Skip to main content
SpinalCode / cybersecurity

Security testing that your whole team can act on.

We look for weaknesses in your systems and write them up so both audiences can use the same document: the engineer who has to fix it, and the person who has to approve the budget.

// services

What we cover

Scoped to your environment rather than sold as a fixed package.

01

Penetration Testing

Controlled attacks against your systems, applications and networks to find what an attacker would find. Scoped up front, with anything critical raised the moment we see it rather than held for the report.

02

Vulnerability Assessment

A structured sweep of your environment to establish where the weak points are, what each one actually risks, and the order in which they’re worth fixing.

03

Cloud Security Assessment

Review of your AWS, Azure or GCP posture across infrastructure, containers and applications, including cloud-specific penetration testing.

04

Security Configuration Review

Misconfiguration causes more incidents than exotic exploits. We check how your systems, applications and cloud services are actually set up against how they should be.

05

Security Architecture Design

Designing the structure rather than bolting on locks. A security framework sized to your organisation and able to grow with it.

06

Awareness Training

Practical sessions so your team can recognise the attacks that actually target them — phishing, pretexting, credential reuse — and know what to do when one lands.

07

Compliance and Risk Management

PDPA, ISO 27001 and BNM guidelines translated into a concrete list of what you need to have in place, what you currently have, and the gap between the two. We’re happy to work alongside your auditor rather than duplicating them.

// method

How an engagement runs

Published in full, because if our approach doesn’t suit your environment it’s better for both of us to find out before you sign anything.

  1. 01

    Scope

    What’s in, what’s off limits, when testing runs, and who to call. Agreed in writing.

  2. 02

    Recon

    Mapping what’s actually exposed, which is often more than the asset register says.

  3. 03

    Test

    Working the agreed scope by hand as well as with tools. Critical findings escalated same day.

  4. 04

    Report

    Severity, plain-language risk, and a remediation step per finding. Written for both audiences.

  5. 05

    Retest

    A walkthrough with your team, then verification once the fixes are in.

See the full methodology →

// what we find

The issues that come up most

Not client data — these are the recurring weaknesses we look for first, because they’re common, cheap to fix, and routinely missed.

Exposed admin interfacesManagement endpoints reachable from the public internet, often with no rate limiting and occasionally with default credentials still active.High
Outdated componentsA dependency, plugin or CMS version with a publicly documented exploit. The most commonly used route in, because it needs no skill.High
Broken access controlOne user able to reach another user’s records by changing an identifier in the URL. Rarely caught by scanners; needs a human.High
Form and payment abuseSubmission endpoints without rate limiting or validation, allowing spam, card testing or inflated transaction volume.Medium
Weak email authenticationMissing or permissive SPF, DKIM and DMARC records, letting an attacker send mail that appears to come from your domain.Medium
Transport not enforcedHTTPS available but not required, no HSTS, or mixed content — leaving traffic interceptable on untrusted networks.Medium
Verbose error messagesStack traces and version banners that hand an attacker a map of your stack before they try anything.Low
Missing security headersAbsent CSP, X-Frame-Options and related headers. Individually minor, collectively the difference between a contained bug and a real incident.Low

Severities shown are typical, not fixed. The same issue can be critical in one environment and negligible in another, which is why every finding in a real report is rated against your context rather than a generic scale.

// credentials

Licensed, and certified nine times over.

Licensed by NACSA, Malaysia’s National Cyber Security Agency. Between four of us we hold these nine industry certifications.

  • Offensive Security Certified Professional (OSCP)
    OSCP
  • Offensive Security Experienced Penetration Tester (OSEP)
    OSEP
  • Certified Information Systems Security Professional (CISSP)
    CISSP
  • CREST Registered Penetration Tester (CRT)
    CREST CRT
  • Certified Red Team Professional (CRTP)
    CRTP
  • GIAC Certified Forensic Analyst (GCFA)
    GCFA
  • AWS Certified Security — Specialty
    AWS Security
  • Microsoft Certified - Azure Administrator Associate
    Azure Admin
  • Google Cloud Certified - Professional Cloud Architect
    GCP Certified Architect

// reference

A recent assessment

A faith-based charitable organisation asked us to review the security of their website.

“What could easily have been an intimidating technical report instead became a usable roadmap.”

“Risks were named plainly, recommendations were practical, and solutions were easily digestible. That clarity made it possible for both our technical contacts and our committee to engage meaningfully and act decisively.”

“We came out of the engagement not just more secure, but more capable.”

President of the society
A faith-based charitable organisation, Kuala Lumpur

Want a second opinion on your systems?

Tell us what you’re running and we’ll tell you how we’d approach testing it. No pressure, just a clear conversation.