Assume it will be attacked
Threat modeling, dependency and access review, and incident response you have actually rehearsed. No certifications we don't hold, and no promises about outcomes nobody can guarantee.
What we actually do
Six areas. None of them make you unbreachable, and anyone promising that is selling
Security Audits & Testing
Assessment and penetration testing against your real systems, with findings ranked by what an attacker reaches first rather than by scanner severity.
- Vulnerability scanning
- Penetration testing
- Security compliance
Threat Detection & Response
Logging and alerting that a person actually reviews, plus a written incident plan. Coverage hours are stated explicitly — we do not imply round-the-clock cover we are not staffed for.
- SOC monitoring
- SIEM implementation
- Threat intelligence
Identity & Access Management
Authentication, authorization, and the joiner-mover-leaver process. Most breaches worth reading about are an access problem long before they are a clever exploit.
- Multi-factor authentication
- Single sign-on (SSO)
- Privileged access management
Data Protection
Classification, encryption in transit and at rest, and retention and deletion that actually happen on schedule.
- End-to-end encryption
- DLP solutions
- Backup & recovery
Network Security
Segmentation, ingress and egress control, and establishing which of your services are reachable from the internet — routinely more than expected.
- Firewall management
- Intrusion detection
- VPN configuration
Endpoint Security
Device hardening, patch cadence, and knowing which machines exist at all. Asset inventory is unglamorous and is usually the thing that is missing.
- Anti-malware protection
- Device management
- Patch management
How an engagement runs
Four stages — and you get the findings whether or not you engage us for the remediation
Assess
Audit and assessment against what you actually run, not against a questionnaire.
Design
A security design proportionate to your risk and budget, with the trade-offs written down.
Implement
Rolled out in an order that does not take the business offline in order to secure it.
Monitor
Ongoing review with agreed coverage hours and an escalation path someone has rehearsed.
Frameworks we build against
These are the regimes we design and document toward. OFO is not itself an audited certificate holder for any of them, and no vendor's badge is a substitute for your own audit.
GDPR
HIPAA
SOC 2
ISO 27001
PCI DSS
NIST Framework
Find out what is actually exposed
Start with an assessment of what you run and what is reachable from outside. You keep the findings either way.
Request Assessment