Evidence, not opinions. Here is exactly what you get.
Everything a buyer needs to decide on one page: the deliverables, the full capability matrix, the seven operations, how an engagement runs, the terms, who this is for, and the questions procurement asks. No forms, no sales sequence. One email starts it.
Three things leave every engagement. Nothing else needs to.
Slide decks do not survive an auditor, a board question or a lawyer. These do.
Findings report
- Every finding ranked by real risk, not scanner score
- An owner and exactly one action attached to each
- Written for the engineer and the board in the same document
- Conditional grammar: what the system permits, never speculation
Evidence register
- The artefact behind every claim: configs, logs, screenshots, requests
- Hashed and time-stamped, chain of custody kept
- Reproducible by your own team or by a regulator
- Mapped to ISO 27001, NIST CSF 2.0, CIS v8, ATT&CK, RDI or BIO as agreed
Read-out and retest
- One session, engineers and management together
- Decisions recorded, not just findings presented
- Retest of the fixes where in scope
- Signed attestation of what was tested and what held
Three domains. Thirty-six disciplines.
Everything the operator has run in production, grouped by domain. Tools named where they matter. This is the bench behind the six operations below.
Cyber security
16Compliance, risk and governance
Risk registers, policy, control mapping and audit evidence that is technically enforceable.
Vulnerability management and exposure
CVSS analysis, risk-based prioritisation, remediation tracking, trend reporting across asset groups.
SIEM, log correlation and threat hunting
Detection engineering, hypothesis-driven hunts, ATT&CK-mapped use cases, enrichment pipelines, noise reduction.
Incident detection, response and forensics
Triage to root cause, containment and eradication, memory and network forensics, timeline reconstruction.
Network security and segmentation
VPN, DMZ, VLAN, micro-segmentation and Zero Trust to stop lateral movement, legacy estates included.
Next-gen firewalls and network controls
Policy design, application control, SSL inspection, threat feeds, firewall log correlation in the SIEM.
Secure protocols and cryptography in use
Certificate chains, cipher hardening, protocol misuse detection, key lifecycle.
Cloud security and hybrid estates
Architecture and operations, internal cloud audit frameworks for drift, privilege exposure and compliance deviation.
Identity and access management
RBAC, PAM, SSO, lifecycle automation, conditional access, least privilege and endpoint privilege management.
Endpoint security and XDR
Hardening, telemetry analysis, detection tuning, device control, endpoint-to-identity correlation.
Web application and API security
OWASP Top 10, API audit frameworks for exposure, authentication models, authorisation logic, validation, logging.
Penetration testing and offensive security
Logic flaws, access-control weaknesses, identity abuse and misconfigurations over tool-only exploitation.
Security awareness and insider risk
Awareness programmes, phishing simulations, insider-risk controls tied to HR and compliance processes.
Tooling, automation and infrastructure as code
SIEM tuning, IR workflows and reporting automated; IaC security; monitoring and analysis pipelines.
Asset inventory and compute visibility
Unified view across servers, VMs and endpoints by correlating scanner, MDM, directory and SIEM data.
Backup, recovery and platform hardening
Ransomware recovery validation with forensic checks, DR optimisation, baselines for Windows, hybrid and legacy platforms.
Blockchain security and engineering
07Smart-contract engineering and security
Checks-effects-interactions, reentrancy prevention, upgradeability patterns, safe token handling.
Oracle and pricing integration
Freshness checks, fallback logic, manipulation-resistant price paths.
Staking, rewards and tiering logic
Abuse-resistant reward and tier designs.
Governance architecture
Modular execution, role-gated calls, on-chain auditability.
DeFi threat modelling
Flash-loan abuse, oracle manipulation, front-running and MEV exposure, mapped before deployment.
Audit workflows
Static analysis, symbolic execution, fuzzing, false-positive triage, risk documentation.
AI-assisted contract analysis
Security-first research with AI-assisted review pipelines, automated Slither runs.
AI and machine learning for security
13AI red teaming of LLM systems
Prompt injection, agentic attack chains, adversarial misuse of LLM-powered workflows; formal red-team AI training in progress.
AI safety, governance and auditability
Per-user and per-model rate limits, full audit logging of AI interactions, input validation, role-based module access.
AI-assisted SOC operations
Log correlation, anomaly detection and detection enrichment with models in the loop.
Agentic AI and ReAct architecture
Autonomous agents with planning, tool invocation and self-correction, executed in isolated sandboxes per session.
Model orchestration
Multi-provider routing behind one API with fallback chains, reasoning-effort controls and routing telemetry.
Local AI infrastructure
CPU and GPU inference stacks, LoRA and QLoRA fine-tuning, dataset curation.
Full-stack AI platform delivery
Production AI platform shipped end to end: backend, frontend, streaming, cost tracking, tiered access, JWT, TOTP/2FA.
AI-driven threat intelligence
IOC correlation across sources, attack-chain reconstruction, automatic ATT&CK classification, YARA rule generation.
Forensic evidence processing with AI
Multi-format ingestion (email, captured traffic, documents, audio, video), severity triage, chain-of-custody tracking.
Network traffic and HAR forensics
Reconstruction of platform behaviour and session anomalies from captured HTTP sessions as auditable artefacts.
Audio intelligence and transcription
Speech-to-text pipelines inside forensic workflows for structured dossier construction.
Forensic prompt engineering
System prompts that separate facts, evidence and assumptions, with confidence labels per conclusion, for defensible output.
Security automation deliverables
Autonomous red-team simulations, analyst copilots, security playbook generators.
