Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Methodology

How our engagements run

What happens from the first conversation to the final report, and the safeguards that apply along the way.
  1. Scoping and a written proposal

    Every engagement begins with a written scope and proposal.

    Before any work starts, we agree on the question the engagement has to answer, what’s in scope, and what isn’t. Remote-first, senior-led delivery. Every engagement is led by an experienced practitioner.

    What shapes scope and price

    Pricing depends on environment size, complexity, testing depth, locations, applications, accounts, user roles, compliance objectives, and delivery timeline. Every engagement begins with a written scope and proposal. Taxes, travel, remediation, third-party audit or certification fees, licensing, and emergency work are separate. Readiness services do not include independent certification, attestation, legal advice, or a guarantee of passing.

    See indicative starting prices for each service

  2. Authorization before any testing

    All penetration testing requires written authorization, a signed scope, rules of engagement, approved targets, testing windows, emergency contacts, and stop conditions.

    Penetration testing touches live systems, so these documents are in place before testing begins.

    Written authorization
    Permission, in writing, from someone with the authority to approve testing of the systems in scope.
    Signed scope
    The systems, applications, and accounts that are included, and the ones that aren't.
    Rules of engagement
    What testers may and may not do while testing.
    Approved targets
    The specific addresses, hostnames, or applications that may be tested.
    Testing windows
    The dates and times when testing is allowed.
    Emergency contacts
    Who to reach, on both sides, if something unexpected happens.
    Stop conditions
    The situations in which testing pauses right away.
  3. Handling your evidence

    Assessments and readiness work often involve sensitive material, such as configurations, policies, logs, and test results.

    Don't send sensitive information through this website

    We don't collect sensitive evidence through this website. Please don't send passwords or other credentials, sensitive incident details, payment card data, health information, or controlled defense information through a website form. When an engagement needs sensitive evidence, we arrange a secure channel with you after initial contact.

    Active client records follow the signed contract and applicable legal and accounting schedules.

  4. Reporting

    Penetration tests

    Penetration-test pricing assumes authorized manual testing, an executive summary, a technical report, remediation guidance, and one retest within 60 days unless the proposal says otherwise.

    Assessments, readiness, and advisory work

    Deliverables differ by service, so each service page describes its own. Browse services and their deliverables

  5. Frameworks we reference

    Security posture and risk assessments mapped to NIST CSF 2.0 and CIS Controls.

    NIST Cybersecurity Framework (CSF) 2.0
    Published by the U.S. National Institute of Standards and Technology. It describes security outcomes under six functions: Govern, Identify, Protect, Detect, Respond, and Recover. It gives a shared way to describe where an organization is today and where it wants to be.
    CIS Critical Security Controls v8.1
    Published by the Center for Internet Security. A prioritized set of technical safeguards, grouped into implementation groups by an organization’s resources and risk, that turns priorities into concrete steps.

    Compliance readiness for SOC 2, ISO/IEC 27001, the HIPAA Security Rule, PCI DSS, and CMMC. Compare compliance readiness options

  6. Independence

    When a program requires a formal assessment, audit, or certification, it's performed by an independent, authorized assessor. We keep advisory work and formal assessment apart: a practitioner never assesses controls they designed, developed, or implemented.

    How we keep readiness and assessment apart

Primary sources

Start with a scoping conversation

Tell us what you need to decide or prove, and we’ll start from there.