Penetration testing and security assessments for organisations that need to know their real exposure — not a scanner export with a logo on it. Every finding is proven by hand, rated by business impact, and shipped with the steps to fix it.
Every engagement is scoped up front with a fixed price and a defined deliverable, so you know exactly what you're getting before we start.
Goal-based testing of your external perimeter, internal network, web and mobile applications and cloud estate — executed the way a real attacker would.
A clear-eyed review of where you actually stand — architecture, identity, endpoints and process — benchmarked against a framework that fits your business.
Preparation and evidence work for the standard you're being held to, without turning your team into a full-time audit department.
Support when something has already gone wrong — containment, root-cause analysis, and an honest account of what happened and what it will take to stop a repeat.
Design review and hardening guidance for cloud and hybrid environments — identity, segmentation, logging and the controls that actually reduce blast radius.
Simulated phishing and practical training that changes behaviour, measured against a baseline so you can show the improvement to your board.
Most small and mid-sized businesses need someone accountable for security and for technology strategy — but not full-time, and not at a full-time salary. That's what a virtual CISO and a virtual CIO are for.
A named security lead for your business on a monthly retainer. Owns the security programme: risk register, policies, vendor and cyber-insurance questionnaires, incident readiness, board and customer reporting — and sits on your side of the table when an auditor, insurer or enterprise customer asks hard questions.
Technology strategy and oversight for businesses that have outgrown "whoever knows computers." Roadmap and budget, vendor and contract review, cloud and licensing rationalisation, project oversight — decisions made by someone whose only incentive is your outcome, not a reseller margin.
We also design, build and host websites and applications — on the same hardened footing we'd demand of a client. One firm for the site, the hosting, the email and the security, so nothing falls between vendors.
Fast, accessible sites built by hand — no page-builder bloat, no third-party trackers, strict security headers and a real 404 page from day one.
Sites served from a global edge network — DDoS protection, a web application firewall, TLS and DNSSEC included as standard, not sold as extras.
Infrastructure on the major clouds, sized to the workload rather than the vendor's price list. When moving providers cuts the bill, we handle the migration.
Business-grade email set up properly — SPF, DKIM and DMARC enforced on every domain, so nobody can send email as you. The control most small businesses are missing.
Registration, transfers and DNS managed with DNSSEC validating — the foundation everything else depends on, and the piece most often left at a registrar's defaults.
Updates, monitoring, backups and a rollback path that has actually been tested — and a person to call when something breaks, not a ticket queue.
We agree what's in, what's out, and what success looks like — in writing, before any work begins.
Hands-on assessment against your actual environment, with a live channel open for anything critical.
Findings ranked by real business risk, each with reproduction steps and a concrete fix.
Once you've remediated, we verify it — and you get a clean report you can hand to a client or auditor.
No engagement should end with a surprise. This is the deliverable set for every test we run — agreed in the statement of work before we start, and the same whether you're a twelve-person startup or a regulated enterprise.
The person who scoped your engagement is the person who runs it. Nothing is handed to a junior once the contract is signed.
Scanner output is a starting point, never a deliverable. If we report it, we exploited it, and we show you how.
Verification of your fixes is included in the engagement, not a second invoice.
vSevens Consulting is built on more than fifteen years of hands-on cybersecurity and infrastructure work across banking, healthcare and education — sectors where a security decision is also a regulatory one, and where the systems that most need fixing are the ones you can least afford to take offline.
Environments where every control has an examiner behind it, evidence matters as much as the fix, and an outage is measured in penalties as well as revenue. We know what holds up when someone is auditing the answer.
Clinical systems that run continuously, connected equipment that cannot simply be patched on a Tuesday, and some of the most sensitive data any organisation holds. Remediation here has to work around care, not interrupt it.
Networks designed to be open, thousands of devices nobody controls, and budgets that reward pragmatism over ideal-world architecture. Advice that ignores those constraints gets filed and never actioned.
That background is the difference. Plenty of people can run a scan and hand you a list. Fewer have carried the pager for the platform underneath — designed the segmentation, owned the identity estate, sat in the change advisory board, and been the one accountable when something broke at two in the morning.
So when we report a finding, the fix accounts for change windows, legacy dependencies and the team who has to keep the service running. Not "upgrade everything" — what to do first, what it will actually take, and what you can safely defer.
Answered up front, so you don't have to run a discovery call to find out how we work.
Fixed price against a fixed scope, quoted before any work begins. If scope changes mid-engagement we stop and re-quote rather than run up hours.
We agree a testing window and a rules-of-engagement document first. Destructive techniques are opt-in only, and we hold a live channel open throughout.
You hear about it immediately — not in the report three weeks later. Critical findings are escalated the moment they're confirmed.
Yes, as standard. Say so in your first message and we'll have one in place before any technical detail is exchanged.
Scoping is typically a short call and a questionnaire. Testing duration depends on the estate, and we commit to a date range in the statement of work.
Scope confirmation, written authorisation to test, and a technical point of contact. For internal or cloud work, appropriate access.
Send a few lines about your environment and what's prompting the review. You'll get a reply from a consultant, not a sales sequence.