Skip to content
NedSec

Services

We put automated tooling and AI to work alongside our testers, because the two together find more than either does on its own. Below is what we do most often. If your target is close to one of these, it's worth a conversation.

We work through your web application the way someone trying to break into it would: who can reach what, what happens to the input you accept, and where the logic can be talked into doing something it shouldn’t. Coverage follows the OWASP Web Security Testing Guide.

Most web applications are a front end sitting on top of an API, so the API gets tested as part of every web application test we run. Where the API is the product in its own right, with no front end or one somebody else built, we test it on its own, working against the endpoints directly rather than through a browser.

This one starts inside, from where a phished employee, a stolen laptop or a contractor on the VPN would land, and works out how far that gets. The report follows the attack paths we found, so you can see the handful of places worth fixing first rather than a flat list of hosts.

Android and iOS apps tested on real handsets: the app itself, what it leaves behind on the device, and the backend it talks to. We cover the OWASP Mobile Application Security Verification Standard, and the write-up is meant to be useful to the people building the app.

Phishing, phone calls, and where the scope allows, someone turning up in person. All of it runs against a list you sign off in advance. We report what happened and the patterns behind it rather than who clicked, so you end up with something your awareness programme can use.

For teams running a security operations centre, or building one. We look at what your detections actually cover, how alerts get handled once they fire, and whether the tooling earns its place. It often works best as a purple team run alongside one of the tests above, with your analysts watching.

How we run an engagement

  • Scope in writing first. Targets, timing, rules of engagement, and emergency contacts are agreed and signed before anything starts.
  • The right mix. Automated tools and AI give us reach across the whole target; our testers follow the leads that look interesting and work out what they actually mean for you.
  • Talk to us during, not just after. Critical findings are reported the day we find them, not held for the report.
  • Retest included. Once you have remediated, we re-test the findings and reissue the report so you have clean evidence for customers and auditors.

How we price

Fixed fee per engagement*, based on scope and estimated days. Retests of the original findings are included, and there is no recurring subscription to sign.

* Discounts for new and referring clients apply.