What Does Not Change
- Passive only — no systems, networks or accounts are accessed, probed or tested at any point. No authorisation to test is required and no operational risk is introduced.
- Evidence attached to every finding — nothing is asserted that cannot be reproduced from publicly available sources.
- Triaged, not counted — findings are prioritised against confirmed exploitation status, exploitation probability and asset exposure, so you receive decisions rather than a severity histogram.
- Dual-audience reporting — a Board section stating the position plainly, and a technical section your security function or auditors can verify independently.
- A recorded rationale for every finding not remediated immediately, which is the artefact that matters if the question is asked after an incident rather than before one.
Packages and pricing are set out on the assessment packages page. To scope an engagement against your specific obligations, book a short call.