Cybersecurity services
Everything we do falls into three groups: testing, the platform that keeps watching between tests, and bespoke engagements built around your organisation.
Where to start
| If you need | Start with |
|---|---|
| Evidence of testing for a customer, insurer or auditor | A penetration test of the systems in question |
| To know everything you expose to the internet | Attack surface management |
| To cut through scanner noise and fix what matters | Vulnerability management |
| To know whether you would detect a real attack | A red team engagement |
| To prepare leadership for an incident | A tabletop exercise |
| To build something new securely | Threat modelling at design stage |
| To reduce the risk of phishing | Phishing simulation |
Penetration testing
Penetration testing overview →
Web application and API penetration testing
Manual web application and API penetration testing. We find the authentication, access control and business logic flaws that automated scanners miss.
Read more →Infrastructure and network penetration testing
External and internal network penetration testing, including Active Directory. See how far an attacker could get from the internet or inside your network.
Read more →Cloud security assessments for AWS, Azure and Google Cloud
Cloud security assessments and penetration testing for AWS, Azure, Google Cloud and Microsoft 365: identity, storage, network and real attack paths.
Read more →Mobile application penetration testing
Penetration testing of iOS and Android apps and the APIs behind them, aligned to OWASP MASVS: data storage, traffic, authentication and code.
Read more →Wireless network penetration testing
On-site wireless penetration testing: rogue access points, WPA2 and WPA3 configuration, enterprise authentication and guest network separation.
Read more →The platform
Attack surface management
Continuous external attack surface management. Discover every internet-facing asset, including shadow IT, and get alerted to new exposures as they appear.
Read more →Vulnerability management
Validated vulnerability management on the APOLLOSEC platform. We confirm which issues are exploitable, set deadlines by severity and retest every fix.
Read more →Bespoke engagements
Red team assessments
Covert, objective-led red team engagements that test whether your people, processes and technology detect and stop a determined attacker.
Read more →Cyber incident tabletop exercises
Realistic cyber incident tabletop exercises for leadership and technical teams. Rehearse your incident response plan before you need it.
Read more →Threat modelling
Threat modelling for new systems and whole organisations: what could go wrong, who would do it, and which controls matter most, validated against real attacks.
Read more →Social engineering assessments
Social engineering assessments that test how your people and processes respond to phishing, phone pretexting, impersonation and physical intrusion.
Read more →Phishing simulation
Phishing simulations that mirror the lures attackers use now. Measure clicks, credential entry and reporting rates, then improve them over time.
Read more →Physical penetration testing
Physical penetration testing: tailgating, badge cloning, reception pretexts and access to server rooms. Could someone walk in and leave with your data?
Read more →