Case
studies.
Anonymised summaries of recent engagements. Client names withheld; methodology, timelines, and outcomes are real.
- 01 · Web infrastructure · Incident response · 2 weeks ·
Contained a click-fix campaign abusing a zero-day across 60+ Cloudflare-fronted subdomains
Two-week incident response engagement against an active click-fix campaign that abused a cPanel zero-day to weaponise over sixty subdomains across a shared hosting estate.
Outcomes
- Attacker dwell time confirmed at 6 weeks
- All 60+ subdomains restored within the engagement window
- Detection content (Sigma + YARA) delivered to SOC
- Full timeline and remediation roadmap delivered
- Client retained on a quarterly IR retainer post-incident
Read full case study - 02 · Fintech · Series A · Pre-launch audit · 2 weeks ·
Identified 3 critical auth bypasses and a privilege-escalation chain before public launch
Two-week web and API security audit for a Series A fintech ahead of public launch. Three critical authentication bypasses plus a chained privilege-escalation path were identified, fixed, and retested without shifting the launch date.
Outcomes
- 3 critical, 7 high, 12 medium findings
- End-to-end privilege-escalation chain demonstrated with PoC
- Retest completed before launch
- SOC 2 Type 1 readiness summary appended for auditors
- Launch shipped on the original date
Read full case study - 03 · Fintech · Series B · Compliance · ISO 27001 + SOC 2 · 6 months ·
Dual-framework ISO 27001 and SOC 2 Type 2 readiness for a Series B fintech in six months
Six-month compliance readiness programme for a Series B fintech needing both ISO 27001 and SOC 2 Type 2 to unlock enterprise sales. Coordinated multi-framework approach reduced effort 35% vs sequential certification.
Outcomes
- ISO 27001 certified on first audit attempt
- SOC 2 Type 2 report issued with one minor exception
- Multi-framework approach cut effort ~35% vs sequential
- Evidence-collection automated for 80% of recurring controls
- Two enterprise contracts unblocked within 30 days of certification
Read full case study - 04 · Healthcare SaaS · Red team engagement · 8 weeks ·
Established C2, evaded EDR for 14 days, exfiltrated simulated PHI. Full detection roadmap delivered.
Eight-week full-scope red team engagement against a HIPAA-regulated SaaS platform. Initial access via targeted phishing, domain administrator within five days, persistent C2 maintained for fourteen days without detection.
Outcomes
- Domain administrator in 5 days from initial access
- 14-day C2 dwell time without EDR detection
- Simulated PHI exfiltration completed without alert
- Detection roadmap covering 11 ATT&CK techniques
- Purple-team debrief with the blue team on engagement close
Read full case study - 05 · B2B SaaS · Cloud security audit · 3 weeks ·
Surfaced misconfigured IAM policies exposing internal services across AWS accounts. Remediation completed in 9 days.
Three-week AWS cloud security audit across a multi-account estate. IAM graph analysis uncovered three cross-account privilege-escalation chains. Client closed all findings within nine days of report handover.
Outcomes
- 3 cross-account privilege-escalation chains identified
- IAM excessive-privilege report covering 142 roles
- 9-day remediation cycle
- Attack-path diagrams handed to platform team for ongoing reference
- SOC 2 + ISO 27001 control mapping appended
Read full case study
Client names, regulated data, and identifying details are withheld under engagement NDAs. References available on request.