Cybersecurity training and audits
Practical cybersecurity and secure AI training, IT security audits, penetration testing and AI system assessments for companies and organisations.
Prepare people first, then strengthen the systems around them
Employee training is the first and most important route. When an organisation needs more, we connect education with safe simulations, incident exercises, assessments and technical testing.
Cybersecurity training and phishing simulations
Cybersecurity training for employees, leaders and IT, paired with safe phishing simulations, behavioural metrics and a concrete improvement plan.
- Phishing, vishing, QR codes and fake sign-in
- MFA fatigue, passwords and secure reporting
- Data, devices and working away from the office
Web application and API penetration testing
Manual web, API and mobile penetration testing covering authorisation, business logic, sessions, data and integrations. Evidence, priorities and retesting.
- IDOR/BOLA and privilege escalation
- Sessions, MFA, password reset and account recovery
- OAuth/OIDC, SSO, tokens and API keys
Active Directory and Entra ID penetration testing
Security testing for Active Directory, Entra ID and hybrid identity. Attack paths, permissions, delegations, safe evidence and a hardening plan.
- ACLs, privileged groups and tiering
- Kerberos, SPNs, delegation and RBCD
- GPO, AD CS, service accounts and secrets
AWS, Azure and GCP cloud security assessment
AWS, Azure and GCP security assessment across IAM, networks, data, logging, CI/CD, containers and escalation paths, with a hardening roadmap.
- Roles, policies, service accounts and federation
- Organisations, accounts, projects and guardrails
- Keys, secrets and workload identity
IT security audit
IT security audit across architecture, configuration, identity, backups, logging, process and risk, producing an evidence-based remediation roadmap.
- Asset inventory and criticality
- MFA, privileged access and joiner/mover/leaver lifecycle
- Segmentation, remote access and suppliers
AI red teaming for LLMs and agents
AI red teaming for LLM, RAG and agentic systems: prompt injection, data leakage, tool abuse, tenant boundaries, impact evidence and remediation.
- Direct and indirect prompt injection
- RAG poisoning and cross-tenant retrieval
- Prompt, data and secret extraction
Secure AI implementation for organisations
Design and implementation of AI with data controls, access boundaries, supplier review, guardrails, evaluations and monitoring from architecture to production.
- Use case, risk and build-versus-buy
- Supplier, DPA, region and retention
- RAG, integrations and system boundaries
Incident response readiness and tabletop exercises
Incident-response readiness assessment, playbooks and tabletop exercises for ransomware, data breaches, account compromise and supplier incidents.
- Incident classification and ownership
- Technical, business and legal escalation
- Emergency contacts and deputies
NIS2 and DORA readiness assessment
Technical NIS2 and DORA readiness assessment across assets, risk, incidents, resilience, suppliers, controls and an evidence-based implementation plan.
- Assets, critical services and risk assessment
- Board roles, owners and reporting
- Policies, exceptions and metrics
One evidence standard across every service
Every engagement ends with something the organisation can use: a practised decision, confirmed evidence, clear priorities and a realistic next step.
Clear learning outcome
Audience, decisions and the expected change are agreed before work starts.
Safe delivery
Exercises protect people and systems, with explicit boundaries and no public shaming.
Readable evidence
Leadership receives a clear result while teams receive practical next steps.
Reinforcement
Follow-up actions turn a workshop, exercise or finding into a lasting improvement.
Not sure where to begin?
Tell us what you want to protect, assess or improve. We will help you match training, an audit or a test to the organisation’s real risk and capacity.