Skip to content

TECHNOLOGY · SECURITY · ADVISORY

We help organizations design, secure, engineer and transform technology across applications, AI, infrastructure, compliance and digital platforms.

01WHAT WE ARE

Build it, secure it, prove it.

One practice across the full life of a system. We design and build technology, we assess and secure it, and we help you govern it well enough to show a regulator, an auditor or your largest customer.

01

TECHNOLOGY

We design and develop software, applications, digital platforms, SaaS products, AI solutions and technology-enabled services.

02

SECURITY

We assess, engineer and secure applications, AI systems, cloud environments, infrastructure and digital technologies.

03

ADVISORY

We help organizations navigate security architecture, privacy, GRC, ISO, compliance, risk and technology transformation.

02What we do

Ten practices, one accountable team.

85 services across assessment, engineering, build, governance and advisory. Most engagements draw on two or three.

03AI Security · in practice

An AI system is an architecture, not a model.

Every component moves trust somewhere new, and every label under it is a class of finding we test for. This is the scope of an AI security assessment.

  1. 01

    USER

    Untrusted input, always

  2. 02

    AI APPLICATION

    Where policy is enforced: or is not

    PROMPT INJECTION
  3. 03

    LLM

    Instruction-following, not judgement

    GUARDRAIL EVASION
  4. 04

    RAG

    Retrieved content is executable text

    INDIRECT INJECTION
  5. 05

    AGENT

    Plans, loops and acts on your behalf

    AGENTIC RISK
  6. 06

    TOOLS

    Every tool is a new privilege

    TOOL ABUSE
  7. 07

    MCP

    Transitive trust across servers

    PRIVILEGE ESCALATION
  8. 08

    ENTERPRISE DATA

    The boundary that must hold

    DATA LEAKAGE
04How findings are delivered

A finding is a fact. A path is a business risk.

We do not hand over a list of issues. We show the chain, how one weak assumption becomes access to the thing you actually care about, and what breaking the chain costs.

  1. 01

    Entry

    Attacker

    Unauthenticated, internet-based

    No credentials, no prior access, no insider. Everything that follows is earned from a standing start, which is what makes the chain worth taking seriously.

  2. 02

    Exposure

    Public API

    Undocumented v1 route still reachable

    A deprecated endpoint nobody owns is still routed, still authenticating, and absent from the asset inventory the security team works from.

  3. 03

    Vulnerability

    Broken authorization

    Object ID accepted without ownership check

    Any authenticated user can read any object by changing an identifier. Individually this scores medium. In this chain it is the hinge everything turns on.

  4. 04

    Pivot

    Internal service

    Trusted network call, no second check

    The internal service trusts the caller because the call came from inside the perimeter. The perimeter stopped being a boundary two steps ago.

  5. 05

    Privilege

    Cloud role

    Service identity scoped far too widely

    The workload's role can read every bucket in the account rather than the one it needs. Convenience at provisioning time becomes blast radius at breach time.

  6. 06

    Objective

    Crown jewel

    Customer data store, fully readable

    The full customer dataset, readable and exfiltratable without a single alert firing. This is the number that appears in the breach notification.

05How we work

Assess. Advise. Architect. Assure.

One continuous engagement model. Each stage hands the next something real, and the last one hands you evidence.

01

ASSESS

Establish the real picture

Systems, exposure, ownership and business impact, mapped as they actually are rather than as the architecture diagram claims. Nothing useful follows from a scope built on assumptions.

  • Attack surface and asset discovery
  • Trust boundaries and privilege paths
  • Impact framed in business terms
02

ADVISE

Turn findings into decisions

Findings ranked by consequence rather than severity label, with trade-offs made explicit. Leadership gets a small number of decisions to make, each with a cost and a reason.

  • Prioritised, costed remediation
  • Board and regulator-ready framing
  • Clear ownership per decision
03

ARCHITECT

Design what closes the gap

Reference architectures, control design and the operating model that keeps them working after we leave. Design-level fixes close classes of issues rather than individual tickets.

