About the lab.
A senior, practitioner-led lab. We break systems for clients who need proof their defences hold, build the automation that takes repetitive work off their people, and advise the leadership teams who have to decide what happens next.
A small lab.
Specific obsessions.
"We break things so adversaries can't."
We started the lab because we were tired of penetration-test reports that read like compliance theatre — long PDFs full of CVSS scores nobody acted on, signed off by people who had never actually exploited anything. We wanted somewhere operators run operations, researchers have time to research, and the reports tell the truth: not "you have fourteen high-severity vulnerabilities," but "here is exactly how we became domain admin in four hours, and here is the one detection rule that would have caught us."
The automation practice grew out of the same instinct. Clients kept asking whether the tooling we built for ourselves could be pointed at their operations instead of their defences — and it turned out the discipline transfers. Understanding exactly how a system fails is most of what it takes to build one that doesn't.
We have specific obsessions: how authentic threat actors actually move rather than how vendors say they do, the failure modes of LLM-based agents, and the unglamorous data work that decides whether automation survives contact with a real business. We pick clients who care about the same things.
We don't run a sales team. The people who answer your first email are the people who will do the work. If you want a vendor with slick decks and a quarterly review template, we're visibly the wrong call. If you want practitioners who will tell you uncomfortable things and then help you fix them, that's the work.
Three things we
actually believe.
Practitioners do the work. Not project managers.
The senior person who scopes your engagement is the same one on the keyboard on day one. There's no sales-to-delivery handoff, because every handoff is somewhere context dies. If you have a question at 2am on day twenty-three, the person who answers is the person who can actually answer it.
This puts a hard ceiling on how many engagements we run in parallel. We're fine with that.
The deliverable is the product. Everything else is research.
The report — or the running system, or the roadmap — is the artefact that survives the engagement. It gets read by people who weren't in the room, and it has to stand on its own when an executive picks it up six months later.
We write reports the same week we run the operation, while the context is still warm, then re-read them cold a day later — checking every finding reproduces from the write-up alone — before they reach the client.
If we find a zero-day, the vendor knows before anyone.
Coordinated disclosure isn't a marketing checkbox — it's a written commitment in every engagement contract. If we find a novel vulnerability in your environment, the vendor gets a 90-day disclosure window with full technical detail, and your environment gets immediate mitigation guidance.
We don't sell findings. We don't broker them. We don't keep them in a vault for later. See our disclosure policy.
Three lines.
One team.
The lines share a practitioner deliberately. The automation is built by someone who attacks systems for a living, and the advisory work is written by the person who has to deliver against it.
Breaking things, carefully
Multi-vector, objective-based engagements that simulate real adversaries against your full attack surface — perimeter, internal, cloud, identity, supply chain, and the OT and ICS networks behind them. Adversarial testing of the AI systems you're putting into production. Named-actor emulation that measures what your detection stack genuinely catches.
Every operation is patient, disciplined, and led by a senior practitioner from scope through to retest.
Building things that hold
Workflow automation, internal copilots and the systems integration that makes both possible. We scope against measured hours rather than projected savings, pilot before we build, and hand over documentation and source so you can run it without us.
Every system we ship gets the same offensive review we'd give a client's, before it touches production data.
Saying the useful thing
Fractional CISO cover, security programme design, AI adoption strategy, and compliance readiness for SOC 2, ISO 27001, DORA and the EU AI Act. Advisory from people who still run operations and ship systems, so the recommendations are costable and buildable.
Including, regularly, the recommendation not to buy the thing you were about to buy.
Work with the people who
actually do it.
Every conversation starts with a practitioner, under NDA, with a written brief inside 72 hours.