SAK Get your exposure reportFree report
SAK Services

Seven engagements, each with a platform behind it

Every service starts from data our platforms already hold, which is why scoping takes days rather than weeks — and why the deliverable stays live after the report is signed off.

Leadership

vCISO Flagship

A fractional security executive who arrives with the platforms already reporting — so board papers take an hour, not a fortnight. Our most-requested engagement.

From 2 days a month
Advisory

GRC advisory

Framework readiness, gap assessment and certification support, run inside GRCorb rather than a spreadsheet.

Delivered in GRCorb
Managed

Managed exposure

SAK Surface, Brand and Deep run for you as a managed service: continuous discovery, impersonation takedowns and credential-leak alerting, reviewed by a named analyst. Platform-delivered — not a staffed SOC.

Business hours · platform-delivered
Offensive

Offensive security

External and internal penetration testing, application and infrastructure assessment, and secure code review, scoped from what SAK Surface already found.

Scoped from SAK Surface
Cloud

Cloud security

AWS and Azure posture review, secure landing zones, CSPM tuning and continuous configuration evidence.

Feeds GRCorb monitoring
Emerging

AI security & governance

LLM and agent threat modelling, prompt-injection testing, model supply chain, and an AI governance program that survives audit.

ISO 42001 · NIST AI RMF
People

Awareness & training

Phishing simulation and role-based training, with completion records filed straight into the evidence store.

Evidence auto-filed
Flagship engagement

vCISO — security leadership without the executive hire

A named security executive owning your framework readiness, with platform evidence behind every board paper.

See the vCISO service
Delivery network

Accredited delivery partners

We work with accredited specialist firms — ISO certification bodies, offensive security teams and training providers — who deliver alongside our platforms. That is how a product company ships enterprise engagements without pretending to be a body shop, and it means each engagement is staffed by the firm best suited to it, not the only one we have.

Certification

ISO & compliance audit

ISO 27001, 22301, 9001, 27017/27018, PCI DSS, SOC 1/2/3 and SAMA CSF certification and audit practice.

Feeds GRCorb audit workspace
Offensive

Red team & testing

Black, white and grey box penetration testing, malware analysis, compromise assessment, secure code review.

Feeds SAK Surface
Education

Accredited training

Internationally accredited IT security training and certification courses for client teams, run by partner training faculties.

Records filed as evidence
Not sure where to start?

Start with your exposure, not a sales call

The free external exposure report shows what an attacker can already see. It is also the fastest way to scope any of the engagements above.

Request the report