Cybersecurity and Assurance
Penetration testing, ISO 27001, SOC 2, PCI DSS and the CBN Risk-Based Cybersecurity Framework — readiness, remediation and certification support.
Class A — Documentation and assessment
| Service | Turnaround |
|---|---|
| Business Continuity and Disaster Recovery Plan Continuity and recovery planning built from a business impact analysis, with recovery objectives that reflect what your infrastructure can actually deliver. | 5 business days |
| CBN Risk-Based Cybersecurity Framework Assessment An assessment against the CBN Risk-Based Cybersecurity Framework, producing the evidence base for your annual return. | 5 business days |
| Incident Response Plan and Playbooks An incident response plan with scenario playbooks, written so an on-call engineer at 3am can follow it. | 5 business days |
| Information Security Policy Suite A complete information security policy set, sized to your organisation rather than copied from a multinational. | 5 business days |
| ISO 27001 Internal Audit The internal audit an ISO 27001 management system requires before certification or surveillance, conducted against the standard rather than a checklist. | 5 business days |
| ISO 27001 ISMS Documentation Suite The full documented information set an ISO/IEC 27001:2022 information security management system requires, including all Annex A controls in scope. | 5 business days |
| PCI DSS v4.x Gap Assessment and Scoping Cardholder data environment scoping and a gap assessment against PCI DSS v4.0.1, including the requirements that became mandatory in 2025. | 5 business days |
| Secure SDLC Programme Design A secure development lifecycle your engineering team will actually follow, with the gates placed where they catch problems rather than where they slow releases. | 5 business days |
| SOC 2 Readiness Assessment A readiness assessment mapped to the Trust Services Criteria, telling you exactly what will fail before the auditor tells you at a higher price. | 5 business days |
| Third-Party Security Assessment An independent security assessment of one of your suppliers, producing a decision you can put in front of a risk committee. | 5 business days |
Class B — Technical testing
| Service | Turnaround |
|---|---|
| API Penetration Test Schema-driven testing of an API including an authorisation matrix across every role and endpoint — the class of flaw automated scanners consistently miss. | 10 business days |
| Cloud Configuration and Security Review A configuration review of an AWS, Azure or GCP account against CIS benchmarks, covering identity, network, storage exposure and logging. | 10 business days |
| Dependency and Container Security Assessment Software composition analysis and container image scanning, with exploitability triage rather than a raw CVE dump. | 10 business days |
| External Network Penetration Test Testing of your internet-facing perimeter: exposed services, patch currency, TLS posture and default credentials. | 10 business days |
| Internal Network Penetration Test Assumed-breach testing from inside your network: lateral movement, privilege escalation and directory service configuration. | 10 business days |
| Mobile Application Penetration Test Static and dynamic testing of a mobile application against OWASP MASVS, covering local storage, certificate pinning and the backend it talks to. | 10 business days |
| PCI ASV External ScanningPartner signed Quarterly external vulnerability scanning of your cardholder data environment, delivered through an Approved Scanning Vendor. | — |
| Phishing Simulation Campaign A controlled phishing campaign measuring click, credential submission and reporting rates, with follow-up training for those who engage. | 10 business days |
| Platform Configuration Review A hardening review of a single platform — Active Directory, a database, a Kubernetes cluster or a firewall estate — against CIS benchmarks. | 10 business days |
| Remediation Validation Retest A retest of previously reported findings, producing a validation letter stating what was fixed, what remains and what is new. | 10 business days |
| Secure Source Code Review Static analysis with manual review of security-critical paths: authentication, authorisation, cryptography and payment handling. | 10 business days |
| Web Application Penetration Test Authenticated and unauthenticated testing of a web application against OWASP ASVS, combining an automated toolchain with manual validation of every critical and high finding by a named consultant. | 10 business days |
| Wireless Security Assessment Assessment of wireless networks at a site: authentication strength, segmentation from corporate systems and rogue access point detection. | 10 business days |
Class C — Scoped engagement
| Service | Turnaround |
|---|---|
| Card Scheme and EMV Certification Support Support through Visa, Mastercard, Verve, NIBSS and EMV Level 2 and 3 certification. | As scoped |
| ISO 27001 Full Implementation to CertificationPartner signed End-to-end ISO/IEC 27001:2022 implementation: risk assessment, controls, documentation, internal audit and support through the certification audit. | As scoped |
| PCI DSS Report on CompliancePartner signed A managed route to a PCI DSS Report on Compliance: scoping, remediation and evidence assembly, with the assessment performed by a Qualified Security Assessor. | As scoped |
| Red Team and Adversary Simulation An objective-based adversary simulation testing detection and response, not just whether vulnerabilities exist. | As scoped |
| SOC 2 Type I AuditPartner signed A point-in-time SOC 2 Type I report, usually the fastest route to satisfying an enterprise procurement requirement. | As scoped |
| SOC 2 Type II AuditPartner signed A managed route to a SOC 2 Type II report, covering readiness, the observation period and the audit itself. | As scoped |
Class D — Retainer
| Service | Turnaround |
|---|---|
| Continuous Attack Surface Monitoring Ongoing discovery and monitoring of your internet-facing estate, with alerting on new exposure. | Ongoing |
| Incident Response Retainer A four-hour response commitment with a pre-agreed team, contract and access model, so the paperwork is done before the incident. | Ongoing |
| Virtual Chief Information Security Officer A named senior security leader accountable for your security programme, governance and regulator-facing security obligations. | Ongoing |
| Vulnerability Management as a Service A managed vulnerability management programme: scanning, triage, tracking and verification of remediation. | Ongoing |