Cybersecurity

Led by professionals with experience in offensive security and in governance.

Offensive security
Professional experience
Governance
Professional experience
Process
TALUS, built in house

Services

Secure code review

A senior read of the codebase against a threat model built for it, rather than a linter run with a cover page.

Threat model first, then the code read against it
Findings ranked by what they actually break
Remediation notes an engineer can act on
Generated code held to the same standard

Password assessment

Active Directory password testing driven by Ashfall's organization-tailored prioritization, supercharged by OMEN, instead of just replaying a leak corpus.

Roughly four times the recovery of the strongest wordlist run
Published method and a reproducible benchmark
Per policy and per department breakdown
Out-of-policy and reused passwords flagged across the network
Stale service accounts surfaced

Internal PCI compliance scanning

Scheduled scanning that feeds your own compliance programme, delivered in plain terms rather than raw output.

Quarterly or on demand
Deduplicated across scan cycles
Remediation notes with each finding

Penetration testing

Senior led and manual, run through our own TALUS driven process so the coverage is consistent between engagements.

Scoped, run, and reported by practitioners
External, internal, or application scope
Retest included on agreed findings
Reporting

Ranked by Impact

A one line fix and a design level flaw never share a bucket. You get a ranking an engineer can act on and a summary a board can read.

StructuralA design level flaw. The fix changes how the system works, not one line of it.
ExploitableReachable today with access an attacker can plausibly obtain.
ContainedReal, but bounded by another control that currently holds.
HygieneWorth fixing, breaks nothing on its own. Grouped, never inflated.

Common Questions

Who does the work?

Practitioners. Where we bring in an external tester, they work inside TALUS on the same terms, and the report is ours.

How is AI used in a review?

Internally, under our own process, where it improves our output. A person owns every finding that reaches you.

How small is too small?

A single service, a single domain, or a two week build are all normal scopes for us.

What do you need to start?

The outcome you want, the access required to reach it, and a date. Scope and price come back from that.