Working With Us
How engagements run, who delivers them, and what happens to your data.
It starts with a conversation. You tell us what you're trying to protect and what's worrying you; we ask questions, then come back with a written scope, timeline, and fixed price. There's no obligation at any point before you sign the scope - and the initial consultation is always free.
No - making enterprise-grade security accessible to smaller organisations is literally our mission. Engagements scale down as well as up: a focused review for a ten-person startup is as normal for us as a multi-month programme for an enterprise.
Named, vetted Cyse practitioners - you'll know who they are before the engagement begins. We don't anonymously subcontract delivery, and the person who scopes your work stays accountable for it end to end.
Both. Most assessment and advisory work is delivered remotely as standard, which keeps costs down and scheduling flexible. Where the work genuinely benefits from presence - physical security reviews, workshops, incident war rooms, hardware testing - we come to you. With offices in London, Sydney, and New York, we cover UK, European, APAC, and US time zones without treating any of them as an afterthought.
Yes, and we usually do. We agree up front who owns what - typically we find, explain, and prioritise, while your team or provider remediates with our support. We're careful to work as an ally to in-house staff and existing suppliers: our reports are written to make their job easier, not to score points against them.
Our client base spans SaaS and technology, financial services, healthcare, legal, retail, and the public sector. The methodology adapts to context: a fintech facing PCI DSS and a hospital facing patient-safety constraints get materially different treatment, not the same template. If your sector has unusual regulatory or operational constraints, raise them at scoping and we'll plan around them.
We collect the minimum needed to do the job, store it encrypted, restrict access to the engagement team, and destroy it on an agreed schedule after delivery. Our handling practices are documented and available for your review - just ask.
Penetration Testing
Scoping, methodology, safety, and what you receive at the end.
Every layer of a modern attack surface: web applications and APIs, external and internal infrastructure, mobile applications, cloud environments, and the human layer through social engineering. For organisations further along, we also run full red team operations that chain these together the way a real adversary would. If you're unsure which applies, describe the system and we'll recommend the right shape of test.
Enough to size the work honestly: the URLs or IP ranges involved, roughly how large the application is (screens, endpoints, user roles), what environments exist, and what you most want answered. A 30-minute scoping call usually covers it. From that we produce a written scope with effort, timeline, and a fixed price - if we discover mid-test that the scope was bigger than described, we tell you before anything changes commercially.
Black box (no access) simulates an outside attacker but spends much of the budget on discovery. White box (full access, source code, architecture) finds the most issues per day of testing. Grey box - authenticated access with documentation - is the sweet spot for most applications: realistic attacker perspective, without wasting paid hours rediscovering what you could have just told us. We'll recommend one per target rather than one-size-fits-all.
Testing is controlled and scoped in advance: destructive techniques are excluded by default, exploitation is done carefully with agreed rules of engagement, and high-risk checks can be scheduled out of hours. Genuine outages caused by professional testing are rare - and if anything unexpected happens, we stop and tell you immediately.
Either can be right. Staging lets us test aggressively without business risk, but only tells the truth if it genuinely mirrors production - same code, same configuration, same integrations. Production gives certainty but requires more careful rules of engagement. A common pattern is deep testing in staging plus a lighter verification pass against production. We'll help you pick based on how faithful your environments actually are.
Test accounts and evidence are handled like the sensitive material they are: credentials exchanged over encrypted channels rather than email, findings stored encrypted and access-restricted to the engagement team, and everything destroyed on an agreed schedule after delivery. Exploited data is captured only to the minimum depth needed to prove impact.
Two things: an executive summary written for leadership, and a technical report with every finding evidenced, risk-rated, and paired with specific remediation guidance. We walk both through with you on a call, and a retest of your fixes is included in the price.
At minimum annually, and after any significant change - a new application, a major release, an infrastructure migration. Many compliance frameworks (PCI DSS, ISO 27001, SOC 2) expect this cadence. Higher-risk organisations often move to quarterly or continuous testing.
A penetration test aims to find as many vulnerabilities as possible in a defined scope. A red team engagement pursues a specific objective - like reaching your crown-jewel data - using any realistic means, to test whether your defences and people detect and stop a genuine adversary. Most organisations should test thoroughly before they red team.
