Capability

The full spectrum,

at a depth others don’t reach.

Compromise assessment, digital forensics and incident response, threat hunting, SOC assessment and OT security, run from Switzerland for organizations across Europe and the Gulf. Whatever the engagement, the standard is the same: bespoke scope, senior delivery, and the rigor to go deeper than the brief requires.

Read this as a range of capabilities, not a list of products. Most engagements draw on several of them, in full or in part, assembled into one scope that answers the question actually being asked. A compromise assessment that becomes an investigation, a readiness review with a threat hunt inside it, a retainer that carries forensic capacity: that is the normal shape of the work.

HOW WE ENGAGE

  • Scoped, never templated Every engagement is shaped to the organization’s profile, technology and threat landscape, not fitted to a standard package.
  • Senior hands only A principal-level operator leads the work, not a junior analyst learning on the account.
  • Capability left behind Knowledge transfer and clear documentation mean the team is stronger after the engagement than before it.
[ 01 / PROACTIVE ]

Anticipate and strengthen.

Find and close the weaknesses before an adversary does, and prove the organization is ready for the day one gets through. SOC assessment, incident response planning and tabletop exercises.

01

RAMP SOC

A SOC assessment done as a deep technical review, service by service, not a maturity checklist. Ten SOC services, each measured across four axes, for a precise and defendable picture of how effectively each one delivers and where to invest.

Scope & method
Service-centric assessment across strategy, coverage, integration and continuous improvement; configuration-level validation of SIEM, EDR, logging and IR tooling; executive and technical reporting, with a prioritized capability-uplift roadmap.
Two-page brief (PDF) →
02

Cybersecurity Incident Readiness

What an organization needs to do the right things when an incident hits: contain fast, allocate resources where they matter, and avoid the costly missteps. Built on hundreds of real incidents rather than a template.

Scope & method
Incident response plan and handling guides matched to the organization’s profile; tabletop exercises for technical and executive audiences; DFIR functional exercises that pressure-test the team against realistic, evidence-based scenarios.
Two-page brief (PDF) →
[ 02 / MANAGED ]

Continuous defense.

Senior expertise kept on tap and calibrated to a moving threat, so protection does not decay between point-in-time engagements. Managed threat hunting and a continuous cyber defence program.

03 FLAGSHIP

Cyber Defense Assurance Program

A multi-year, threat-informed program that keeps defenses calibrated to the adversaries most likely to target the organization, and proves they work. The client’s team operates; principal-level experts design, engineer and advise at a depth an internal SOC cannot self-supply.

Scope & method
Continuous compromise assessment and monthly penetration testing; detection and threat-hunting engineering; hardening and identity or perimeter reduction; IR readiness; every finding carried to verified closure, with an embedded Virtual Principal Consultant.
Two-page brief (PDF) →
04

Threat Hunting as a Service

Hypothesis-driven hunts run on a regular cycle against the organization’s own telemetry, surfacing the stealthy activity that conventional controls miss and turning each finding into lasting detection.

Scope & method
Monthly hunts combining threat-intelligence-led and anomaly-based techniques; telemetry processed on a dedicated environment; deliverables include hunt findings, new real-time detection use-cases, and a continuous improvement plan.
Two-page brief (PDF) →
[ 03 / REACTIVE ]

When it counts.

Fast, expert answers to incidents and the questions they raise, including the cases another team has already closed. Emergency incident response, digital forensics and compromise assessment.

05

Where the hard cases land. The work reconstructs what happened even when the evidence is cold, degraded or was written off as gone, then contains, eradicates and recovers with the calm of people who have done it before. When another team has already closed the case, this is often the second call, and the one that solves it.

Scope & method
Emergency response for ransomware, APT and insider cases; disk, memory and cloud forensics; root-cause and timeline reconstruction; daily client updates and regulatory or legal support documentation.
Two-page brief (PDF) →
06

More than a hunt for intruders. The assessment examines the environment for active compromise and, in the same pass, for the gaps between existing controls and best practice that would let an attacker move laterally, escalate privilege or persist. Run over time, one of the most effective ways to drive down high-severity incidents.

Scope & method
Collection across endpoints, Active Directory, DNS, proxy and firewall, and cloud identity, using Velociraptor-based tooling; threat-intelligence-led triage; findings, impact assessment and a prioritized remediation plan.
Two-page brief (PDF) →
[ 04 / SPECIALIZED ]

Advanced and unusual environments.

The estates where availability, safety or architecture make standard IT security approaches a poor fit. OT and ICS security, IoT, and forensics on log formats no SIEM can parse.

07

Non-Standard Log Forensics

Investigation of business application logs that no SIEM can onboard: undocumented formats, no parser, no vendor schema. The work reverse engineers the log format itself and, where the documentation does not exist, how the application’s own security controls behave, then reconstructs events from evidence nobody designed to be read.

Scope & method
Reverse engineering of proprietary and undocumented log formats; reconstruction of the application’s authentication, authorization and audit behaviour where no documentation exists; parsers and normalization built for the engagement; timeline reconstruction at volumes approaching a terabyte, processed on the hardware the engagement allows.
Two-page brief (PDF) →
08

IoT and OT Security

OT, ICS and IoT security for Operational Technology and Internet-of-Things environments, where availability and safety constraints make conventional security approaches unworkable.

Scope & method
Attack-surface and architecture review for OT and IoT estates; segmentation and monitoring guidance; threat modeling against the systems and protocols specific to the environment.
Two-page brief (PDF) →

Flagship program

CDAP / MULTI-YEAR

Cyber Defense Assurance Program

A multi-year, threat-informed program that keeps defenses calibrated to the adversaries most likely to target the organization, and proves they work. The client’s team operates; principal-level experts design, engineer and advise at a depth an internal SOC cannot self-supply.

It is still scoped bespoke. What changes is continuity: the same senior lead, the same understanding of your estate, and every finding carried through to verified closure rather than handed over as a report.

TYPICAL SHAPE OF ONE CYCLE

  • Continuous compromise assessment, estate-wide
  • Monthly penetration testing against the live estate
  • Detection and threat-hunting engineering
  • Hardening and identity or perimeter reduction
  • Incident readiness, exercised not assumed
  • Embedded Virtual Principal Consultant

Cadence, systems in scope and the mix of engagements are set per client. Every finding is carried to verified closure rather than logged and left.

NEXT / DEPTH

Approach

How these engagements are actually run, and what the evidence looks like.

NEXT / SCOPING

Engage

Consultant availability is limited by design. Describe the situation and we respond with a path forward.