Skip to content
INLD LimitedCybersecurity Consulting

About

A consultancy built around one deliverable: an assessment somebody else can rely on

INLD Limited provides independent security assessments to organisations that must demonstrate their security posture to a third party as well as manage it internally.

Overview

INLD Limited is a UK-based cybersecurity consultancy providing independent security assessments to regulated businesses, with a focus on financial services, fintech, cryptocurrency and digital asset platforms. We are registered in England and Wales under company number 12040493 and have been incorporated since 10 June 2019.

Our work is narrow by design. We test systems, assess controls against published standards, and produce documentation that a client can put in front of an auditor, a banking partner or a supervisory authority without editing it first. We do not resell security products, operate a managed service, or act as an intermediary in any licensing process — activities that would create commercial pressure on the content of a report.

Mission

We deliver assessments that are technically rigorous, regulatorily meaningful and operationally actionable. Those three properties are usually in tension. A report can be technically impressive and useless to a compliance function; it can satisfy a checklist and miss the exploitable path; it can be accurate and still fail to tell an engineering team what to do on Monday. Holding all three together is the discipline the firm is built around.

Our approach

Every engagement is scoped around the client's specific regulatory environment and business risk profile. A payment processor and a custodial wallet operator both need penetration testing, but the questions that matter differ: for one it is the exemption boundary in an authentication flow, for the other it is whether a single compromised operator can complete a withdrawal approval. We spend time on that difference before testing starts, because a technically correct assessment aimed at the wrong risk is an expensive way to learn nothing.

We work from internationally recognised standards — the OWASP Testing Guide v4.2, PTES, NIST SP 800-115, the OWASP API Security Top 10 — and score findings under CVSS 4.0 with the full vector published. Standards alignment is stated as alignment, never as certification. INLD holds no ISO/IEC 27001 certification, no CREST membership, no PCI QSA status and no other accreditation, and our documentation says so wherever the question could arise.

Team

Our team brings together penetration testers, cloud security engineers and compliance specialists with backgrounds in regulated financial technology, exchange and custody infrastructure, and cloud platform engineering. Engagements are staffed against the technology and regulatory context in scope rather than by whoever is next available, and the client is told at scoping which disciplines will be involved.

We do not publish individual biographies or photographs. Assessment personnel are named to the client under the engagement's confidentiality terms, along with their relevant background, so the people doing the work can be verified where that matters — which is the client's file, not a public web page.

Independence

INLD is not affiliated with any technology vendor, platform provider, exchange, custodian or licensing intermediary. We hold no reseller agreements and take no referral commission. Where we have previously advised on a control, any later assessment covering that control declares the prior involvement so a reader can weigh the conclusion accordingly.

Start with a scoping conversation

Tell us about your environment, regulatory context and timelines. We will tell you what an assessment would realistically involve, before any commitment.