Our services
We focus on three areas and do them thoroughly. Each service follows recognised standards and ends with findings your team can act on.
-
IT Audit
An independent review of how your IT is governed, operated and controlled, measured against the frameworks your auditors, regulators and customers expect.
- IT general controls (ITGC)
- ISO/IEC 27001 readiness
- Policy and controls review
-
Penetration Testing
Authorised, hands-on testing that finds the weaknesses an attacker could exploit in your applications and infrastructure, and shows you how to close them.
- Web applications
- APIs
- Mobile applications
- Network and infrastructure
-
PCI DSS v4.0
Practical help to understand which PCI DSS v4.0 requirements apply to you, where you fall short, and how to close the gaps before your assessment.
- Scoping and data-flow review
- Gap assessment
- Readiness support
- Remediation support
Not sure where to start?
Many organisations combine services. For example, an IT audit to close control gaps, penetration testing to validate technical defences, and PCI DSS readiness for payment environments. Tell us your goal and we will suggest a sensible order.
Ready to find out where you stand?
Tell us about your environment and goals. We will reply with a suggested scope and next steps.