The People Testing Your Systems
Security work is only as good as the people doing it. Here is how our team is staffed, credentialed, and held to account on every engagement.
Who does the work, and who answers for it
The commitments we make about staffing are the ones that decide whether a test is worth anything.
A named lead on every engagement
You know which consultant is testing your systems and you talk to them directly — not through an account manager relaying questions.
No offshore outsourcing
Every test is delivered by our own consultants. Work is never subcontracted to a third party, and your environment is never handed on.
Credentialed, and kept current
Consultants hold recognised offensive-security certifications and keep them current — practical, examined qualifications, not vendor courses.
Available after the report lands
The consultant who found a finding is the one who explains it to your developers, and the one who retests it once you have fixed it.
What the team holds
The offensive-security and audit certifications our consultants carry into an engagement.
OSCP
Offensive Security Certified Professional
OSWE
Offensive Security Web Expert
OSEP
Offensive Security Experienced Penetration Tester
OSWP
Offensive Security Wireless Professional
GWAPT
GIAC Web Application Penetration Tester
GXPN
GIAC Exploit Researcher & Advanced Penetration Tester
eCPPT
eLearnSecurity Certified Professional Penetration Tester
eWPT
eLearnSecurity Web Application Penetration Tester
CREST CPSA
CREST Practitioner Security Analyst
CRTP
Certified Red Team Professional
AZ-500
Microsoft Certified: Azure Security Engineer Associate
Want to know who would run your engagement?
Ask us during scoping — you will be introduced to the consultant who does the testing, before you commit to anything.