Consulting

Security consulting is the only service PenCrimson delivers directly. The desk establishes what the problem is, states it in writing, and routes it to whichever company is built for it. Where none of them fits, we run the engagement ourselves.

How an engagement starts

Most consulting starts with a statement of work written by the client before anyone has looked. Ours starts with a look. The scope comes after the diagnosis, which is the only order that produces a scope worth paying for.

You

Tell us what's keeping you up

An incident you can't explain, an audit you can't pass, a datacenter nobody is watching, a board asking questions you can't answer yet. Plain language. No RFP required.

Us

Diagnose it, in writing

A short scoping conversation, then a written read on what the problem is, what it isn't, and what it would take to fix. If the answer is a product, ours or someone else's, we say so.

Then

Route it or run it

Datacenter visibility becomes a TensorOne deployment. Offensive work goes to Cerebro. Everything else is scoped as an engagement with a fixed deliverable, or we tell you that you don't need one.

No retainers to start. The first conversation is a diagnosis. Start the conversation →

What the desk takes on

Everything below is delivered by people who spent their careers on the offensive side of national-security networks. That background is the product: it changes what gets found, what gets ranked first, and what gets dismissed as noise.

Architecture & exposureWhere the estate is exposed, ranked by how an operator would use it. Identity paths, control planes, trust boundaries, and the systems nobody owns.
Detection & visibilityWhat you can see, what you cannot, and the cheapest order to close the gaps. Sometimes a product. Sometimes a config change and a conversation with your SIEM vendor.
Incident readinessPlaybooks, evidence handling, escalation paths, and the decisions you will have to make at 3 a.m., rehearsed in advance.
Threat modelingApplied to new systems during design. How an adversary would approach the architecture, and what to change while changing it is still cheap.
Vendor scrutinyWhat a security product does against what its deck claims, tested the way an attacker would test it. This includes our own products.
Board advisoryRisk, spend and vendor decisions for leaders who need an answer rather than a 90-page assessment. Standing or one-time.

Handoff to a portfolio company

A holding company with its own products has an obvious conflict of interest. We manage it by saying, early and in writing, when the honest answer is one of our companies, and when it isn't.

Hypervisors and control planes nobody is watchingOr a SIEM bill that has become its own line item→ TensorOne
Penetration testing, adversary emulation, intel sharingOffensive work and the hunts that come out of it→ Cerebro
Workforce fundamentals and early-career trainingLinux, Windows, networking, security essentials→ Crimson Academy
Everything elseScoped engagement with a fixed deliverable, or a recommendation to go elsewhere→ Consulting

Get in touch

One conversation. You'll leave it knowing what the problem is, what it would take, and whether we're the right people to do it.