Security services for organisations that carry regulatory weight
Six services, scoped and reported to a single standard: a written boundary, manual verification of every finding, CVSS 4.0 severity, and a retest that confirms closure.
Each engagement below is delivered under the same methodology and produces the same documentation set, so results are comparable between assessments and across years. Where a service touches on advisory work, we keep that work separate from assessment work and declare the overlap in writing. Nothing on this page implies a certification, accreditation or membership that INLD does not hold.
Penetration testing at INLD is a manual discipline supported by tooling, not the other way round. We begin from an agreed scope and rules of engagement, map the attack surface, and then work through authentication, authorisation, session management, input handling, business logic and data exposure in the order that risk dictates. Automated scanners are used with tuned rulesets to clear ground quickly; every candidate finding is then verified by hand so the report contains no unconfirmed scanner output. Where exploitation is authorised, we produce controlled proof-of-concept evidence to establish real impact rather than theoretical severity. Findings are documented with reproduction steps precise enough for a developer to follow without contacting us.
What is included
External and internal network testing within the agreed boundary
Web application testing aligned with the OWASP Testing Guide v4.2
Authentication, session management and access control testing
Business logic and workflow abuse testing
Mobile application testing aligned with the OWASP MASTG (iOS and Android)
Controlled exploitation and privilege escalation where authorised
Manual verification of every automated finding before it reaches the report
Deliverables
Executive summary written for a non-technical board audience
Technical report with CVSS 4.0 vectors, reproduction steps and evidence
Remediation roadmap prioritised by risk and implementation effort
Retest report confirming which findings are resolved
Attestation of completion suitable for regulators, auditors and partners
02
Cloud Infrastructure Security
Typical timeline
2-4 weeks depending on the number of accounts and workloads
Most cloud incidents we see are not exotic. They come from identity policies that grew permissive over time, storage that became reachable through a chain of defaults, secrets committed to build pipelines, or logging that was never routed anywhere an analyst would look. Our cloud assessment reviews the account or subscription structure, identity and access management, network segmentation, data storage and encryption, secrets handling, and detection coverage. We work from the CIS Benchmarks and the relevant provider well-architected security guidance, then apply the client's own regulatory context to decide what actually matters. The output separates control gaps that create present exposure from those that create audit findings, because the two need different response timelines.
What is included
Account, subscription and project structure review
IAM policy analysis: over-permissive roles, unused credentials, privilege paths
Digital asset platforms fail at the seams: between the trading engine and the withdrawal path, between the signing service and the approval workflow, between what the key ceremony documented and what operations actually does on a Friday evening. Our assessments treat key material and withdrawal authorisation as the crown jewels and work outwards. We review hot, warm and cold wallet architecture, HSM and MPC configuration where present, deposit crediting and confirmation logic, withdrawal approval workflows and their limits, address allowlisting, and the internal transfer paths that often sit outside the main control set. Blockchain-specific issues such as chain reorganisation handling, replay exposure and token contract behaviour are assessed against the specific chains in scope.
What is included
Hot, warm and cold wallet architecture review
Key generation, storage, backup and recovery assessment (HSM and MPC configurations)
Withdrawal authorisation workflow, approval thresholds and limit enforcement
Deposit crediting, confirmation depth and reorganisation handling
Exchange platform application and API testing
Internal transfer and treasury operation controls
Token contract and integration review for supported assets
Deliverables
Executive summary framed around custody and withdrawal risk
Technical report with CVSS 4.0 scoring and asset-flow diagrams
Key management gap analysis against documented policy
Remediation roadmap prioritised by loss potential
Retest report and attestation of completion
04
API Security Assessment
Typical timeline
2-4 weeks depending on endpoint count and integration scope
APIs concentrate risk because they expose business logic directly, often to partners whose own security posture is unknown. Object-level and function-level authorisation flaws dominate what we find: an endpoint that checks whether you are authenticated but not whether the record belongs to you. We test against the OWASP API Security Top 10, working through broken object level authorisation, broken authentication, property-level exposure, resource consumption limits, function-level authorisation, sensitive business flow abuse, server-side request forgery, and inventory management. GraphQL scope adds introspection exposure, query depth and complexity limits, and batching abuse. Partner and machine-to-machine integrations are assessed for credential handling, token scope and replay resistance.
What is included
REST and GraphQL endpoint enumeration and inventory verification
Broken object level and function level authorisation testing
Authentication, token issuance, scope and lifetime review
Excessive data exposure and property-level authorisation testing
Rate limiting and resource consumption testing
Sensitive business flow abuse testing
Partner and machine-to-machine integration credential review
Deliverables
Executive summary of API risk posture
Technical findings mapped to the OWASP API Security Top 10
Endpoint inventory highlighting undocumented and deprecated routes
Remediation roadmap with example fixes
Retest report following remediation
05
Compliance Advisory
Typical timeline
3-6 weeks for a readiness assessment; remediation support is scoped separately
Compliance advisory at INLD is about closing the distance between how an organisation actually operates and what a framework requires it to evidence. We run readiness assessments against ISO/IEC 27001:2022 Annex A controls and the SOC 2 Trust Services Criteria, identify which requirements are met in practice but undocumented, which are documented but not performed, and which are genuinely absent. For regulated firms we map security obligations arising from GDPR, DORA and MiCA onto existing controls so the same evidence serves more than one obligation. We do not issue certifications and we are not a certification body; our role is to prepare an organisation so that an accredited auditor finds what they expect to find.
What is included
ISO/IEC 27001:2022 readiness assessment against Annex A controls
SOC 2 Trust Services Criteria gap analysis
GDPR technical and organisational measures review
DORA ICT risk management and incident reporting readiness review
MiCA operational resilience requirements mapping for digital asset firms
Policy and procedure review against operational reality
Evidence-collection guidance ahead of external audit
Deliverables
Readiness report with control-by-control status
Gap register with owner, effort estimate and priority
Consolidated control map showing where one control satisfies several obligations
Remediation plan sequenced against the target audit date
Follow-up review before the external audit window
06
Security Training
Typical timeline
Half-day to three-day formats; scheduled around the client's release calendar
Training only changes behaviour when the examples are recognisable. We build sessions from the findings in your own codebase and infrastructure, anonymised where required, so developers see the actual pattern that produced the vulnerability rather than a textbook illustration. Secure coding workshops cover the vulnerability classes that appear in your stack and language, with hands-on exercises. Vulnerability awareness sessions target product, operations and support staff whose decisions create or close exposure. Incident response tabletop exercises put the response plan under pressure with a scenario drawn from the threat profile of the business — a custody incident for a digital asset firm, a payment fraud chain for a processor.
What is included
Secure coding workshops tailored to the client's stack and languages
Vulnerability awareness sessions for non-engineering staff
Threat modelling facilitation for product and architecture teams
Incident response tabletop exercises with scenario design
Post-exercise review with prioritised plan improvements
Session materials retained by the client for internal reuse
Deliverables
Tailored session materials and exercise packs
Facilitated delivery, remote or on site
Tabletop exercise report with observed gaps and recommendations
Knowledge check results where assessment is requested
Start with a scoping conversation
Tell us about your environment, regulatory context and timelines. We will tell you what an assessment would realistically involve, before any commitment.