Seven operations. Fixed scope, fixed price.
Six map to a layer of the chain: surface, deep or dark. The seventh is for when the chain is used against you. Price is set in the proposal after the scoping call, so the total is known before you commit.
Security Audit and Evidence File
Control design and operating effectiveness against ISO 27001, NIST CSF 2.0, CIS v8, RDI or BIO. Output is the evidence file a regulator, a customer audit or a NIS2 supervisor asks for.
Vulnerability Program Reset
Scanner output becomes a ranked remediation program with owners, deadlines and a trend line. Credentialed scan policies, asset grouping, reporting cycle.
Identity and Access Ledger
Every account, service identity, shared secret and vendor path listed with an owner, a last-use date and a decision. Legacy platforms included.
Detection Engineering and Threat Hunt
Detections mapped to ATT&CK and the tradecraft targeting your sector, tuned in your SIEM, validated by hunts that either find something or prove coverage.
Incident Response and Recovery Validation
Triage to root cause, timeline from the logs that exist, and a tested proof that backups restore what you think they restore.
Offensive Assessment, AI Red Team, Smart Contracts
Authorised testing of web, API, cloud and pipelines, LLM workflows and agents, or smart contracts. Every finding reproduced and retested.
Litigation-Grade Evidence and Dispute Support
When the other side is bigger, better funded and controls the systems, the operator builds the technical case that outlives their story: acquisition with chain of custody, timelines from logs, captures and mail records, the gaps named as findings, a dossier written to be filed, and a technical expert next to your counsel.
Five steps. No surprises.
Scoping call
Your context, the systems in play, the question you need answered.
Fixed-price proposal
Scope, method, deliverables, price and date on one page.
Evidence gathering
Walkthroughs, configuration reviews, log sampling, testing.
Findings that carry weight
Ranked, owned, actionable. Engineers and board together.
Retest and attestation
Fixes verified, file closed with a signed statement.
Plain terms. Written down before day one.
NDA before scoping
Your NDA or the standard one, signed before any system name is spoken. Names are withheld in every public reference, always.
EU-side, encrypted, deleted
Evidence lives on EU-hosted encrypted storage for the engagement and is deleted after hand-over. Deletion is confirmed in writing.
One operator, limited slots
No subcontracting and no parallel overload. If a slot is not available, you hear it on the scoping call, with a date.
Written scope, nothing outside it
Every offensive step is authorised in writing with named systems and time windows. No destructive testing, no social engineering unless explicitly scoped.
Reply within one business day
Email is answered within one business day, incidents faster when a retainer is in place.
Supplier paperwork on request
Questionnaires, insurance and identity documents, data-processing agreement, chain-of-custody statement. KvK 84616458.
Who this is for. And who it is not.
- Organisations in regulated or supervised sectors: telecom, government, finance, healthcare, manufacturing
- Teams facing an audit, a customer questionnaire, a NIS2 duty or a board question with a deadline
- Environments with legacy and cloud side by side, identities nobody owns, vendors nobody mapped
- Product teams shipping AI agents or smart contracts who want them tested before launch
- Organisations, reporting persons and lawyers in a dispute with a party that is bigger and controls the systems
- Buyers who want the person on the call to do the work
- A compliance stamp without fixing anything
- A 200-person managed SOC or 24/7 staffing
- Testing systems you do not own or are not authorised to assess
- Slide decks, awareness posters or generic policy packs
- Anything that needs a team next week, rather than one operator with a plan
Answered once, in writing.
How fast can we start?
Scoping call within days of your email. Written proposal within two business days of the call. Fieldwork usually starts within two to three weeks, depending on the scope and your team's availability for access and interviews.
Who actually does the work?
One senior operator, end to end. No juniors, no subcontractors, no hand-off to a delivery team. The person on the scoping call writes the report and answers for it afterwards.
How is pricing decided?
Fixed price per engagement, set in the proposal after the scoping call, so you know the total before you commit. Anything outside an agreed scope is quoted separately, never billed by surprise.
What do we receive at the end?
A findings report ranked by risk with an owner and one action per finding, the evidence register behind every claim, a read-out session for engineers and management together, and a retest with a written attestation where it is part of the scope.
Is the testing safe for production?
Every offensive step is authorised in writing, scoped to named systems and time windows, and rate-limited. Nothing destructive, nothing outside the scope form. Findings are demonstrated, not exploited beyond proof.
How do you handle our data?
An NDA is signed before scoping, yours or the standard one. Evidence is stored on EU-side, encrypted systems for the duration of the engagement and deleted after hand-over, with the deletion confirmed in writing.
Which frameworks do you audit against?
ISO 27001, NIST CSF 2.0, CIS Controls v8, MITRE ATT&CK for detection coverage, the RDI telecom security framework, and the Dutch government BIO baseline. NIS2 and the Cyberbeveiligingswet duties are mapped in every audit deliverable.
Can you act as the technical expert in a dispute against a large organisation?
Yes. That is Operation 07. The operator has built technical cases with counsel against parties many times larger than the client, from their own logs, captures and mail records, with chain of custody kept. The evidence, not the size of the opponent, decides. Reporting persons under the Dutch whistleblower law are supported with the same method.
Can you work under our procurement rules?
Yes. Supplier questionnaires, insurance and identity documents, a chain-of-custody statement for evidence and a data-processing agreement are provided on request. KvK 84616458.
One email starts it.
Thirty minutes to scope it. A fixed-price proposal within two business days. Reply within one business day.