Services

Security engagements for companies without a security team.

Each engagement is built around one decision a technical leader has to make, delivered in a fixed number of days, and closed with a roadmap that says what to do first and why.

Fixed scope, fixed duration

Scope and timeline are agreed before the engagement starts. Ten to fifteen business days, not an open-ended retainer.

No production access required

All three engagements work from documentation, interviews and externally available information. Nothing is scanned, probed or exploited.

Two reports, two audiences

An executive summary management can decide from, and a technical report engineers can work from — from the same analysis.

A prioritized 90-day roadmap

Every engagement ends with immediate, 30, 60 and 90-day actions, ordered by risk reduction against implementation effort.

Choosing

Which engagement fits your situation?

Most companies start with one engagement and decide about the next one after seeing the findings. These are the usual entry points.

You have a security budget and no priorities

Start with the External Threat & Attack Surface Assessment. It establishes which attacks are realistic against your company before you commit the budget.

External Threat Assessment

You are designing or rebuilding a system

Start with Threat Modeling. Design-time changes are the cheapest security control available, and they stop being available once the system ships.

Threat Modeling

Your controls are in place but your response is not

Start with the Incident Readiness Assessment. It establishes what would actually happen in the first hours of a serious incident, and closes the gaps that would slow it down.

Incident Readiness
Still deciding

Describe the situation and Lion Sec will tell you which engagement fits.

Thirty minutes is usually enough to establish which question is worth answering first — and whether Lion Sec is the right party to answer it.