Skip to content
Education and support

Cybersecurity training and audits

Practical cybersecurity and secure AI training, IT security audits, penetration testing and AI system assessments for companies and organisations.

CYBERSECURITY / SECURE AI
01 / START WITH PEOPLE

Prepare people first, then strengthen the systems around them

Employee training is the first and most important route. When an organisation needs more, we connect education with safe simulations, incident exercises, assessments and technical testing.

HUMAN SECURITY / TRAINING · PHISHING

Cybersecurity training and phishing simulations

Cybersecurity training for employees, leaders and IT, paired with safe phishing simulations, behavioural metrics and a concrete improvement plan.

  • Phishing, vishing, QR codes and fake sign-in
  • MFA fatigue, passwords and secure reporting
  • Data, devices and working away from the office
View scope
OFFENSIVE SECURITY / WEB · API

Web application and API penetration testing

Manual web, API and mobile penetration testing covering authorisation, business logic, sessions, data and integrations. Evidence, priorities and retesting.

  • IDOR/BOLA and privilege escalation
  • Sessions, MFA, password reset and account recovery
  • OAuth/OIDC, SSO, tokens and API keys
View scope
IDENTITY SECURITY / AD · ENTRA

Active Directory and Entra ID penetration testing

Security testing for Active Directory, Entra ID and hybrid identity. Attack paths, permissions, delegations, safe evidence and a hardening plan.

  • ACLs, privileged groups and tiering
  • Kerberos, SPNs, delegation and RBCD
  • GPO, AD CS, service accounts and secrets
View scope
CLOUD SECURITY / AWS · AZURE · GCP

AWS, Azure and GCP cloud security assessment

AWS, Azure and GCP security assessment across IAM, networks, data, logging, CI/CD, containers and escalation paths, with a hardening roadmap.

  • Roles, policies, service accounts and federation
  • Organisations, accounts, projects and guardrails
  • Keys, secrets and workload identity
View scope
SECURITY ASSURANCE / IT AUDIT

IT security audit

IT security audit across architecture, configuration, identity, backups, logging, process and risk, producing an evidence-based remediation roadmap.

  • Asset inventory and criticality
  • MFA, privileged access and joiner/mover/leaver lifecycle
  • Segmentation, remote access and suppliers
View scope
AI SECURITY / LLM · RAG · AGENTS

AI red teaming for LLMs and agents

AI red teaming for LLM, RAG and agentic systems: prompt injection, data leakage, tool abuse, tenant boundaries, impact evidence and remediation.

  • Direct and indirect prompt injection
  • RAG poisoning and cross-tenant retrieval
  • Prompt, data and secret extraction
View scope
AI ENGINEERING / SECURE BY DESIGN

Secure AI implementation for organisations

Design and implementation of AI with data controls, access boundaries, supplier review, guardrails, evaluations and monitoring from architecture to production.

  • Use case, risk and build-versus-buy
  • Supplier, DPA, region and retention
  • RAG, integrations and system boundaries
View scope
CYBER RESILIENCE / IR · TABLETOP

Incident response readiness and tabletop exercises

Incident-response readiness assessment, playbooks and tabletop exercises for ransomware, data breaches, account compromise and supplier incidents.

  • Incident classification and ownership
  • Technical, business and legal escalation
  • Emergency contacts and deputies
View scope
REGULATORY READINESS / NIS2 · DORA

NIS2 and DORA readiness assessment

Technical NIS2 and DORA readiness assessment across assets, risk, incidents, resilience, suppliers, controls and an evidence-based implementation plan.

  • Assets, critical services and risk assessment
  • Board roles, owners and reporting
  • Policies, exceptions and metrics
View scope
02 / STANDARD

One evidence standard across every service

Every engagement ends with something the organisation can use: a practised decision, confirmed evidence, clear priorities and a realistic next step.

01

Clear learning outcome

Audience, decisions and the expected change are agreed before work starts.

02

Safe delivery

Exercises protect people and systems, with explicit boundaries and no public shaming.

03

Readable evidence

Leadership receives a clear result while teams receive practical next steps.

04

Reinforcement

Follow-up actions turn a workshop, exercise or finding into a lasting improvement.

BR / NEXT STEP

Not sure where to begin?

Tell us what you want to protect, assess or improve. We will help you match training, an audit or a test to the organisation’s real risk and capacity.

NDA · clear scope · direct communication