Service
Security Training
Secure coding practice, vulnerability awareness and incident response tabletop exercises. Sessions are built from findings in the client's own environment rather than generic material.
Training only changes behaviour when the examples are recognisable. We build sessions from the findings in your own codebase and infrastructure, anonymised where required, so developers see the actual pattern that produced the vulnerability rather than a textbook illustration. Secure coding workshops cover the vulnerability classes that appear in your stack and language, with hands-on exercises. Vulnerability awareness sessions target product, operations and support staff whose decisions create or close exposure. Incident response tabletop exercises put the response plan under pressure with a scenario drawn from the threat profile of the business — a custody incident for a digital asset firm, a payment fraud chain for a processor.
What the engagement covers
Training changes behaviour only when the examples are recognisable. Generic secure coding material teaches developers to recognise a textbook vulnerability in a textbook context; it does not help them notice the same class of defect in their own repository, written in their own conventions, by a colleague. Our sessions are built from findings in the client's own environment — anonymised where required — so the pattern being taught is the pattern that actually produced an issue.
Delivery formats run from a half-day workshop to a three-day programme, remote or on site, scheduled around the release calendar rather than against it. Materials are handed to the client at the end so they can be reused for onboarding without repeat engagement.
Secure coding workshops
Workshops are built for the client's stack and language. The vulnerability classes covered are chosen from what the codebase and prior assessments actually show, not from a fixed syllabus. Typical content includes authorisation enforcement patterns, input handling at trust boundaries, safe use of cryptographic primitives, secrets handling in code and pipelines, dependency and supply chain hygiene, and the specific pitfalls of the frameworks in use.
Sessions are hands-on. Participants work with deliberately vulnerable code that mirrors their own structure, identify the defect, fix it, and then verify the fix. The final exercise in most workshops is a review of a real pull request pattern that previously introduced a finding, which tends to be the part participants remember.
Awareness for non-engineering staff
Many security outcomes are decided outside engineering. Support staff who can reset an account, operations staff who can approve a transfer, and product staff who define what a workflow is allowed to do all make decisions that create or close exposure. Awareness sessions for these audiences cover social engineering as it presents in that specific role, the internal process controls that exist and why, and how to escalate something that feels wrong without needing to be certain first.
For digital asset and payments businesses, we include the specific pretexts used against those sectors: fake urgency around a withdrawal hold, spoofed communication from a banking partner or supervisor, and recruitment approaches aimed at staff with production access.
Threat modelling facilitation
Threat modelling sessions are facilitated rather than lectured. We take a real feature that the team is about to build, decompose it with them, identify trust boundaries and assets, and work through what an attacker with each level of access could attempt. The output is a set of concrete requirements added to the feature's backlog, and — more importantly — a repeatable method the team can run without us present.
Incident response tabletop exercises
Tabletop exercises put the incident response plan under pressure with a scenario drawn from the organisation's own threat profile: an unexplained withdrawal pattern for a custodian, a compromised support account for a payment processor, a supplier breach for a SaaS platform. The exercise runs in real time with injects that force decisions under incomplete information.
What the exercise usually reveals is not a missing capability but a missing decision owner: who authorises taking a production service offline, who speaks to the regulator, who confirms that a notification clock has started, and what happens when the person named in the plan is unreachable. The post-exercise report records observed gaps against the written plan and gives a prioritised set of plan amendments.
Output
Clients receive tailored session materials and exercise packs, facilitated delivery, a tabletop exercise report where applicable, and knowledge check results where assessment is requested. Where training follows an assessment, we report which finding classes the session was designed to address so the connection between spend and risk is explicit.
Start with a scoping conversation
Tell us about your environment, regulatory context and timelines. We will tell you what an assessment would realistically involve, before any commitment.
