[Engagement: assessment, hardening or response]
[What was found or fixed, and the result.]
Assessment, hardening and monitoring for the systems an organisation depends on, and a response team for when something goes wrong.
Six services, in the order an engagement usually runs. Start at whichever stage you are at: an assessment before launch, or a call in the middle of an incident.
Find out where the organisation is exposed, and what it has to comply with.
Close what the assessment found, and build new systems so it stays closed.
Watch for whatever still gets through, around the clock.
Contain it, find out what happened, and recover.
What a response teaches goes into the next assessment.
The rules the security practice holds itself to on every engagement.
Assessments look for the weakness someone else would find first, not only the ones a checklist expects.
Every fix is checked again before it comes off the list, so the report describes the system as it is now.
Security shapes how our own platforms are designed, written and delivered. It is not a review at the end.
Access, credentials and documentation stay with the client, and the people who run the systems are trained to use them.
[What was found or fixed, and the result.]
[What was found or fixed, and the result.]
[What was found or fixed, and the result.]
Case studies are being written up. Until they are published, ask us for references.
Email Aymen Ibraheem with a line on the organisation and what it needs.