Security testing that your whole team can act on.
We look for weaknesses in your systems and write them up so both audiences can use the same document: the engineer who has to fix it, and the person who has to approve the budget.
// services
What we cover
Scoped to your environment rather than sold as a fixed package.
Penetration Testing
Controlled attacks against your systems, applications and networks to find what an attacker would find. Scoped up front, with anything critical raised the moment we see it rather than held for the report.
Vulnerability Assessment
A structured sweep of your environment to establish where the weak points are, what each one actually risks, and the order in which they’re worth fixing.
Cloud Security Assessment
Review of your AWS, Azure or GCP posture across infrastructure, containers and applications, including cloud-specific penetration testing.
Security Configuration Review
Misconfiguration causes more incidents than exotic exploits. We check how your systems, applications and cloud services are actually set up against how they should be.
Security Architecture Design
Designing the structure rather than bolting on locks. A security framework sized to your organisation and able to grow with it.
Awareness Training
Practical sessions so your team can recognise the attacks that actually target them — phishing, pretexting, credential reuse — and know what to do when one lands.
Compliance and Risk Management
PDPA, ISO 27001 and BNM guidelines translated into a concrete list of what you need to have in place, what you currently have, and the gap between the two. We’re happy to work alongside your auditor rather than duplicating them.
// method
How an engagement runs
Published in full, because if our approach doesn’t suit your environment it’s better for both of us to find out before you sign anything.
- 01
Scope
What’s in, what’s off limits, when testing runs, and who to call. Agreed in writing.
- 02
Recon
Mapping what’s actually exposed, which is often more than the asset register says.
- 03
Test
Working the agreed scope by hand as well as with tools. Critical findings escalated same day.
- 04
Report
Severity, plain-language risk, and a remediation step per finding. Written for both audiences.
- 05
Retest
A walkthrough with your team, then verification once the fixes are in.
// what we find
The issues that come up most
Not client data — these are the recurring weaknesses we look for first, because they’re common, cheap to fix, and routinely missed.
| Issue | Why it matters | Typical severity |
|---|---|---|
| Exposed admin interfaces | Management endpoints reachable from the public internet, often with no rate limiting and occasionally with default credentials still active. | High |
| Outdated components | A dependency, plugin or CMS version with a publicly documented exploit. The most commonly used route in, because it needs no skill. | High |
| Broken access control | One user able to reach another user’s records by changing an identifier in the URL. Rarely caught by scanners; needs a human. | High |
| Form and payment abuse | Submission endpoints without rate limiting or validation, allowing spam, card testing or inflated transaction volume. | Medium |
| Weak email authentication | Missing or permissive SPF, DKIM and DMARC records, letting an attacker send mail that appears to come from your domain. | Medium |
| Transport not enforced | HTTPS available but not required, no HSTS, or mixed content — leaving traffic interceptable on untrusted networks. | Medium |
| Verbose error messages | Stack traces and version banners that hand an attacker a map of your stack before they try anything. | Low |
| Missing security headers | Absent CSP, X-Frame-Options and related headers. Individually minor, collectively the difference between a contained bug and a real incident. | Low |
Severities shown are typical, not fixed. The same issue can be critical in one environment and negligible in another, which is why every finding in a real report is rated against your context rather than a generic scale.
// credentials
Licensed, and certified nine times over.
Licensed by NACSA, Malaysia’s National Cyber Security Agency. Between four of us we hold these nine industry certifications.
- OSCP

- OSEP

- CISSP

- CREST CRT

- CRTP

- GCFA

- AWS Security

- Azure Admin

- GCP Certified Architect

// reference
A recent assessment
A faith-based charitable organisation asked us to review the security of their website.
“What could easily have been an intimidating technical report instead became a usable roadmap.”
“Risks were named plainly, recommendations were practical, and solutions were easily digestible. That clarity made it possible for both our technical contacts and our committee to engage meaningfully and act decisively.”
“We came out of the engagement not just more secure, but more capable.”
Want a second opinion on your systems?
Tell us what you’re running and we’ll tell you how we’d approach testing it. No pressure, just a clear conversation.