01 — Staying Small · Herbarium
The whole collection fits on one sheet.
That is deliberate.
A consultancy grows by hiring faster than it can train, and the cost is paid quietly; in reports written by someone who was never in the room, and in findings triaged by a junior against a checklist. We would rather stay small and remain answerable.
You will always know who tested your estate. You will always be able to speak to them.
02 — Our People · Rosa investigatio
Liam Follin
Founder · Senior Consultant Chartered Cyber Security Professional (ChCSP) · Dual CHECK Team Leader (Application & Infrastructure)
| Handle | gr4y-r0se |
|---|---|
| Chartered | ChCSP · 010829 |
| Qualification | CHECK Team Leader — Application & Infrastructure |
| Disciplines | Web, mobile & desktop applications · APIs · Azure & Office 365 · Internal & external infrastructure · Red teaming · Social engineering · WiFi · Firewalls · Operational technology · Embedded systems · Z-Series mainframes |
| Research | Data exfiltration via DNS · Cross-site scripting |
| Correspondence | liam.follin@therose.garden |
| Repository | github.com/Gr4y-r0se |
There is no naturally grey rose. Breeders have spent the better part of a century chasing one and arrived at lavender, ash, smoke – never quite the thing itself. It is a serviceable handle for this work. The interesting ground is rarely black or white, and the closest anyone gets is a careful approximation, properly documented.
Liam founded The Rose Garden after 7 years spent almost entirely inside other people’s networks, with their written permission.
§ 03 — SPEAKING · Semina
Research that stays in the lab is a hobby. TRG consultants have spoken at conferences and community events across the UK and Europe since 2022.
Forthcoming
Scientific Hooliganism: The History of Hacking – Hack Glasgow, 15 August 2026, 10:30 A look backwards, at where the craft actually came from.
Understanding alert(1) – Hack Glasgow, 15 August 2026, 13:00 A workshop for people who are not yet sure what JavaScript is doing in their browser.
No More Alert(1) – BSides Kraków, 26 September 2026, 13:00 On why cross-site scripting is treated as a solved problem, and why that is naive.
Selected past engagements
- Learning to Trust Again – OSFF London 2025
- Tales of DOMinica – SteelCon · BSides Exeter On DOM-based XSS: the third flavour, why it goes unfound, and a set of labs released alongside.
- No More Alert(1) – SecuriTay 2022 · BSides Belfast · DC151 On turning a proof-of-concept pop-up into demonstrated impact.
- Domain Name Stupidity – BSides Cambridge 2023 · BSides Bristol 2023 · DC151
- How to Get Away with Hacking – BSides Leeds 2023 · Hack Glasgow An unsentimental route into the profession, from apprentice to CHECK Team Leader in four years.
- The Humble Braggings of a Pentester – Cybrewery Leeds · DC151
- On the 7th Day, He Hacked – Cybrewery Leeds
- Cyber Security & Industry Lessons – UA92
Teaching
Talks and sessions delivered to students at Cardiff University, the University of the West of England, York College, UA92, Notre Dame High School and King Edward VII School. These covered cross-site request forgery, penetration testing as a career, and how to start without paying for the privilege.
05 — THE WIDER GARDEN · Consociatio
Some engagements need more hands than one pair.
For those, we work with a small and consistent group of associate consultants. These are each individually vetted and named to you in writing before the engagement begins. All working to the same reporting standard and the same house rules.
You will never find an unfamiliar name in your report. If someone is going to touch your estate, you will have approved them first.
06 — CUTTINGS · Propagatio
We take cuttings rarely, and slowly.
When we do, we look for people who are curious in an inconvenient way. Those who read the RFC, who keep going after the scanner has finished, and who can explain a finding to a board without either flattering or frightening them. Certifications are useful. They are not the interesting part.
Current openings: [None – speculative approaches are read]
Write to jobs@therose.garden with your CV, and why you think you’d be a good fit. Even better, tell us something you have broken and how you knew it was broken.