Services
Offensive testing, governance, leadership, and response
Every engagement is scoped to your risk and delivered against a consistent methodology. IT support and services round out the practice so security and operations stay aligned.
Penetration Testing (VAPT)
We simulate real-world attacks against your external, internal, web, and mobile environments to identify exploitable weaknesses before adversaries do. Engagements are goal-driven and mapped to actual risk, not a generic checklist.
Vulnerability Assessment
Systematic identification, classification, and prioritization of vulnerabilities across your infrastructure. You get actionable, risk-ranked findings, not just a scanner printout.
GRC & Compliance Consulting (ISO 27001)
Gap assessments, control implementation, and audit readiness support for ISO 27001-aligned information security management systems.
vCISO (Virtual CISO)
Fractional access to senior security leadership: strategy, risk management, board and leadership reporting, and program oversight, without the cost of a full-time in-house CISO.
Incident Response
Rapid, structured response to active security incidents: containment, eradication, recovery, and post-incident hardening.
Digital Forensics
Evidence-grade investigation following a breach or suspected compromise: tracing attacker activity, scoping impact, and producing findings suitable for remediation or legal action.
Phishing Simulation
Controlled, realistic phishing campaigns to measure real-world susceptibility and establish a baseline for improvement.
Security Awareness Training
Practical, role-relevant training turning employees into the first line of defense.
IT Support
Responsive technical support for day-to-day IT needs, complementing the security work.
IT Services
Broader IT consulting and systems support: infrastructure guidance, technical advisory, and project-based IT work.
Our Approach
Discovery, Assessment, Testing, Remediation Guidance
The four phases apply across service lines. Scope changes the depth of each phase, not the structure.
Discovery
We define scope, objectives, and rules of engagement with your team, then map the assets, data flows, and threat scenarios that actually matter to your business. Testing is aimed at real risk, not a generic list.
Assessment
We review architecture, configurations, and controls to understand your current posture and where exposure concentrates. This frames the hands-on work and separates theoretical issues from practical ones.
Testing
We safely attempt to exploit identified weaknesses using manual, goal-driven techniques supported by tooling, chaining findings the way an attacker would to demonstrate genuine impact rather than raw scanner output.
Remediation Guidance
You receive risk-ranked findings with clear reproduction steps and specific, prioritized fixes. We debrief your technical and leadership stakeholders and re-test remediated items to confirm closure.
Cyber insurance: we offer advisory and facilitation support around coverage requirements, evidence preparation, and control improvements. Cipher01 is not a licensed insurance broker.