Incident Response
Emergency help, retainers, forensics, and what happens after containment.
Contact us immediately and mark your message as an active incident. Don't power off affected machines (you'll destroy evidence), do disconnect them from the network if you safely can, and start writing down what you're seeing with timestamps. A responder will guide you from first contact.
No - we take emergency cases without a retainer whenever capacity allows. But a retainer guarantees response times, pre-agrees commercial terms, and means we already understand your environment when the clock is ticking. The difference in outcome can be substantial.
Guaranteed response times with pre-agreed commercial terms, an onboarding exercise so we map your environment, contacts, and escalation paths before anything goes wrong, and response playbooks tailored to your most likely scenarios. Most retainers also include readiness work - tabletop exercises and plan reviews - so unused hours still make you measurably better prepared rather than expiring quietly.
The decision stays yours, but you won't make it blind. We establish what was actually encrypted and exfiltrated, whether restoration from backups is viable, and what recovery costs look like on each path - and we coordinate with your legal counsel and insurer, since payment can raise sanctions and coverage questions that need specialist advice. Our job is to replace panic with evidence, fast.
Yes. Digital forensics is part of the practice: affected systems are imaged before they're changed, artefacts are collected and handled with a documented chain of custody, and findings are written up so they hold up with regulators, insurers, courts, and law enforcement. Tell us early if litigation or a claim is likely so we calibrate evidence handling from the first hour.
Containment is the midpoint, not the finish line. We confirm the attacker's access is fully revoked, help you rebuild safely, and then run a structured post-incident review: how they got in, what let them move, what detection missed, and a prioritised hardening plan so the same door isn't open twice. That review is usually the highest-value document the incident produces.
Yes. Our reports are written to support regulatory notifications (including GDPR's 72-hour requirement), insurance claims, and customer communications. We can also join calls with your regulator, insurer, or key customers to explain the technical facts.
Consultancy & vCISO
Strategic guidance, compliance, risk, and security leadership on demand.
Everything a full-time security leader would - strategy, risk decisions, vendor scrutiny, board reporting, incident oversight - delivered fractionally, for a fraction of a senior hire's cost. You get a named practitioner who learns your business, owns your security roadmap, and is accountable for progress against it, backed by the rest of Cyse's specialists when depth is needed.
Most clients land between two and eight days a month, and it flexes with what's happening: heavier during an ISO 27001 push or a major product launch, lighter in steady state. We'd rather scope honestly than sell days - the engagement is reviewed regularly and adjusted in either direction as your programme matures.
Yes - compliance and governance work is a core discipline. We run a gap analysis against the framework, build the remediation roadmap, help you implement controls and evidence them, and support you through the audit itself. Just as importantly, we build the programme so the certificate reflects real security rather than a binder of policies nobody follows.
We identify what actually matters to your organisation - systems, data, processes - then assess the threats to each, how likely they are, and what the impact would be. The output is a prioritised risk register in business language, so leadership can make deliberate decisions about what to fix, what to insure, and what to accept, instead of spending on whatever shouted loudest.
Gladly - translating technical risk into board language is one of the most valuable things we do. Whether it's a quarterly security update, support for an investment case, or answering hard questions after a near miss, we present the facts plainly, with options and costs, and without the fear-mongering that gives security a bad name in boardrooms.
Yes. Security architecture review works best before code is written: we examine the design - trust boundaries, authentication flows, data paths, third-party dependencies - and flag the decisions that would be expensive to unwind later. It's the cheapest security work you'll ever buy, because fixing a diagram costs nothing compared to fixing a deployed system.
Four stages: discovery, where we learn your business and current posture; gap analysis against your chosen framework or threat model; a prioritised roadmap with costs and effort attached; then embed and review, where we help you deliver it and measure progress. You can stop after any stage - though most clients keep us through the roadmap at least.
Cloud Security
AWS, Azure, and GCP assurance - from architecture review to continuous posture.
AWS, Azure, and GCP as first-class citizens, plus the platforms that orbit them - Kubernetes, serverless, and the SaaS tools wired into your cloud accounts. Multi-cloud and hybrid estates are normal for us; the assessment follows your architecture rather than forcing it into one vendor's reference model.
