Services

Offensive testing, governance, leadership, and response

Every engagement is scoped to your risk and delivered against a consistent methodology. IT support and services round out the practice so security and operations stay aligned.

Penetration Testing (VAPT)

We simulate real-world attacks against your external, internal, web, and mobile environments to identify exploitable weaknesses before adversaries do. Engagements are goal-driven and mapped to actual risk, not a generic checklist.

Vulnerability Assessment

Systematic identification, classification, and prioritization of vulnerabilities across your infrastructure. You get actionable, risk-ranked findings, not just a scanner printout.

GRC & Compliance Consulting (ISO 27001)

Gap assessments, control implementation, and audit readiness support for ISO 27001-aligned information security management systems.

vCISO (Virtual CISO)

Fractional access to senior security leadership: strategy, risk management, board and leadership reporting, and program oversight, without the cost of a full-time in-house CISO.

Incident Response

Rapid, structured response to active security incidents: containment, eradication, recovery, and post-incident hardening.

Digital Forensics

Evidence-grade investigation following a breach or suspected compromise: tracing attacker activity, scoping impact, and producing findings suitable for remediation or legal action.

Phishing Simulation

Controlled, realistic phishing campaigns to measure real-world susceptibility and establish a baseline for improvement.

Security Awareness Training

Practical, role-relevant training turning employees into the first line of defense.

IT Support

Responsive technical support for day-to-day IT needs, complementing the security work.

IT Services

Broader IT consulting and systems support: infrastructure guidance, technical advisory, and project-based IT work.

Our Approach

Discovery, Assessment, Testing, Remediation Guidance

The four phases apply across service lines. Scope changes the depth of each phase, not the structure.

01

Discovery

We define scope, objectives, and rules of engagement with your team, then map the assets, data flows, and threat scenarios that actually matter to your business. Testing is aimed at real risk, not a generic list.

02

Assessment

We review architecture, configurations, and controls to understand your current posture and where exposure concentrates. This frames the hands-on work and separates theoretical issues from practical ones.

03

Testing

We safely attempt to exploit identified weaknesses using manual, goal-driven techniques supported by tooling, chaining findings the way an attacker would to demonstrate genuine impact rather than raw scanner output.

04

Remediation Guidance

You receive risk-ranked findings with clear reproduction steps and specific, prioritized fixes. We debrief your technical and leadership stakeholders and re-test remediated items to confirm closure.

Cyber insurance: we offer advisory and facilitation support around coverage requirements, evidence preparation, and control improvements. Cipher01 is not a licensed insurance broker.

Not sure which engagement fits?

Share your objectives and constraints and we will recommend a scope.