Methodology
How it runs
The same five stages on every engagement, whichever service line it starts from. Use this page to judge the process before you commit to a piece of work.
The five stages
05
-
Stage 01
Scope, in writing
What is in, what is explicitly out, who is in the loop, and what happens if we find something serious on day two. Signed before work starts.
-
Stage 02
Evidence before opinion
Findings include reproduction steps. Recommendations include the measurement behind them. Inferences are labelled as such in the same sentence as the claim.
-
Stage 03
Work that lands
Prioritised by what is exploitable or actionable in your environment, not by a generic score. We work with the people who must implement the fixes. A report nobody acts on is an expensive PDF.
-
Stage 04
Verification
We re-test. A closed ticket and a closed vulnerability are different things, and the gap between them is where most incidents live.
-
Stage 05
Handover, not dependency
You keep the tooling, dashboards, runbooks, and reasoning. A retainer should continue because it earns its place, not because leaving would break the work.
What we will not do
- Rename a vulnerability scan as a penetration test.
- Report a platform's own conversion figure as if it were revenue.
- Buy links, followers, or reviews. All three are detectable, and all three cost more later than they return now.
- Hold your accounts, data, or documentation hostage to a renewal.
- Take an engagement we do not think will pay for itself. We will say so, and explain what would.
Put it to the test.
Describe the problem. We will tell you which stage you are at, and whether we are the right people to run it.
Start a brief