Help and support
Frequently asked questions
43 answers, from how an engagement starts to what each service covers.
Working with us
How engagements start, how urgent work is handled, and how we share what we find.
How do I start an engagement?
Call us today, or send a message from the contact page. Tell us what you need protected, or what has already happened. You hear back from the people who do the work.
Do you work with organizations outside your own region?
Yes. Engagements run remotely for organizations worldwide, and calls and reporting are scheduled around your time zone.
We think an attack is under way right now. What should we do?
Call rather than email. Containment decisions are made in minutes, not inboxes, and a call reaches someone who can start working with you straight away.
What areas do your services cover?
Four: proactive security such as red team, penetration testing and threat hunting; defensive security such as endpoint and network security, incident response and privacy solutions; threat intelligence such as threat actor profiling, strategic reporting and advisories on trends and tactics; and advisory and research. Each service has its own page setting out what it covers.
What do the TLP labels on your reports mean?
Traffic Light Protocol, the sharing standard published by FIRST. CLEAR may be shared freely, GREEN stays inside a community, AMBER stays inside the recipient organization and its clients, AMBER+STRICT stays inside the recipient organization only, and RED is for named recipients alone. Every report on this site carries its own marker.
Where can I read your research?
The resources section holds everything we publish, split into threat reports, blog posts, news and case studies. There is an RSS feed if you would rather follow it from a reader.
Security basics
Short answers to the questions we are asked most often outside an engagement.
How do firewalls enhance security?
Firewalls act as a barrier between your network and potential threats. They monitor and control incoming and outgoing traffic based on security rules, helping block unauthorized access and attacks.
How can I protect my mobile devices?
Use strong passwords, enable biometric locks, keep your OS and apps updated, and avoid installing apps from unknown sources. Consider installing a mobile security app for added protection.
How can I identify a secure website?
Look for “https://” and a padlock icon in the browser’s address bar. Also, verify the site’s domain, avoid suspicious pop-ups, and check for trust signals like security badges.
Pro Active Security
Questions clients ask before commissioning this work. Each service page carries the full scope.
Red Team
Service page →What is a Red Team exercise, and how does it differ from penetration testing?
A Red Team exercise is a full-scope, realistic cyberattack simulation designed to test your organization's overall security posture, including people, processes, and technology. Unlike traditional penetration testing, which focuses on specific vulnerabilities, Red Teaming mimics advanced, persistent threats to assess your detection and response capabilities.
How does a Red Team assessment help improve my organization’s security?
Red Team assessments identify weaknesses not only in your technical defenses but also in employee awareness, incident response, and security policies. The insights gained help strengthen your cybersecurity program by revealing gaps that could be exploited by real attackers.
How long does a typical Red Team engagement last?
Red Team engagements usually last from several days up to a few weeks, depending on the scope and objectives. This timeframe allows the team to thoroughly simulate attack scenarios, conduct reconnaissance, exploit weaknesses, and test your detection and response measures.
Penetration Testing
Service page →What is penetration testing, and why does my organization need it?
Penetration testing (or “pen testing”) is a simulated cyberattack conducted by security experts to identify vulnerabilities in your systems, networks, or applications before real attackers can exploit them. It helps uncover security gaps, validate defenses, and ensure compliance, ultimately reducing the risk of data breaches.
How often should penetration testing be performed?
The frequency depends on your organization’s size, industry, and risk profile. However, most businesses benefit from at least annual penetration testing, as well as after major system changes, new application deployments, or following a security incident to ensure ongoing protection.
What types of penetration tests do you offer?
We provide a range of penetration testing services, including:Network Penetration Testing (internal and external)Web Application Penetration TestingWireless Network TestingSocial Engineering and Phishing SimulationsOur tests can be tailored to meet your specific security goals and c
Threat Hunting
Service page →What is threat hunting, and why is it important?
Threat hunting is the proactive process of searching for hidden threats and malicious activities within your network before they cause damage. Unlike automated tools, threat hunting involves expert analysis to detect advanced or stealthy attackers that might bypass traditional security defenses.
How does threat hunting differ from traditional threat detection?
Traditional threat detection relies on alerts generated by security tools when known threats are identified. Threat hunting goes beyond this by actively seeking out unknown threats and subtle indicators of compromise through hypothesis-driven investigation and data analysis.
How often should organizations perform threat hunting?
Threat hunting is ideally a continuous or regular practice, depending on the organization's size and risk level. Some organizations run ongoing threat hunting programs, while others schedule hunts monthly or quarterly to complement automated detection systems.
Defensive Security
Questions clients ask before commissioning this work. Each service page carries the full scope.
End Point & Network Security
Service page →What is the difference between network security and endpoint security?
Network security focuses on protecting an organization's internal networks from unauthorized access, attacks, and data breaches, using tools like firewalls, intrusion detection systems, and secure VPNs. Endpoint security protects individual devices, such as laptops, desktops, and mobile devices, against malware, phishing, and other cyber threats, ensuring they don’t become entry points for attackers.
Why are network and endpoint security essential for my business?
Cyber threats often target both networks and endpoint devices. Without proper protection, attackers can exploit vulnerabilities in either area to gain unauthorized access, steal data, or disrupt operations. A layered security approach that covers both networks and endpoints significantly reduces your organization’s overall risk.
What solutions does your company offer for network and endpoint security?
We provide comprehensive solutions including next-generation firewalls, intrusion detection/prevention systems (IDS/IPS), secure VPNs, endpoint protection platforms (EPP), endpoint detection and response (EDR), patch management, and device encryption services, all tailored to your specific business environment and risk profile.
Incident Response
Service page →What is incident response, and why is it crucial for organizations?
