.

What we look at

  • Internet-facing systems and services
  • Internal hosts, configurations, and patch levels
  • Cloud and identity misconfigurations

What you receive

  • Prioritized findings ranked by real-world exploitability
  • Step-by-step remediation guidance
  • An executive summary for leadership

Cyber threat intelligence

Intelligence that answers your questions: who is likely to target an organization like yours, how they get in, and which of your defenses they would test first.

What we look at

  • Threat actors active in your industry and region
  • Their known tactics, techniques, and infrastructure
  • Exposure of your organization's data and credentials

What you receive

  • A written threat profile mapped to MITRE ATT&CK
  • Priority defensive actions tied to each threat
  • Optional recurring briefings

Identity and access security review

Most breaches run through an account. We review how identities are created, granted access, and removed across Active Directory and Microsoft Entra ID.

What we look at

  • Privileged accounts and administrative roles
  • MFA coverage and conditional access policies
  • Stale accounts and joiner, mover, and leaver processes

What you receive

  • A list of risky accounts and permissions to fix
  • Policy recommendations sized to your environment

AI system security assessment

For organizations deploying large language models or AI agents. We assess how they could be misused, what data they can reach, and what guardrails are in place.

What we look at

  • Prompt injection and data leakage risks
  • Tool and data access granted to AI agents
  • Logging, monitoring, and human oversight

What you receive

  • A threat model for your AI deployment
  • Prioritized controls to reduce misuse and exposure

Scope an engagement

Tell us what you need assessed and we'll reply with a proposed scope and price.

Contact us