  • Reference architectures and control design
  • Policy, process and accountability
  • Built to be run by your team
04

ASSURE

Prove it holds

Validation that the change worked, documented to a standard that survives a customer security review, a regulator or an audit committee.

  • Targeted retesting and verification
  • Evidence packs for audit and customers
  • Ongoing assurance cadence
07Selected work

What the engagements produced.

Anonymised, but real. Each ran the same way: assess the actual exposure, advise on the decisions that matter, design the fix, prove it holds.

Multi-cloudCloud security

89 findings

misconfigurations closed across AWS and Azure

Challenge
Two clouds grown separately, with no shared view of identity, exposure or blast radius.
Approach
We reviewed both estates against the privilege paths that actually reach data, rather than auditing settings in isolation.
Outcome
Eighty-nine misconfigurations remediated and a single posture baseline the team could keep enforcing after we left.
HealthcareAI security

Adversarial

vulnerabilities found in a clinical ML model

Challenge
A healthcare AI system heading toward clinical use with no adversarial testing in its assurance plan.
Approach
We tested the model the way an attacker would: crafted inputs, boundary probing and the data pipeline feeding it.
Outcome
Adversarial weaknesses identified and documented before deployment, with retraining and input-validation guidance.
Incident responseContainment

2 hours

to containment, 100% of data recovered

Challenge
Live ransomware with encryption already spreading across shared infrastructure.
Approach
Containment first, forensics second: isolate propagation paths, then establish entry point and dwell time.
Outcome
Contained inside two hours with full data recovery, followed by the access-control changes that closed the original route in.
08Specialist depth

The patterns we see before you do.

Four things the engagements keep proving. Recognising them on day one is most of what makes an assessment fast.

Agent & MCP trust

An agent's real authority is always wider than its operator believes.

Permission scope compounds across tool servers. We map effective authority rather than declared authority, because the gap between the two is where agent compromise actually happens.

ASSESSED ON EVERY AI ENGAGEMENT

Retrieval integrity

Retrieved content is executable text, and most pipelines treat it as data.

We test RAG against an attacker who can write to the corpus, because that is the only threat model that matters once retrieval sits in the loop. Provenance and isolation hold. Output filtering does not.

STANDARD SCOPE IN LLM TESTING

Cloud privilege paths

The route from build pipeline to production data is usually three steps.

The same role-assumption chains recur across estates because the same provisioning habits do. We look for them first, which is why cloud assessments close faster than teams expect.

FOUND IN MOST MULTI-ACCOUNT ESTATES

Assurance & evidence

Most penetration-test reports fail a customer security review.

Auditors, enterprise buyers and regulators each accept different evidence. We write to all three from the first day of an engagement, which is why our reports survive procurement instead of triggering another round.

BUILT INTO EVERY DELIVERABLE

09Standards

Measured against what your auditors actually ask about.

Findings are mapped to the frameworks your regulators, customers and certification bodies already use, so the work lands as evidence rather than opinion.

EU AI Act

AI regulatory readiness

NIST AI RMF

AI risk management

ISO/IEC 42001

AI management systems

ISO 27001

Information security management

NIST CSF

Program benchmarking

NIST 800-53

Control baselines

GDPR

Privacy and data protection

OWASP LLM Top 10

AI failure classes

10FAQ

The questions people actually ask.

If yours is not here, ask it directly: the first reply comes from a practitioner, not a sales desk.

It starts with a scoping conversation, not a proposal template. Most engagements run Assess → Advise → Architect → Assure, though many clients begin with a single assessment and expand from there. You will know the shape and the cost before any work begins.

Cybaethrex Training

Need to build your team's security capabilities?

Cybaethrex Training delivers professional, corporate and university programs in AI security, cloud security and offensive security, taught by the same practitioners who run the engagements.

Explore Cybaethrex Training

Next step

Have a security decision to make?

Let’s make it an informed one.

Tell us what you are building, adopting or worried about. You will get a practitioner’s view of where the risk actually sits, before any engagement is scoped.