Services

01 — Services · Catalogus plantarum

Everything here has been grown before it was sold.

What follows is a catalogue. Each entry is something we test, what it involves, roughly how long it takes, and what we need from you before the first day.

If your estate is not on the list, write anyway. Half of this work is deciding what the right test actually is.


GROUP I

Applications

Tested as each kind of user in turn, because almost every serious finding is something one role can do to another.

PLATE 01

Web application testing

Rosa applicata

Authenticated testing of the application as every kind of user, aimed at the logic a scanner cannot reach: broken access control, injection, session handling, and everything a role is not supposed to be able to do.

5–10 days · remote · one account per role, ideally two

PLATE 02

API testing

Rosa interfaciei

REST, GraphQL and gRPC surfaces tested against their documentation and against what they actually accept. Authorisation between accounts, mass assignment, object-level access, and rate limiting that only looks like rate limiting.

3–8 days · remote · a schema or collection, two accounts per role

PLATE 03

Mobile application testing

Rosa portabilis

iOS and Android, examined as a running app and as a file on disk. Binary and static review, traffic interception, local storage, pinning and anti-tamper, and the backend the app trusts more than it should.

5–12 days · remote · an installable build and test accounts

PLATE 04

Desktop & thick client

Rosa sedentaria

Installed Windows and cross-platform clients. Local privilege, file and registry permissions, embedded secrets, update mechanisms, and the protocol running back to the server once nobody is watching it.

4–8 days · remote or on site · installer, licence, a representative host

PLATE 05

Secure code review

Rosa scripta

Reading the source rather than inferring it from the outside. Targeted at authentication, authorisation, and every path that handles input from someone you do not employ. Usually paired with Plate 01 or 02.

3–10 days · remote · read-only repository access


GROUP II

Infrastructure

The estate itself: what is exposed, what an intruder reaches once inside, and whether the boundaries on the diagram exist on the wire.

PLATE 06

External infrastructure

Rosa ad muros

Everything reachable from the internet: exposed services, patch levels, forgotten hosts nobody has owned since a migration, and credentials already sitting in public. What a stranger learns before breakfast.

2–6 days · remote · IP ranges and domains, confirmed in writing

PLATE 07

Internal infrastructure

Rosa interior

From the position of someone already inside — a contractor’s laptop, a reused VPN certificate, one phished account. Domain privilege, lateral movement, and how far an entirely unremarkable user can travel.

4–10 days · on site or via jump host · network access, one standard user

PLATE 08

Build & device review

Rosa fabricata

A laptop, VDI image or kiosk build, examined as an attacker holding it would. Local escalation, disk encryption, application allow-listing, peripheral access, and what the lock screen genuinely keeps out.

2–4 days · on site or shipped device · one representative build

PLATE 09

Firewall & segmentation review

Rosa saepes

Rule base review paired with traffic testing across each boundary, including the paths nobody remembers approving. Required annually by PCI DSS, and quietly useful to everyone else.

2–5 days · remote · configuration exports and a host in each segment


GROUP III

Cloud & identity

Where the perimeter went. Reviewed as configuration and then tested as a live environment, because the two rarely agree.

PLATE 10

Azure & Entra ID

Rosa caerulea

Tenant, subscription and identity configuration. Conditional access and its exemptions, privileged role assignment, consent grants, managed identities, and the escalation routes that run between all four.

3–7 days · remote · a reader role and one standard user account

PLATE 11

Microsoft 365

Rosa officii

Exchange, SharePoint and Teams, with the sharing defaults nobody has revisited since rollout. External sharing, mail flow rules, legacy authentication, and precisely what one compromised mailbox hands over.

2–5 days · remote · read-only administrative access

PLATE 12

AWS & Google Cloud

Rosa nubila

IAM policy and role assumption chains, storage exposure, network boundaries, secrets handling, and the metadata service that turns a small application flaw into an account-wide one.

3–8 days · remote · a read-only audit role

PLATE 13

Build pipeline review

Rosa germinans

CI/CD treated as an attack surface. Who can change what runs, where the secrets live, what an untrusted pull request is permitted to execute, and what the pipeline can deploy to without a human present.

2–5 days · remote · pipeline definitions and read access


GROUP IV

Adversarial

Objectives rather than checklists. These engagements test whether anybody notices, which is a different question from whether anything is vulnerable.

PLATE 14

Red team

Rosa adversaria

Agreed objectives, no announced scope beyond the rules of engagement, and a written account of what was detected and when. Run alongside your defenders, or without their knowledge, as you prefer.

15–30 days · blended · an executive sponsor and written authorisation

PLATE 15

Social engineering

Rosa suasoria

Pretexted email, telephone and message campaigns against agreed targets, measured on what people did rather than what they clicked. Reported as patterns and numbers. We do not name individuals to their employer.

