Services

Findings, evidence and certification.

Work that produces a defensible answer rather than a codebase. You get the report, the evidence behind it and the remediation plan, whether or not you hire us to do the remediation.

  • PQC readiness
  • Offensive testing
  • GRC
  • Audit support
  • Training

S—01

Post-quantum readiness assessment

Six to eight weeks. The cheapest way to find out how exposed you are.

Before any migration, you need to know where your cryptography lives. Most organisations have never had that inventory built.

Discovery

  • Cryptographic bill of materials
  • Certificate and key inventory
  • Protocol and cipher-suite scanning
  • Third-party and supply-chain dependencies

Risk

  • Exposure ranked by confidentiality lifetime
  • Harvest-now-decrypt-later modelling
  • Regulatory deadline mapping
  • Business impact and prioritisation

Roadmap

  • Costed, sequenced migration plan
  • Crypto-agility target architecture
  • Vendor and product gap analysis
  • Board-level summary and technical annex

Standards

  • NIST FIPS 203 / 204 / 205 alignment
  • Entropy source validation, SP 800-90B
  • Key management policy review
  • Cryptographic governance framework

S—02

Security assessment and testing

Scoped, authorised and evidenced. Findings come with reproduction steps.

Offensive testing against your systems, run under written authorisation with agreed rules of engagement.

Penetration testing

  • External and internal network
  • Web and API application testing
  • Mobile application assessment
  • Cloud configuration review

Code and design

  • Secure source code review
  • Cryptographic implementation review
  • Threat modelling and architecture review
  • Dependency and SBOM analysis

Adversarial

  • Red team engagements
  • Social engineering and phishing simulation
  • Physical and access control testing
  • Purple team exercises with your SOC

Infrastructure

  • Network segmentation review
  • OT and embedded device assessment
  • Configuration and hardening audits
  • Vulnerability management programmes

S—03

Governance, risk and compliance

We prepare you for the audit. An independent body issues the certificate.

Framework implementation, gap closure and the evidence pack your assessor will ask for.

Frameworks

  • ISO 27001 and ISO 27701
  • SOC 1, SOC 2 and SOC 3 readiness
  • PCI DSS
  • NIST CSF and ISO 22301

Privacy

  • GDPR alignment and DPIAs
  • Qatar data protection compliance
  • HIPAA and HITRUST
  • Cross-border transfer and residency

Programme

  • Gap analysis and remediation planning
  • Policy and control set development
  • Risk register and treatment plans
  • Internal audit and management review

Supply chain

  • Third-party risk assessment
  • Vendor security questionnaires
  • Contractual security requirements
  • Continuous monitoring programmes

S—04

Advisory and technical due diligence

Short engagements. Written answers to questions that carry real cost.

Independent judgement where the decision matters more than the deliverable.

Strategy

  • Quantum readiness roadmaps
  • Build, buy or wait assessments
  • Vendor and platform selection
  • Security architecture review

Feasibility

  • Is this problem worth quantum attention
  • Classical baseline establishment
  • Proof-of-concept scoping
  • Cost and timeline modelling

Due diligence

  • Technical review for investors
  • Claims verification on quantum products
  • Codebase and architecture assessment
  • Team capability review

Incident

  • Cryptographic incident response
  • Key compromise recovery planning
  • Post-incident review
  • Tabletop exercises

S—05

Training and enablement

Delivered in Doha or remote. Built around your codebase, not a generic curriculum.

Your engineers should be able to carry this work after we leave. Training is how that happens.

Quantum

  • Quantum computing foundations for engineers
  • Optimization and QUBO formulation workshops
  • Quantum machine learning practicum
  • Hands-on labs on real backends

Cryptography

  • Post-quantum cryptography for developers
  • Crypto-agility design patterns
  • Key management and PKI operations
  • Migration planning workshops

Security

  • Secure development lifecycle
  • Threat modelling for product teams
  • Security awareness for non-technical staff
  • Incident response drills

Executive

  • Board briefings on quantum risk
  • Regulatory landscape sessions
  • Investment and prioritisation framing
  • Separating the claims from the physics

§ What you receive

Report

Findings, ranked

Every finding carries severity, reproduction steps, business impact and a remediation path. Written so an engineer can act and an executive can decide.

Evidence

The working

Scan output, test artefacts, inventory data and methodology. Your auditor will ask for this, and so will anyone who wants to reproduce our conclusions.

Debrief

A session, not a PDF drop

We walk your team through the findings and answer questions. Re-testing after remediation is included in the original scope.

Get in touch

Tell us what you need evidenced.

A readiness assessment, an audit you have to pass, or a claim you need verified independently. Send the scope and we will tell you what it takes.

Doha, Qatar