A configuration audit reviews your cloud estate from the inside - IAM policies, network rules, storage permissions, logging - against best practice and your own intent, giving broad coverage quickly. A cloud penetration test attacks from an adversary's position to prove what's actually exploitable. They answer different questions; mature programmes use both, typically audit first.
Identity is the real perimeter in the cloud, so we map who and what can access which resources - humans, roles, service accounts, federated identities - and compare it to what each actually needs. The output is a concrete least-privilege plan: excess permissions to revoke, risky trust relationships to break, and the handful of identities whose compromise would hurt most, hardened first.
The unglamorous ones: storage buckets exposed to the internet, IAM roles with far more permission than their job requires, missing or unmonitored logging, secrets committed to code, and dormant access keys nobody remembers creating. Almost every serious cloud breach traces back to a misconfiguration of this kind - which is also why they're so worth finding early.
Yes - security that ships with your code is the goal. We scan Terraform and CloudFormation for dangerous defaults before they deploy, review container images and workload configurations, and help you put secrets management on rails so credentials stop living in repositories. Done well, this moves security from a periodic audit into your pipeline, where issues cost minutes instead of incidents.
A point-in-time audit tells you how secure your cloud was on the day we looked; posture monitoring keeps watching as your environment changes - new resources, drifted configurations, fresh permissions - and alerts on regressions. If your teams ship to the cloud weekly, an annual snapshot leaves long blind windows. Monitoring closes them for a fraction of the cost of the incident it prevents.
Threat Intelligence
Dark web monitoring, brand protection, and intelligence you can act on.
It's knowing what's circling your organisation before it strikes: which adversaries target your sector, what credentials of yours are already circulating, who's impersonating your brand. Without it, you defend blind and react late. You don't need a feed of ten thousand indicators - you need the handful of facts about your own exposure that change decisions, which is precisely what we deliver.
Criminal marketplaces, leak sites, stealer-log dumps, and closed forums - watching for your domains, employee credentials, customer data, and mentions of your organisation. When something surfaces, you get an analyst-verified alert with context: what leaked, how fresh it is, and exactly what to do about it, typically before the credentials are used against you.
Yes - brand protection covers lookalike domains, phishing sites, fake social profiles, and fraudulent apps trading on your name. We detect them early through registration and certificate monitoring, then handle the takedown process with registrars, hosts, and platforms. Speed matters here: most impersonation campaigns do their damage in the first days of existence.
In whatever form your team can act on: curated alerts when something needs attention now, scheduled briefings that summarise your threat landscape in plain language, and machine-readable feeds for your security tooling. Every item is filtered for relevance and explained by an analyst - we'd rather send you three findings that matter than three hundred that don't.
Yes. Indicators and alerts can flow directly into your SIEM, SOAR, or ticketing systems in standard formats, enriched so your analysts aren't left googling context. If you have no SOC at all, that's fine too - our analysts effectively become the intelligence function, telling you what surfaced and what to do about it.
More than you'd think. Credential stuffing, phishing kits, and stolen-data markets don't discriminate by company size - smaller organisations are often hit precisely because nobody is watching. A right-sized monitoring service costs little and answers a question most companies can't: is our data already out there? Frequently, the first report is eye-opening.
Data Privacy
GDPR, DPIAs, DPO services, and privacy programmes that earn trust.
With a data map: you can't protect or lawfully process what you haven't located. We chart what personal data you hold, where it lives, why you process it, and who it flows to - then gap-assess against the regulation and build a prioritised remediation plan. It's a faster, calmer path than starting from a policy template and hoping it fits.
A named, qualified Data Protection Officer - fractional, like our vCISO service. Some organisations are legally required to appoint one (large-scale monitoring or special-category data processing, and most public bodies); many others simply need the expertise without a full-time hire. Your DPO handles regulator liaison, data subject requests, DPIAs, and keeps your programme honest.
A Data Protection Impact Assessment is a structured analysis of a processing activity that's likely to pose high risk to individuals - think new tracking technology, large-scale profiling, biometrics, or novel uses of AI on personal data. GDPR requires one before such processing begins. We run them with your teams, document them properly, and turn the findings into design changes rather than shelf-ware.
