Skip to main content
Offensive security & risk management

Assume you are already breached.Then go and prove it.

Assumed Breach is a cybersecurity consultancy that attacks your network, applications, cloud and people the way a real adversary would, then hands you the findings, the proof, and the fix, in plain language your board and your engineers can both act on. Assumed breach is the model we work from: we start from the position that an attacker is already inside.

  • Penetration testing
  • Red team operations
  • Cloud & API security
  • Incident response
About us

Security work that ends in evidence, not a checklist

We assess the systems you actually run, in the way an adversary would actually approach them. Every engagement is scoped around your environment and delivered with proof of what we found and a route to fixing it.

  • Comprehensive security assessments
  • Cybersecurity awareness training
  • Tailored testing strategies
  • Incident response & recovery
  • Penetration testing & audits
  • Cloud and API security

All of it runs on one assumption: that a breach is already assumed, and the question worth answering is what happens next.

Illustration of a security assessment in progress
Evidence

What the work leaves behind

Engagement reports are confidential, so what follows is written rather than lifted. Each case study is a composite: the shape of the work and the class of finding, with no real client, system, date or figure in it.

Writing

Notes from the work

Technical write-ups from real engagements and research: what we found, how it was exploited, and what closes it.

Services

What we test, and how deep we go

Engagements are scoped to your estate and your risk, not to a package tier. Every one of these ends in a report you can hand to an engineer and a summary you can hand to your board.

Not sure which of these you need? Tell us what you are worried about and we will scope it with you.

Why Assumed Breach

What working with us actually looks like

No packaged tiers, no scan-and-send. Here is what you can expect from an engagement, before you ever get on a call with us.

End-to-end coverage

From discovery and exploitation through to remediation guidance and re-testing.

One team, whole estate

Network, applications, cloud, APIs and people assessed by the same team, against one threat model.

Practitioners, not scanners

Testing is hands-on and manual. Automated tooling supports the work; it never substitutes for it.

Support past the report

We stay available through remediation and re-test the fixes rather than closing the engagement at delivery.

Current tradecraft

Techniques tracked against how intrusions are actually carried out today, not a static checklist.

Reports you can act on

Findings are reproducible, prioritised by real exploitability, and written to be read by both engineers and executives.

Our approach

How the work is actually done

  1. We start from the assumption that you are already compromised

    Perimeter-first thinking asks whether someone can get in. We ask what happens once they have. That reframing is what surfaces the flat networks, the over-privileged service accounts and the unmonitored lateral paths that a pass/fail scan will never report.

  2. Findings come with proof and a route to remediation

    Every issue we raise is demonstrated, rated by real exploitability in your environment, and paired with the change that closes it. You get a technical report your engineers can work from and a summary that answers the only question leadership is asking: how exposed are we.

  3. When something does happen, we help you get back

    Incident response work focuses on containment and eviction first, then a clear account of how the intrusion happened and what has to change so it does not happen the same way twice.

Certifications

Credentials behind the work

The people running your engagement hold recognised offensive security certifications. These are the ones we hold.

  • Practical Network Penetration Tester (PNPT), TCM Security

    PNPT

    TCM Security

  • Red Team Ops I (CRTO), Zero-Point Security

    CRTO

    Zero-Point Security

  • CompTIA Security+ (CE) (Security+), CompTIA

    Security+

    CompTIA

  • Google IT Support Certificate, Google

    Google IT Support Certificate

    Google

Track record

Why teams bring us in

Drawn from recommendations written by the people we have worked with and from completed contracts. Summarised here rather than quoted, because the originals are theirs to have written; both sources are public and linked below.

  • Ownership past the brief

    The people we have worked with describe scope being extended rather than defended: work taken on without being asked for, and value added beyond what was agreed.

  • Environments, not only findings

    Alongside assessment work we have designed live capture-the-flag environments and proof-of-concept ranges for security products, built to be attacked rather than demonstrated.

  • Pace that fits a product schedule

    Engagements have run against real product deadlines, including getting a platform ready for red team testing, at a pace the teams involved called out specifically.

  • Findings a board and an engineer can both use

    The point most consistently raised is communication: technical depth that survives being explained, and collaboration that people wanted to repeat.

Contact

Tell us what you are worried about

Describe the environment and the concern. We will come back by email with the questions we would need answered to scope it properly.

Get the write-ups by email

New technical write-ups and notable breach analysis, sent when we publish. No drip sequences, no sales cadence, unsubscribe any time.