Case studies
How engagements unfold
Anonymised accounts of the work: what was tested, what turned up, and what changed afterwards. Each one says plainly where it comes from.
Illustrative studies are composites. Engagement reports are confidential, so no client, system, date or figure in them is real. They show the shape of the work and the class of finding, not a particular engagement.
Based on a real engagement means exactly that, with the client anonymised and details changed so they cannot be identified.
Illustrative
Finding the authorisation gaps before launch, not after
A platform preparing to launch asked for a web, API and cloud assessment. The interesting findings were not missing patches but authorisation decisions the application made correctly in the interface and incorrectly in the API behind it.
- Engagement
- Pre-launch assessment: web application, API and cloud
- Outcome
- Fixed and verified by retest before launch, with residual risks accepted knowingly
Read the case study →
Based on a real engagement
The suspected breach that was not a breach, and the real exposure underneath
An organisation believed an outsider had reached a private form. The evidence did not support that. Establishing it surfaced a materially worse exposure that nobody had reported, sitting in plain sight the whole time.
- Engagement
- Incident response: investigating a suspected breach
- Outcome
- The reported intrusion closed as unfounded; a worse, unreported exposure escalated for remediation and notification
Read the case study →
Based on a real engagement
The first day of a source repository compromise
A software company found commits in its source repositories that nobody on the team had written, and developers had already pulled them. The first day was containment: cut off access, stop further changes landing, establish what had changed and which machines had it, then plan the rest deliberately.
- Engagement
- Emergency incident response
- Outcome
- Write access revoked and reissued, main branches behind review, history preserved, affected machines identified, next stage scoped
Read the case study →
Public breach analyses
Separate from our own work: well-documented public incidents, read from published reports through an assumed-breach lens. What the attacker did after getting in, which controls would have stopped or caught each step, and what a test would have shown first.
Read the analyses