
We work in five areas of cyber defence: security assessments, dark-web exposure monitoring, fast and discreet incident response, industrial (OT/SCADA) security and red-team operations. The work suits organisations that treat security as a board-level matter.
Five capabilities, each delivered as its own service.
Each has its own scope and timeline, and you can commission one without the others. The sections below set out how we work and what you receive.
NIS2 and ISO 27001 compliance is handled by our dedicated practice, IHS Audit.
Cyber Security Assessment
Vulnerability assessment and penetration testing for web applications, networks, mobile, cloud and identity. Our testers chain findings into real attack paths that scanners miss. Reporting is ranked by risk and readable at board level.
- Scope and rules of engagement set against your threat model and risk tolerance
- External and internal reconnaissance: passive OSINT, attack-surface mapping, authenticated testing where relevant
- Web applications per OWASP Testing Guide / ASVS; networks per OSSTMM and PTES; mobile per OWASP MASVS; cloud per CIS Benchmarks (AWS / Azure / GCP); identity via an Active Directory / Azure AD / Okta hardening review
- Manual exploitation, vulnerability chaining and post-exploitation checks
- Lateral-movement and privilege-escalation paths mapped to your assets
- Wireless, segmentation and physical-access testing where authorised
- Re-test after remediation, on request
- Full technical report with attack chains, proof-of-concept evidence and CVE / CWE mappings
- Remediation advice ranked by risk, with effort estimates
- Executive summary in business language, ready for the board
- Optional re-test letter confirming the before and after position
- Briefing for your in-house security team
Threat Exposure Management (TEM)
Continuous monitoring of the surface, deep and dark web: leaked credentials, brand impersonation, exposure through suppliers, and your data on illicit marketplaces. An ongoing service, not a project.
- Coverage of dark-web forums, Telegram channels (58,000+ tracked), ransomware leak sites, paste sites, illicit marketplaces and stealer logs
- Leaked credentials matched to your identity providers (Active Directory / Azure AD / Okta / Workspace) for immediate revocation
- Brand-impersonation and look-alike domain monitoring, with takedowns via hosting providers and registrars
- Breaches at partners and suppliers traced back to your organisation
- Threat-actor profiles and historical search across forums and breach data
- AI-assisted translation of foreign-language dark-web chatter into structured intelligence
- Real-time alerts by priority; high-severity alerts go to a named analyst
- Monthly briefing with threat summary and KPI dashboard
- Takedown management for impersonation and look-alike domains
- Integration with your SIEM / SOAR / ticketing (Splunk, Sentinel, QRadar, ServiceNow) where needed
- Quarterly threat-actor updates for your sector
- One named analyst as your point of contact
Incident Response — Quick & Discreet
Fast activation when a breach is suspected or confirmed. Discreet in every report and conversation. Available 24/7 under a retainer.
- 24/7 activation line; a named first-response analyst within the agreed SLA
- Triage and threat-actor identification: group, tooling fingerprint, likely objectives
- Containment with minimal business disruption: segmentation, account isolation, controlled traffic blocks
- Forensic preservation of endpoint memory, disk, network, cloud workloads, identity audit logs and SaaS audit trails per ISO/IEC 27037
- Root-cause analysis mapped to MITRE ATT&CK and the Diamond Model; NIST 800-61-aligned playbook
- Communications support where retained: legal, regulatory disclosure, media holding statements
- Post-incident threat hunt for residual access and parallel intrusions; hardening roadmap based on what failed
- Forensic report that meets chain-of-custody standards
- IOC list and TTP-mapped attacker profile
- Intrusion timeline showing where detection and response could have stepped in
- Log of containment and recovery decisions you can defend to regulators, insurers and counsel
- Post-mortem briefing and hardening roadmap
- Threat-hunt report for the wider environment
Industrial / SCADA / OT Security
Security assessment for sites where downtime is not an option: pharma, energy, water, logistics, transport, manufacturing. Production keeps running while we test.
- Passive observation and asset discovery before any active testing: span-port capture and controlled traffic analysis, no aggressive scanning of OT
- Asset inventory across PLC, HMI, RTU, DCS, SCADA, historian and engineering workstations
- Segmentation review against the Purdue Reference Model and IEC 62443 zones and conduits
- IT/OT boundary review: DMZ controls, firewall rules, jump hosts, USB and removable-media policy, vendor access
- Hardening review of engineering workstations (Windows / vendor OEM)
- Active testing only in agreed maintenance windows
- Method aligned to ICS-CERT, NIST 800-82, IEC 62443 and IEC 61850 (where power infrastructure is in scope)
- OT asset inventory with criticality mapping
- Segmentation map: current against target state, per IEC 62443 zones and conduits
- Findings ranked by exposure and downtime impact
- Hardening roadmap planned around maintenance windows
- Optional tabletop exercise for OT incident response (cascading failure, ransomware on OT)
Red Team & Adversary Simulation
Realistic attack simulations for organisations with mature security programmes. The team stays hidden and tests whether your detection and response hold up, using MITRE ATT&CK tactics. For corporate, financial and critical-infrastructure clients ready for advanced testing.
- 01Plan, scope and threat model: rules of engagement, assumed-breach starting points, blue-team awareness, success criteria
- 02Reconnaissance: OSINT, dark-web research before the attack, supply-chain mapping
- 03Initial access: phishing, exposed services, supply chain, or physical entry and drop devices
- 04Privilege escalation, persistence and lateral movement towards the agreed objectives
- 05Controlled completion of the objective, such as simulated data exfiltration or critical-system access
- 06Optional purple-team phase: detection engineering together with the blue team
- 07Joint red/blue debrief
- TTP-mapped technical report with the full attack timeline
- ATT&CK heatmap: techniques used, detected and missed
- Video proof of concept for key moments, where relevant
- Detection-rule and control recommendations (Splunk, Sentinel or any SIEM)
- Joint red/blue debrief session
Speak with a cyber defence specialist.
We will respond within one business day. Initial conversations are confidential and without obligation.
Request a Quote