Seven engagements, each with a platform behind it
Every service starts from data our platforms already hold, which is why scoping takes days rather than weeks — and why the deliverable stays live after the report is signed off.
vCISO Flagship
A fractional security executive who arrives with the platforms already reporting — so board papers take an hour, not a fortnight. Our most-requested engagement.
From 2 days a monthGRC advisory
Framework readiness, gap assessment and certification support, run inside GRCorb rather than a spreadsheet.
Delivered in GRCorbManaged exposure
SAK Surface, Brand and Deep run for you as a managed service: continuous discovery, impersonation takedowns and credential-leak alerting, reviewed by a named analyst. Platform-delivered — not a staffed SOC.
Business hours · platform-deliveredOffensive security
External and internal penetration testing, application and infrastructure assessment, and secure code review, scoped from what SAK Surface already found.
Scoped from SAK SurfaceCloud security
AWS and Azure posture review, secure landing zones, CSPM tuning and continuous configuration evidence.
Feeds GRCorb monitoringAI security & governance
LLM and agent threat modelling, prompt-injection testing, model supply chain, and an AI governance program that survives audit.
ISO 42001 · NIST AI RMFAwareness & training
Phishing simulation and role-based training, with completion records filed straight into the evidence store.
Evidence auto-filedvCISO — security leadership without the executive hire
A named security executive owning your framework readiness, with platform evidence behind every board paper.
Accredited delivery partners
We work with accredited specialist firms — ISO certification bodies, offensive security teams and training providers — who deliver alongside our platforms. That is how a product company ships enterprise engagements without pretending to be a body shop, and it means each engagement is staffed by the firm best suited to it, not the only one we have.
ISO & compliance audit
ISO 27001, 22301, 9001, 27017/27018, PCI DSS, SOC 1/2/3 and SAMA CSF certification and audit practice.
Feeds GRCorb audit workspaceRed team & testing
Black, white and grey box penetration testing, malware analysis, compromise assessment, secure code review.
Feeds SAK SurfaceAccredited training
Internationally accredited IT security training and certification courses for client teams, run by partner training faculties.
Records filed as evidenceStart with your exposure, not a sales call
The free external exposure report shows what an attacker can already see. It is also the fastest way to scope any of the engagements above.
Request the report