Cybersecurity Consulting

We test like an adversary.
We report like an engineer.

Penetration testing and security assessments for organisations that need to know their real exposure — not a scanner export with a logo on it. Every finding is proven by hand, rated by business impact, and shipped with the steps to fix it.

> Fixed scope, fixed price
> Critical findings escalated immediately
> Retest included
Services

Security work that produces decisions, not just documents.

Every engagement is scoped up front with a fixed price and a defined deliverable, so you know exactly what you're getting before we start.

Penetration Testing

Goal-based testing of your external perimeter, internal network, web and mobile applications and cloud estate — executed the way a real attacker would.

External perimeter · internal network · web & API · cloud · mobile

Security Assessments

A clear-eyed review of where you actually stand — architecture, identity, endpoints and process — benchmarked against a framework that fits your business.

Architecture · identity · endpoint · logging · process

Compliance Readiness

Preparation and evidence work for the standard you're being held to, without turning your team into a full-time audit department.

Gap analysis · control mapping · evidence · audit support

Incident Response

Support when something has already gone wrong — containment, root-cause analysis, and an honest account of what happened and what it will take to stop a repeat.

Containment · forensics · root cause · post-incident review

Security Architecture

Design review and hardening guidance for cloud and hybrid environments — identity, segmentation, logging and the controls that actually reduce blast radius.

Cloud & hybrid design · IAM · segmentation · detection coverage

Awareness & Phishing

Simulated phishing and practical training that changes behaviour, measured against a baseline so you can show the improvement to your board.

Baseline · simulation · targeted training · board reporting
Fractional leadership

Executive-level security and technology leadership, without the executive payroll.

Most small and mid-sized businesses need someone accountable for security and for technology strategy — but not full-time, and not at a full-time salary. That's what a virtual CISO and a virtual CIO are for.

vCISO — Virtual Chief Information Security Officer

A named security lead for your business on a monthly retainer. Owns the security programme: risk register, policies, vendor and cyber-insurance questionnaires, incident readiness, board and customer reporting — and sits on your side of the table when an auditor, insurer or enterprise customer asks hard questions.

Security programme · risk & policy · audit and insurer liaison · incident readiness · board reporting

vCIO — Virtual Chief Information Officer

Technology strategy and oversight for businesses that have outgrown "whoever knows computers." Roadmap and budget, vendor and contract review, cloud and licensing rationalisation, project oversight — decisions made by someone whose only incentive is your outcome, not a reseller margin.

Technology roadmap · budget & vendor management · cloud and licensing · project oversight · staff guidance
Web & Cloud

Security is the focus. It isn't the whole business.

We also design, build and host websites and applications — on the same hardened footing we'd demand of a client. One firm for the site, the hosting, the email and the security, so nothing falls between vendors.

Web Design & Development

Fast, accessible sites built by hand — no page-builder bloat, no third-party trackers, strict security headers and a real 404 page from day one.

Design · build · copy & structure · privacy-respecting analytics

Web Hosting

Sites served from a global edge network — DDoS protection, a web application firewall, TLS and DNSSEC included as standard, not sold as extras.

Edge delivery · WAF · HSTS · DNSSEC · uptime

Cloud & Application Hosting

Infrastructure on the major clouds, sized to the workload rather than the vendor's price list. When moving providers cuts the bill, we handle the migration.

Compute · storage · migration · monitoring · backups

Business Email

Business-grade email set up properly — SPF, DKIM and DMARC enforced on every domain, so nobody can send email as you. The control most small businesses are missing.

Setup · migration · SPF / DKIM / DMARC · signatures

Domains & DNS

Registration, transfers and DNS managed with DNSSEC validating — the foundation everything else depends on, and the piece most often left at a registrar's defaults.

Registrar · DNS · DNSSEC · email records

Managed Hosting & Support

Updates, monitoring, backups and a rollback path that has actually been tested — and a person to call when something breaks, not a ticket queue.

Monitoring · patching · backups · restore drills · support
Approach

Four steps. No surprises on the invoice.

01

Scope

We agree what's in, what's out, and what success looks like — in writing, before any work begins.

02

Test

Hands-on assessment against your actual environment, with a live channel open for anything critical.

03

Report

Findings ranked by real business risk, each with reproduction steps and a concrete fix.

04

Retest

Once you've remediated, we verify it — and you get a clean report you can hand to a client or auditor.

Deliverables

Exactly what lands on your desk.

No engagement should end with a surprise. This is the deliverable set for every test we run — agreed in the statement of work before we start, and the same whether you're a twelve-person startup or a regulated enterprise.

  • The senior consultant does the work

    The person who scoped your engagement is the person who runs it. Nothing is handed to a junior once the contract is signed.

  • Every finding proven by hand

    Scanner output is a starting point, never a deliverable. If we report it, we exploited it, and we show you how.

  • Retest is part of the price

    Verification of your fixes is included in the engagement, not a second invoice.

About vSevens

Fifteen years inside the environments we now test.

vSevens Consulting is built on more than fifteen years of hands-on cybersecurity and infrastructure work across banking, healthcare and education — sectors where a security decision is also a regulatory one, and where the systems that most need fixing are the ones you can least afford to take offline.

Banking & financial services

Environments where every control has an examiner behind it, evidence matters as much as the fix, and an outage is measured in penalties as well as revenue. We know what holds up when someone is auditing the answer.

Healthcare

Clinical systems that run continuously, connected equipment that cannot simply be patched on a Tuesday, and some of the most sensitive data any organisation holds. Remediation here has to work around care, not interrupt it.

Education

Networks designed to be open, thousands of devices nobody controls, and budgets that reward pragmatism over ideal-world architecture. Advice that ignores those constraints gets filed and never actioned.

We built and ran these systems before we tested them.

That background is the difference. Plenty of people can run a scan and hand you a list. Fewer have carried the pager for the platform underneath — designed the segmentation, owned the identity estate, sat in the change advisory board, and been the one accountable when something broke at two in the morning.

So when we report a finding, the fix accounts for change windows, legacy dependencies and the team who has to keep the service running. Not "upgrade everything" — what to do first, what it will actually take, and what you can safely defer.

Engagement

The questions procurement always asks.

Answered up front, so you don't have to run a discovery call to find out how we work.

How is pricing structured?

Fixed price against a fixed scope, quoted before any work begins. If scope changes mid-engagement we stop and re-quote rather than run up hours.

Will testing disrupt production?

We agree a testing window and a rules-of-engagement document first. Destructive techniques are opt-in only, and we hold a live channel open throughout.

What if you find something critical?

You hear about it immediately — not in the report three weeks later. Critical findings are escalated the moment they're confirmed.

Do you work under NDA?

Yes, as standard. Say so in your first message and we'll have one in place before any technical detail is exchanged.

How long does an engagement take?

Scoping is typically a short call and a questionnaire. Testing duration depends on the estate, and we commit to a date range in the statement of work.

What do you need from us?

Scope confirmation, written authorisation to test, and a technical point of contact. For internal or cloud work, appropriate access.

Get in touch

Tell us what you're worried about.

Send a few lines about your environment and what's prompting the review. You'll get a reply from a consultant, not a sales sequence.

Confidential enquiriesHappy to work under NDA — just say so in your first message.
Response timeWithin one business day.