3–8 days · remote · a target list and an agreed pretext boundary

PLATE 16

Physical intrusion

Rosa ianuae

Doors, badges, receptions, and the helpful colleague holding one open. Reconnaissance, entry, and an honest account of what could be reached from a desk once inside the building.

3–6 days · on site · site owner authorisation, carried in writing


GROUP V

Specialist estates

The environments most consultancies decline, subcontract without telling you, or test with the wrong instincts entirely.

PLATE 17

Wireless

Rosa aetheris

Corporate and guest networks, the authentication protecting each, the segregation supposedly between them, and rogue access points. Including what can be captured from the car park without entering the building.

2–4 days · on site · site access and a floor plan

PLATE 18

Operational technology

Rosa machinalis

ICS and SCADA environments tested with the caution they demand: passive observation first, active testing only where agreed, and nothing at all against a running process without a written safety case.

5–12 days · on site · an engineering contact and an agreed safety case

PLATE 19

Embedded & IoT

Rosa inclusa

Hardware in hand. Debug interfaces, firmware extraction, secure boot, keys held in storage that was never meant to be read, and the cloud service the device trusts without ever verifying.

5–12 days · lab · two or three sample units we may destroy

PLATE 20

Z-Series mainframe

Rosa maiorum

z/OS security testing: RACF configuration, dataset and resource protection, APF authorisation, surrogate access, and the routes from an ordinary TSO login to something it was never intended to touch.

5–15 days · remote or on site · a TSO account and a systems programmer to talk to


GROUP VI

Before and afterwards

A test is a moment. Most of the value is in what happens either side of it.

PLATE 21

Threat modelling & design review

Rosa praevisa

Before it is built. A structured session over the architecture with the people who designed it, producing the list of things that must be true for the design to hold, and what happens to each if it is not.

1–3 days · remote or on site · architecture documentation and its authors

PLATE 22

Retest

Rosa iterata

Every remediated finding retested and the report reissued with each one marked closed, partially addressed, or still open. Included with every engagement in this catalogue. Not a separate line on an invoice.

included · remote · notice that the fixes are live

PLATE 23

Advisory retainer

Rosa perennis

A set number of days each quarter, drawn down as you need them: a question, a design review, a second opinion on a supplier’s report, or a short test at short notice without going back through procurement.

by arrangement · remote · an annual agreement


02 — Included throughout · Comitantia

The same six things arrive with every engagement.

Not a premium tier, not an upgrade, and not itemised separately. They are simply what a penetration test is when it is done properly.

  • I
    A named testerYou are told who is testing before it starts, and you can speak to them during it.
  • II
    Contact while the work runsA short daily note during the testing window, and an immediate telephone call for anything critical. You never wait for the report to hear bad news.
  • III
    A report written by the testerAn executive summary your board can read, technical detail your engineers can act on, and reproduction steps for every finding.
  • IV
    Evidence behind every ratingEach severity is tied to something demonstrated. We also record what we tried and could not achieve, because that is a result too.
  • V
    A debriefAn hour with your engineers to walk the findings, argue about the ratings, and agree what order to fix them in.
  • VI
    A retestYour fixes verified and the report reissued. Included, not invoiced.

03 — Schemes & standards · Regula mensurae

If a framework is driving this, say so early.

It changes what evidence the report has to carry, and it is far easier to build that in from the scope than to retrofit it afterwards.

PCI DSS

Segmentation testing and application testing scoped to the requirements, with findings mapped to the control they answer.

ISO 27001

Testing positioned as evidence for the technical controls, in a form an auditor will accept without a follow-up question.

Supplier assurance

Customer security questionnaires, due diligence packs, and the annual test a contract has started demanding.

CHECK

Testing is led by a dual-qualified CHECK Team Leader in both Application and Infrastructure. Where an engagement must be delivered under the NCSC CHECK scheme itself, we will tell you plainly and introduce you to a firm that holds it.


04 — Not on offer · Quae non serimus

Some things are not in the catalogue on purpose.

  • An automated scan sold as a penetration test. If a tool could have found it alone, that is a scan, and it should be priced like one.
  • A severity rating we cannot demonstrate. If we could not prove the impact, the report says so.
  • Work we are not qualified for. We will tell you, and point you at someone who is, which costs us a fee and saves you a report worth nothing.
  • Testing without written authorisation. The Computer Misuse Act requires it and so do basic manners.
  • Your findings as our marketing. Nothing from your engagement becomes a case study, a slide, or a conference talk without your written permission.

Bring the plate number, or bring nothing at all.

Most engagements begin with half an hour on the telephone with the person who would do the testing. No charge, no slide deck, and no discovery call about the discovery call.

If you already know what you want, quote the plate number. If you do not, describe what is worrying you and we will work out the scope together — that is part of the job, not a prerequisite for asking.

Start a scope