Cyber Security

Penetration Testing, Red Teaming and Digital Forensics

We provide comprehensive testing and audit services that proactively identify, report and help remediate your security weaknesses. Our tests do not stop at automated scanner output; they include manual verification, exploit chaini…

OWASPPTESMITRE ATT&CKNIST SP 800-115Red / purple team
01

Methodology and Frameworks

  • OWASP Testing Guide and OWASP Top 10 / API Top 10
  • PTES (Penetration Testing Execution Standard)
  • OSSTMM (Open Source Security Testing Methodology Manual)
  • NIST SP 800-115 technical security testing guide
  • Finding classification mapped to MITRE ATT&CK tactics and techniques
  • CVSS severity rating combined with business impact for prioritisation
02

Network and Infrastructure

  • External penetration testing of internet-facing assets
  • Internal penetration testing: lateral movement, privilege escalation and domain takeover scenarios
  • Active Directory security testing and attack path analysis
  • Wireless network penetration testing and rogue access point scenarios
  • Cloud environment (IaaS/PaaS) configuration and access testing
03

Applications

  • Web application penetration testing (authenticated and unauthenticated)
  • API and microservice security testing
  • Mobile application security testing (Android / iOS, based on OWASP MASVS)
  • Thick client and desktop application testing
  • Source code review and secure code audit
04

Human and Physical Layer

  • Phishing and spear phishing simulations
  • Voice (vishing) and SMS (smishing) based social engineering
  • Physical security testing: unauthorised entry, tailgating, device drop scenarios
  • USB drop testing and awareness measurement
05

Specialised Areas

  • Embedded system, IoT device and firmware security analysis
  • Hardware interface review and secure boot chain assessment
  • Industrial control system (OT/SCADA) security assessment
  • Cryptographic implementation and key management review
06

Infrastructure Security Audit

  • Vulnerability scanning and analysis (including authenticated scans)
  • Security configuration audit (CIS Benchmarks, vendor hardening guides)
  • Network infrastructure and firewall rule set audit
  • Entitlement and access rights audit
  • Backup and disaster recovery adequacy audit
  • Cloud environment security audit and benchmarking report
07

Red, Blue and Purple Teaming

  • Objective-based red team operations emulating real adversary behaviour
  • Assumed breach scenarios to measure detection capability
  • Assessment of blue team detection capability and rule development
  • Purple team exercises with attack and defence teams working simultaneously
  • Producing a MITRE ATT&CK coverage map and closing detection gaps
  • Executive-level tabletop crisis exercises
  • Post-exercise maturity score and progress tracking
08

Digital Forensics and Incident Response

The right reflex during an incident is preserving the evidence. The ONGSEC forensics team acquires images, analyses and reports while maintaining evidential integrity. The same team can take on technical coordination during the incident response process.

  • Digital evidence collection, imaging and chain of custody management
  • Disk, memory (RAM), network and cloud forensic analysis
  • Timeline construction and reconstruction of the attack flow
  • Static and dynamic malware analysis
  • Impact assessment, propagation analysis and recovery support in ransomware incidents
  • Internal investigation and data leakage review (coordinated with HR and legal)
  • Incident response coordination and crisis communication support
  • Preparation of court-admissible forensic reports
  • Post-incident root cause analysis and recommendations for preventive controls
09

SOC and CSIRT Establishment Consultancy

  • SOC establishment consultancy: organisation, process, technology and physical space design
  • Establishment of a computer security incident response team (CSIRT/SOME), role definitions and training
  • Creating incident response procedures and a playbook library
  • Designing the shift model, escalation matrix and service level definitions
  • SOC maturity assessment and improvement roadmap
10

Reporting and Closure

  • Executive summary: risk and business impact explained in non-technical language
  • Technical report: findings, evidence, reproduction steps, impact and remediation advice
  • Remediation roadmap prioritised by severity
  • Free retest once findings have been closed
  • Advisory and verification support to technical teams during remediation
  • Annual recurring test programme and trend comparison report
11

Secure Code Review and Application Security Testing

Source code and the running application are examined together; findings are reported in developer language with fix examples.

  • Static analysis (SAST) setup, rule tuning and false-positive reduction
  • Dynamic analysis (DAST) including authenticated scanning
  • Software composition analysis (SCA) for open-source dependency risk
  • Manual review of authentication, authorisation and cryptography
  • Threat modelling workshop and security requirements list
  • Developer training and a secure coding standard
12

Phishing Simulation and Social Engineering Testing

The human layer is measured; the aim is not blame but to see which scenario works and shape training around it.

  • Targeted spear-phishing campaign design
  • QR code, voice (vishing) and SMS scenarios
  • Measurement of click, credential-entry and reporting rates
  • A report button and user feedback loop
  • Targeted awareness training based on results
  • Periodic repetition and an improvement curve report
13

Cyber Exercises and Crisis Management Drills

Who does what during an incident is tested by drill. The tabletop exercise comes before the technical simulation.

  • Scenario design: ransomware, data leak, supplier breach
  • Executive tabletop exercise
  • Live response simulation for the technical team
  • Measurement of decision points, timings and communication flow
  • Press, customer and regulator communication rehearsal
  • Exercise report and improvement action list

Get started

Let us talk about your project.

The first meeting is a discovery session, not a sales pitch. You are also welcome to evaluate our capability directly through a short pilot or proof of concept (PoC) in your own environment.

Fill in the enquiry form

WhatsApp