Skip to content
INLD LimitedCybersecurity Consulting

Services

Security services for organisations that carry regulatory weight

Six services, scoped and reported to a single standard: a written boundary, manual verification of every finding, CVSS 4.0 severity, and a retest that confirms closure.

Each engagement below is delivered under the same methodology and produces the same documentation set, so results are comparable between assessments and across years. Where a service touches on advisory work, we keep that work separate from assessment work and declare the overlap in writing. Nothing on this page implies a certification, accreditation or membership that INLD does not hold.

01

Penetration Testing

Typical timeline

3-6 weeks depending on scope, including retest

Full service detail

Penetration testing at INLD is a manual discipline supported by tooling, not the other way round. We begin from an agreed scope and rules of engagement, map the attack surface, and then work through authentication, authorisation, session management, input handling, business logic and data exposure in the order that risk dictates. Automated scanners are used with tuned rulesets to clear ground quickly; every candidate finding is then verified by hand so the report contains no unconfirmed scanner output. Where exploitation is authorised, we produce controlled proof-of-concept evidence to establish real impact rather than theoretical severity. Findings are documented with reproduction steps precise enough for a developer to follow without contacting us.

What is included

  • External and internal network testing within the agreed boundary
  • Web application testing aligned with the OWASP Testing Guide v4.2
  • Authentication, session management and access control testing
  • Business logic and workflow abuse testing
  • Mobile application testing aligned with the OWASP MASTG (iOS and Android)
  • Controlled exploitation and privilege escalation where authorised
  • Manual verification of every automated finding before it reaches the report

Deliverables

02

Cloud Infrastructure Security

Typical timeline

2-4 weeks depending on the number of accounts and workloads

Full service detail

Most cloud incidents we see are not exotic. They come from identity policies that grew permissive over time, storage that became reachable through a chain of defaults, secrets committed to build pipelines, or logging that was never routed anywhere an analyst would look. Our cloud assessment reviews the account or subscription structure, identity and access management, network segmentation, data storage and encryption, secrets handling, and detection coverage. We work from the CIS Benchmarks and the relevant provider well-architected security guidance, then apply the client's own regulatory context to decide what actually matters. The output separates control gaps that create present exposure from those that create audit findings, because the two need different response timelines.

What is included

  • Account, subscription and project structure review
  • IAM policy analysis: over-permissive roles, unused credentials, privilege paths
  • Network boundary review: security groups, network ACLs, private connectivity
  • Storage and database exposure review, including encryption at rest and in transit
  • Secrets management and CI/CD pipeline credential handling
  • Logging, monitoring and detection coverage assessment
  • Benchmark comparison against CIS and provider security guidance

Deliverables

03

Cryptocurrency and Digital Asset Security

Typical timeline

4-8 weeks depending on platform complexity and chain coverage

Full service detail

Digital asset platforms fail at the seams: between the trading engine and the withdrawal path, between the signing service and the approval workflow, between what the key ceremony documented and what operations actually does on a Friday evening. Our assessments treat key material and withdrawal authorisation as the crown jewels and work outwards. We review hot, warm and cold wallet architecture, HSM and MPC configuration where present, deposit crediting and confirmation logic, withdrawal approval workflows and their limits, address allowlisting, and the internal transfer paths that often sit outside the main control set. Blockchain-specific issues such as chain reorganisation handling, replay exposure and token contract behaviour are assessed against the specific chains in scope.

What is included

  • Hot, warm and cold wallet architecture review
  • Key generation, storage, backup and recovery assessment (HSM and MPC configurations)
  • Withdrawal authorisation workflow, approval thresholds and limit enforcement
  • Deposit crediting, confirmation depth and reorganisation handling
  • Exchange platform application and API testing
  • Internal transfer and treasury operation controls
  • Token contract and integration review for supported assets

Deliverables

04

API Security Assessment

Typical timeline

2-4 weeks depending on endpoint count and integration scope

Full service detail

APIs concentrate risk because they expose business logic directly, often to partners whose own security posture is unknown. Object-level and function-level authorisation flaws dominate what we find: an endpoint that checks whether you are authenticated but not whether the record belongs to you. We test against the OWASP API Security Top 10, working through broken object level authorisation, broken authentication, property-level exposure, resource consumption limits, function-level authorisation, sensitive business flow abuse, server-side request forgery, and inventory management. GraphQL scope adds introspection exposure, query depth and complexity limits, and batching abuse. Partner and machine-to-machine integrations are assessed for credential handling, token scope and replay resistance.

What is included

  • REST and GraphQL endpoint enumeration and inventory verification
  • Broken object level and function level authorisation testing
  • Authentication, token issuance, scope and lifetime review
  • Excessive data exposure and property-level authorisation testing
  • Rate limiting and resource consumption testing
  • Sensitive business flow abuse testing
  • Partner and machine-to-machine integration credential review

Deliverables

05

Compliance Advisory

Typical timeline

3-6 weeks for a readiness assessment; remediation support is scoped separately

Full service detail

Compliance advisory at INLD is about closing the distance between how an organisation actually operates and what a framework requires it to evidence. We run readiness assessments against ISO/IEC 27001:2022 Annex A controls and the SOC 2 Trust Services Criteria, identify which requirements are met in practice but undocumented, which are documented but not performed, and which are genuinely absent. For regulated firms we map security obligations arising from GDPR, DORA and MiCA onto existing controls so the same evidence serves more than one obligation. We do not issue certifications and we are not a certification body; our role is to prepare an organisation so that an accredited auditor finds what they expect to find.

What is included

  • ISO/IEC 27001:2022 readiness assessment against Annex A controls
  • SOC 2 Trust Services Criteria gap analysis
  • GDPR technical and organisational measures review
  • DORA ICT risk management and incident reporting readiness review
  • MiCA operational resilience requirements mapping for digital asset firms
  • Policy and procedure review against operational reality
  • Evidence-collection guidance ahead of external audit

Deliverables

06

Security Training

Typical timeline

Half-day to three-day formats; scheduled around the client's release calendar

Full service detail

Training only changes behaviour when the examples are recognisable. We build sessions from the findings in your own codebase and infrastructure, anonymised where required, so developers see the actual pattern that produced the vulnerability rather than a textbook illustration. Secure coding workshops cover the vulnerability classes that appear in your stack and language, with hands-on exercises. Vulnerability awareness sessions target product, operations and support staff whose decisions create or close exposure. Incident response tabletop exercises put the response plan under pressure with a scenario drawn from the threat profile of the business — a custody incident for a digital asset firm, a payment fraud chain for a processor.

What is included

  • Secure coding workshops tailored to the client's stack and languages
  • Vulnerability awareness sessions for non-engineering staff
  • Threat modelling facilitation for product and architecture teams
  • Incident response tabletop exercises with scenario design
  • Post-exercise review with prioritised plan improvements
  • Session materials retained by the client for internal reuse

Deliverables

Start with a scoping conversation

Tell us about your environment, regulatory context and timelines. We will tell you what an assessment would realistically involve, before any commitment.