Home / Clients
Selected engagements

Work we are able to talk about.

Security work is mostly invisible by design. The engagements below are named with permission; a good deal of what we do sits under non-disclosure and will never appear on a page like this. What follows is the shape of the work rather than a list of logos.

ERP Security

Prom Tech

Practice lines · BIZ-08 · SEC-01

Securing a live ERP deployment — the finance and operations system that the business runs on, and therefore the system where a single over-privileged account does the most damage.

The service behind this

How the engagement worked

ERP platforms concentrate risk in one place: purchasing, payroll, inventory and banking integration all sit behind the same login. The work here focused on making privilege explicit rather than inherited, closing the gap between what users could technically reach and what their job actually required, and making every financially significant action attributable to a named person afterwards.

Scope covered

  • Role and permission redesign
  • Segregation of duties controls
  • Database encryption at rest
  • Audit logging of financial transactions
  • Secure integration and API endpoints
  • Backup and tested recovery
  • Administrative access review
VAPT

POW IT UP

Practice lines · OFF-02

Vulnerability assessment and penetration testing across the external perimeter and application surface, delivered as a scored report with reproduction steps rather than a scanner export.

The service behind this

How the engagement worked

Testing ran under a signed authorization letter with agreed rules of engagement and a named emergency contact. Findings were chained manually — the value is not a list of open ports but a demonstrated path from the internet to something that matters. Each finding carried a CVSS v4.0 score, evidence, and remediation guidance specific to the platform and version in use, followed by a retest to confirm closure.

Scope covered

  • External perimeter testing
  • Web application testing to OWASP ASVS
  • Authenticated business-logic testing
  • API authorization testing
  • CVSS v4.0 scored findings
  • Executive and technical reporting
  • Remediation retest
Cybersecurity Training

SEPCO 3

Practice lines · TRN

A structured cybersecurity training program for staff across technical and non-technical roles, delivered in English and Urdu.

The service behind this

How the engagement worked

Awareness training fails when it is generic — a warehouse supervisor and a finance clerk face different attacks and need different examples. Content was built around the organization's own systems and the pretexts most likely to be used against it, with recognition and reporting drilled rather than described. Comprehension was measured before and after so management received evidence of improvement, not just an attendance sheet.

Scope covered

  • Role-based awareness sessions
  • Phishing and social engineering recognition
  • Password and multi-factor hygiene
  • Safe handling of company data
  • Incident reporting procedure
  • Pre and post comprehension assessment
  • Per-department reporting to management
SIEM & EDR

Tworth Resources

Practice lines · DET-03 · OPS-07

Building detection and response capability from the ground up: centralized logging, tuned detections, endpoint detection and response across the estate, and the playbooks that turn an alert into an action.

The service behind this

How the engagement worked

The organization was already generating most of the telemetry needed to catch an intrusion — it was being discarded on a rolling buffer nobody had configured. Work began with a source inventory, then collection and parsing validated end to end before any rule was written. Detections were mapped to MITRE ATT&CK and tuned against a live baseline so that the alerts firing were the ones worth waking someone for, with EDR deployed to give containment options at the endpoint rather than only visibility.

Scope covered

  • Log source inventory and coverage map
  • SIEM deployment and normalization
  • Detection rules mapped to MITRE ATT&CK
  • EDR rollout and policy tuning
  • Alert triage and response playbooks
  • Tamper-evident log retention
  • Handover, runbooks and team training
References

Ask us for a reference, not a logo wall.

Logos prove somebody signed an invoice. A conversation with a client in your own sector tells you whether we turned up when it mattered.

Request a reference
How to get one
Tell us your sector and the work you are considering. Once a mutual non-disclosure agreement is in place we will introduce you to a client who has had the same engagement.
Why some clients are unnamed
Naming a client alongside the words "penetration test" tells an attacker where to look and when the assessment happened. Several clients ask us not to, and we agree.
What we will never share
Findings, reports, configurations or evidence from any engagement, named or otherwise — including to demonstrate our own competence.
Sectors delivered in
Power and energy, technology and software, industrial and resources, and professional services. See Industries for how scope changes by sector.
Next step

Your engagement could be the next one we cannot talk about.

Tell us what you run and what worries you. You will get a written scope, a fixed price and the three things we would fix first.

Book an assessment Email us directly

Scoping calls are free · Reply within one business day