Our Past Projects
A selection of engagements across incident response, red teaming, penetration testing, AI security, and our in-house tooling. Client identities and specifics are kept confidential under NDA.
Challenge — Organisations across manufacturing, marketing, and the public sector faced active threats — ransomware, APT intrusions, and insider attacks — demanding rapid, discreet response.
Approach — Our certified team combined AI-assisted triage of logs and event data with hands-on forensic analysis to contain, investigate, and eradicate each threat, extending detection and attribution with VirusTotal Enterprise threat intelligence.
Outcome — Incidents were contained and remediated with client operations and trust preserved. Specific details remain confidential under NDA.
Challenge — A software vendor specialising in game development needed comprehensive, ongoing security across its development lifecycle and digital assets.
Approach — We delivered end-to-end consultancy — incident response, advanced penetration testing, security assessments, policy reviews, and project advisory — with real-time monitoring via Splunk and threat intelligence via VirusTotal Enterprise.
Outcome — The vendor gained a robust, continuously monitored defence and a trusted long-term security partner. Details remain confidential under NDA.
Challenge — A prestigious Hong Kong financial corporation wanted to know how its defences would hold against a real, full-scale cyber attack.
Approach — We simulated an end-to-end adversary campaign following the MITRE ATT&CK framework — testing electronic trading systems, backend databases, and the human layer through social engineering — augmented with AI-accelerated reconnaissance.
Outcome — The client received a clear map of exploitable paths and detection/response gaps, with prioritised guidance to strengthen its overall security posture. Details remain confidential under NDA.
Challenge — Distinguished organisations across the charity, sports, insurance, financial, and NGO sectors needed to uncover weaknesses before attackers could.
Approach — We combined real-world penetration testing with methodical vulnerability assessment — validating and prioritising findings with our in-house AI Bug Hunt engine, while consultants drove strategy and confirmed real-world impact.
Outcome — Each organisation received a prioritised, risk-ranked roadmap to remediate weaknesses across infrastructure, applications, and operational procedures. Details remain confidential under NDA.
Challenge — Teams needed practical, real-world cybersecurity skills rather than theory.
Approach — Our tailored training suite covers incident handling, red vs. blue team simulations, web hacking (SQL injection, XSS), advanced exploitation, and security awareness — now including AI security topics such as the OWASP LLM Top 10 and prompt injection.
Outcome — Participants leave equipped to identify, contain, and mitigate modern threats, with a stronger security culture across the organisation.
Challenge — Development teams needed to build security into their .NET and Java Spring Boot applications from the start.
Approach — Through hands-on secure-coding training and code review — accelerated by our AI Bug Hunt tooling for coverage across large codebases — we taught teams to identify and mitigate risks at every stage of the software development lifecycle.
Outcome — Developers gained the skills and practices to ship more secure, resilient applications by design.
Challenge — A public-facing AI chatbot/assistant needed testing against emerging LLM threats — prompt injection, sensitive data leakage, jailbreaks, and abuse of connected tools.
Approach — We developed purpose-built software to automate adversarial prompt generation and response evaluation at scale, with certified consultants confirming exploitability and prioritising real-world impact — the same capability behind our AI Resil engine.
Outcome — The client received actionable hardening guidance to secure its AI application before attackers could reach it. Details remain confidential under NDA.
Challenge — Off-the-shelf tooling often can’t keep pace with modern, AI-era attack surfaces.
Approach — Our team builds its own security software — including our AI Bug Hunt engine and AI Resil testing engine — to give our consultants faster, broader, and more consistent coverage, with human expertise and judgement at the core. We also develop custom security software selectively, on request.
Outcome — Clients benefit from capabilities beyond standard methodology, and bespoke tools when an engagement demands them.