Independent testing and audit that shows what is actually exposed, followed by the
policy work that turns findings into a position you can defend to a client or a regulator.
Scoped individually or combined. Most organisations run the audit first, then test what the audit flags.
Authenticated and unauthenticated testing of your web applications and APIs against the OWASP methodology: injection, broken access control, authentication logic, file upload handling and session management. Supports PCI DSS, ISO 27001 and GDPR-style requirements.
External and internal testing of the security posture of your network infrastructure and devices: exposed services, segmentation weaknesses, lateral movement paths, default credentials and unmanaged devices. Mapped to NIST, CIS and ISO 27001.
An independent, qualified team reviewing your IT systems, processes and controls. We agree scope, objectives and methodology with you, execute the audit, and deliver findings with evidence, recommendations and remediation support.
Acceptable use, access control, incident response and NDPR-aligned data handling policy, written to be enforceable rather than filed. Includes the control mapping that evidences your position during a client or regulator review.
An audit reviews how your systems are configured, governed and documented against a standard. A penetration test attacks them the way an outsider would, to prove what is actually exploitable. Most organisations need the audit first.
Testing windows are agreed in advance and destructive techniques are excluded unless you authorise them in writing. Production impact is treated as a fault, not an acceptable cost.
Web application testing follows the OWASP methodology and maps to PCI DSS, ISO 27001 and GDPR-style control requirements where those apply. Network testing maps to NIST, CIS benchmarks and ISO 27001. Nigerian clients also get NDPR-aligned data handling findings.
Yes. We map how personal data moves through your systems, identify where it is exposed, and draft the technical policies and controls that support a compliance position. Filing itself stays with your counsel or data protection officer.
An executive summary written for non-technical readers, a technical findings report with evidence and severity ratings, and a remediation plan ranked by risk with effort estimates. Retesting after fixes is included.
Annually as a baseline, and after any major change: a new office, a new application handling customer data, a cloud migration or a merger. Financial services clients usually test twice a year.
The first assessment is free, and you keep the findings whether or not you engage us.