Incident response is the structured approach to detecting, managing, and mitigating cybersecurity incidents such as data breaches, malware infections, or ransomware attacks. It’s crucial because quick and effective response minimizes damage, reduces downtime, and helps organizations recover faster.
How quickly can your incident response team be deployed after a security incident?
Our incident response team is available 24/7 and can be deployed immediately upon detecting or being notified of a security incident to begin containment, investigation, and remediation efforts.
What steps are involved in your incident response process?
Our incident response process typically includes identification and containment of the threat, investigation and analysis of the incident, eradication of malicious elements, recovery and restoration of affected systems, and post-incident reporting with recommendations to prevent future attacks.
Why Choose Our Incident Response?
• 24/7 readiness from seasoned cybersecurity experts • Fast containment and operational recovery • Thorough, legally-defensible forensic investigations • Actionable remediation and improved future resilience • Compliance support and cyberinsurance alignment Whether you’re recovering from an attack or strengthening your prevention strategy, our Incident Response services ensure you’re always prepared.
Privacy Solutions
Service page →What are privacy solutions, and why does my business need them?
Privacy solutions help organizations protect sensitive data, such as personal customer information and proprietary business data, from unauthorized access, misuse, or breaches. They ensure compliance with data protection laws like GDPR, CCPA, and other regulations, safeguarding your reputation and avoiding costly fines.
What does disabling telemetry and diagnostics mean for my organization’s privacy?
Disabling telemetry and diagnostics stops your devices or software from sending usage data, performance metrics, or error reports back to the vendor. This reduces the amount of potentially sensitive or personal information being shared externally, enhancing your organization's privacy and control over its data.
How can privacy solutions improve my organization’s cybersecurity posture?
By implementing robust privacy controls, organizations reduce the risk of data leaks and breaches. Privacy solutions also help establish clear data handling policies, improve employee awareness, and build trust with customers and partners through transparent data protection practices.
Threat Intelligence
Questions clients ask before commissioning this work. Each service page carries the full scope.
Threat Actor Profiling
Service page →What is threat actor profiling and why is it important?
Threat actor profiling involves researching and analyzing cybercriminal groups or individuals to understand their tactics, techniques, motivations, and targets. This helps organizations anticipate attacks, strengthen defenses, and respond more effectively to threats.
How does threat actor profiling benefit my organization?
By knowing who the likely attackers are and how they operate, your organization can tailor its cybersecurity strategies, prioritize protections for vulnerable assets, and improve incident response plans, reducing the risk and impact of cyberattacks.
What kind of information is included in a threat actor profile?
A typical profile includes details such as the threat actor’s known methods (TTPs), malware or tools they use, historical attack patterns, targeted industries, geographic focus, and potential motivations like financial gain or espionage.
Strategic Threat Intel Reports
Service page →What are Strategic Threat Intelligence Reports?
Strategic Threat Intelligence Reports provide high-level analysis of cyber threat trends, emerging risks, and threat actor behaviors that can impact an organization’s long-term security posture. These reports help executives and decision-makers understand the broader threat landscape to inform strategic planning.
Who should use Strategic Threat Intelligence Reports?
These reports are ideal for C-suite executives, security leaders, risk managers, and board members who need actionable insights to guide cybersecurity investments, risk management strategies, and compliance efforts.
How often are Strategic Threat Intelligence Reports delivered?
The frequency can be customized based on client needs but is typically delivered monthly, quarterly, or semi-annually to keep organizations informed about evolving threats and emerging cyber risks.
Advisory on Threat Trends & Tactics
Service page →What is Advisory on Threat Trends & Tactics?
This service provides expert guidance on the latest cyber threat trends, emerging attacker tactics, techniques, and procedures (TTPs). It helps organizations stay ahead by understanding how threats evolve and what defensive strategies to adopt.
How can this advisory service benefit my organization?
By receiving timely insights and recommendations, your organization can proactively adjust security measures, prioritize defenses against the most relevant threats, and enhance overall resilience against cyberattacks.
Who typically uses Advisory on Threat Trends & Tactics?
Security teams, CISOs, risk managers, and executives use this service to make informed decisions about cybersecurity strategy, resource allocation, and incident preparedness based on current and forecasted threat landscapes.
Advisory & Research
Questions clients ask before commissioning this work. Each service page carries the full scope.
Security Consultant
Service page →What does a security consultant do for my organization?
A security consultant assesses your current cybersecurity posture, identifies vulnerabilities, and provides expert recommendations tailored to your business needs. They help design and implement effective security strategies to protect your assets and ensure compliance.
When should my organization engage a security consultant?
Engage a security consultant when launching new IT projects, undergoing compliance audits, after a security incident, or simply to improve your overall cybersecurity defenses. Consultants provide valuable expertise during critical decision-making phases.
How does a security consultant differ from internal IT security staff?
Security consultants offer specialized, unbiased expertise and fresh perspectives that complement your internal team. They stay up-to-date with the latest threats and best practices, providing strategic guidance and industry insights that may not be available in-house.
Security Research
Service page →What is security research, and why is it important for cybersecurity?
Security research involves analyzing emerging threats, new attack techniques, vulnerabilities, and defensive technologies. It helps organizations stay ahead of cybercriminals by providing early warning of risks and developing effective countermeasures before threats become widespread.
How does your security research benefit my organization?
Our security research identifies critical vulnerabilities, zero-day exploits, and evolving attacker tactics that may impact your systems. This allows your organization to proactively adjust defenses, patch weaknesses, and strengthen security policies based on the latest intelligence.
What types of research does your cybersecurity team conduct?
We conduct research on malware analysis, vulnerability discovery, attack trends, threat actor profiling, and emerging technologies. Our findings help inform strategic threat reports, advisory services, and security solutions tailored to protect your business.
Contact
Still not answered?
Send us the question. We answer directly, not with a brochure.
Or email [email protected]
