About

01 — ABOUT · Hortus conclusus

A garden is an adversarial system.

Something is planted where it did not grow. Something else is pulled out before it can spread. The gardener works patiently, seasonally, and with very little regard for how the border looked from the road last summer.

We take the same view of your estate.

The Rose Garden is a UK penetration testing and security research consultancy. We are engaged to be the problem, under contract, in writing, on a schedule, so that nobody else gets to be the problem for free.


02 — WHY FLOWERS · Rosa apologia

Because the alternative was another shield, another padlock, another hooded figure at a terminal, and the industry has quite enough of those.

But the metaphor holds, which is why we kept it. Both disciplines reward slow observation and unglamorous maintenance. Both depend on noticing a small change early. Both are, finally, the practice of tending something living that would much rather do as it likes.

The botanical plates, the Latin binomials, the paper-coloured reports — that is sincerity in a good coat. The work underneath is methodical, evidence-led, and boring in precisely the way you want it to be.


03 — METHOD · Tres notae

A perfume is built in three movements. So is an intrusion. We structure engagements the same way because it maps cleanly onto how an attacker actually arrives.

TOP NOTESReconnaissance. What is volatile and immediately apparent. External footprint, OSINT, attack surface mapping, exposed services, credential exposure. What is everything a stranger can learn about you before breakfast, without ever touching a login page.

HEART NOTESExploitation. The body of the engagement. Web and mobile applications, APIs, internal and cloud infrastructure, build pipelines, network segmentation, and the people who operate all of it. This is where the assumptions get tested rather than restated.

BASE NOTESPersistence. What remains once everything volatile has evaporated. Privilege escalation, lateral movement, detection and response validation, and the longer question – what could an attacker still be doing on day ninety, and would anyone know?


04 — THE GARDENER · Rosa investigatio

The practice is deliberately small. You speak to the person holding the terminal, not to an account manager relaying a summary of a summary. Reports are written by the consultant who did the testing, which is the only way a report is worth reading.

Research is not a side project here. Time is set aside for it, findings are disclosed responsibly, and what we learn in the lab arrives in client engagements rather than in a press release.


05 — HOUSE RULES · Regulae horti

I. Nothing without written authorisation. The Computer Misuse Act requires it. So do basic manners.

II. Scope is a fence, not a hedge. We do not wander, and we tell you before we test anything adjacent.

III. Evidence over adjectives. Every severity rating is tied to something we demonstrated and can reproduce in front of you.

IV. We report what we could not do, as well as what we could. A quiet test is a result, not a failure.

V. The findings are yours. Client material does not become a case study, a marketing line, or a conference talk without your explicit permission.


06 — CONTACT · Ad hortum

Most engagements begin with a conversation about what you are actually worried about, which is rarely the thing in the tender document.

Please contact us if you want to discuss an engagement.