Architecture & threat modelling
Identify assets, trust boundaries and abuse scenarios early enough to influence the design.
Service portfolio / 04
Make security part of how software is designed, built, released and maintained.
Explore the scopeService scope
Security decisions begin before a penetration test. Work through the architecture, code and release process to identify the controls developers need and the checks that make sense for each application.
Identify assets, trust boundaries and abuse scenarios early enough to influence the design.
Review sensitive code paths and interface contracts, with attention to identity, data handling and business logic.
Define automated checks and review gates that support development without obscuring responsibility.
Examine dependencies, secrets, build permissions and artefact handling across the delivery process.
When this is useful
Deliverables to define in your scope
Application-specific security requirements
Findings and implementation guidance for developers
A practical plan for security checks in delivery
Connected expertise
Connect this engagement to the other parts of your security programme when the scope calls for it.
Scope the work around your business.