Yes - and the clock is more manageable with help. We work alongside our incident response team to establish what data was affected, assess the risk to individuals, and draft the regulator notification and any customer communications. Note the deadline: 72 hours from becoming aware, weekends included. Contact us immediately and we'll take the process off your plate.
Yes - with offices in London, Sydney, and New York, multi-jurisdiction work is our normal. We help you navigate UK and EU GDPR, Australia's Privacy Act, and the growing patchwork of US state laws, including the international transfer mechanisms (adequacy, SCCs) that connect them. The aim is one coherent programme that satisfies all of them, not separate compliance silos per country.
Building products so privacy is a property of the system, not a policy bolted on afterwards: collecting less by default, minimising retention, isolating identifiers, and making consent meaningful. We review designs and data flows before launch and give engineers concrete requirements. It also pays commercially - enterprise procurement teams increasingly buy from vendors who can evidence exactly this.
AI Security
LLM red teaming, AI governance, and securing what you build and buy.
Adversarial testing of AI systems: prompt injection, jailbreaks, data exfiltration through model responses, and abuse of any tools or APIs the model can reach. We attack your AI feature the way a motivated adversary would - including indirect injection, where malicious instructions arrive hidden in content the model later processes - and show you exactly what an attacker could make it do.
Three broad classes. New attack surface: models can be manipulated through their inputs in ways traditional appsec doesn't cover. New data exposure: sensitive information flows into prompts, training sets, and vendor systems that your existing controls don't see. And new accountability: regulators are actively watching how organisations deploy AI. None of this argues against adopting AI - it argues for testing it like you test everything else.
With a policy people can actually follow. Blanket bans just push usage into the shadows; we help you define which tools are approved for which data, put technical guardrails around the riskiest flows, and train staff on what never belongs in a prompt. The goal is capturing AI's productivity gains with your sensitive data still under your control.
Yes, and earlier is cheaper. An AI architecture review examines the design - what the model can access, how prompts are constructed, where untrusted content enters, what actions the system can take - and flags the decisions that create exploitable paths. The most important principle: anything irreversible should require human confirmation or a deterministic check the model can't talk its way past.
The emerging canon: the OWASP Top 10 for LLM applications for technical testing, NIST's AI Risk Management Framework for governance, and the regulatory requirements taking shape around the EU AI Act. Because the field moves quickly, our methodology is updated continuously from our own research and engagement findings rather than frozen to any single checklist.
Where it genuinely helps - triaging telemetry, accelerating analysis, spotting patterns at scale - always with an analyst validating anything that reaches you. We hold our own usage to the same standards we advise clients on, which keeps us honest: every recommendation we make about AI governance is one we've had to implement ourselves.
Commercial & Legal
Pricing, contracts, insurance, and scheduling.
Project work (like penetration tests) is fixed-price against a written scope, so there are no surprises. Ongoing services (managed detection, vCISO, retainers) are a monthly subscription that scales with your size and requirements. Every quote itemises exactly what's included.
Scoping usually happens within days of first contact. Delivery start depends on the service: incident response begins immediately, advisory work typically within a week or two, and testing engagements are usually scheduled two to four weeks out.
Yes - NDAs, data processing agreements, and supplier security questionnaires are routine for us. We carry professional indemnity and cyber insurance, and we're happy to evidence our own security controls as part of your vendor process.
Yes - professional indemnity and cyber liability cover, maintained continuously. Certificates of insurance are available on request for your vendor onboarding, and if your contracts require specific cover levels, raise it during scoping so we can confirm before you commit.
Terms are agreed per engagement and stated on the quote - no hidden schedules. We invoice clients across the UK, Europe, APAC, and North America routinely, in the major currencies, and we're comfortable working within enterprise procurement and PO processes when that's how your organisation buys.
Life happens - releases slip and priorities shift. Give us reasonable notice and we'll rearrange scheduled work without drama; the specific notice terms are written into your scope so there's never ambiguity. The earlier you tell us, the more flexibility we have with the calendar.
You're not dropped at delivery. Testing engagements include a retest of your fixes; every report comes with a walkthrough call and a window for follow-up questions. Many clients then keep a light advisory retainer so the practitioner who knows their environment stays available - and anything we deliver is designed so your team can run with it independently.