Skip to content

All services

all services, and the ways to buy them.

18 services · 6 categories · 6 ways to buy

The list is grouped by what the work protects, because that is usually how the problem arrives — an inbox, a pipeline, a network nobody designed, an office with a front door.

The six engagements further down are ways to buy that work, not a seventh category.

What we protect

the six things we protect, and what sits under each.

The 18 below are capabilities rather than packages — what the work covers, not how it is bought. Each category has a page of its own, and every service is a section on it.

Core services

six ways to buy the work.

Six ways to work with us. Two are a one-off look at where you stand, one is a programme that keeps it moving, three run continuously.

/ 01

one-off engagement

security posture assessment

Find out where you actually stand

We look at what you have and tell you which gaps matter and which don’t, then give you a short list in the order things should be fixed.

  • what’s exposed now
  • what audits ask for
  • what to fix first
view details

/ 02

one-off engagement

penetration testing

We try to break in, on purpose

Real attempts against your apps, cloud and network in the way someone hostile would, followed by a list of what actually worked, worst first.

  • apps, cloud and network
  • findings engineers can use
  • re-test after fixes
view options

/ 03

programme engagement

devshield — managed security program

Security with an owner every month

Instead of a project that ends, you get a monthly plan, someone whose job it is to close what is on it, and a report you can pass upward.

  • a monthly plan
  • fixes that get closed
  • reporting for your board
see how it works

/ 04

ongoing engagement

mdr / mxdr — 24/7 detection & response

Someone is watching, and wakes up when it matters

Most companies already collect the evidence of a break-in without anyone reading it, so we watch it instead and act when something is wrong.

  • 24/7 coverage
  • threat detection & containment
  • sla-backed response
explore mdr

/ 05

ongoing engagement

vciso (fractional)

A security lead without hiring one

You get the person who decides what matters first, answers the questions customers and investors ask, and keeps the written record, for a few days a month rather than a salary.

  • priorities and decisions
  • answers for customers
  • the written record
view scope

/ 06

ongoing engagement

human risk management

The part where somebody clicks the link

Most break-ins start with a person rather than a server, so we find who is vulnerable, train them, and show whether the risk is going down.

  • real phishing tests
  • training that follows
  • risk you can measure
see program

How the two lists fit together

an engagement is a way to buy, not a seventh category.

Each of the six does its work inside one of the categories above — and five of them appear there as a capability as well. DevShield is the only one that exists purely as a programme.

security posture assessment
does its work in Governance & compliance
penetration testing
does its work in Infrastructure & cloud
devshield — managed security program
does its work in Code & delivery
mdr / mxdr — 24/7 detection & response
does its work in Infrastructure & cloud
vciso (fractional)
does its work in Governance & compliance
human risk management
does its work in People

Where to start

not sure which of these you need?

Tell us what’s happening and we’ll say which of it is urgent, which can wait, and what it would take. If the answer is “you’re fine for now”, we’ll say that too.