04 · Security
Protect it here. Test it at SkullSploit.
Security is layers. Skull Solutions handles the people, the network, the accounts and the design. SkullSploit, our offensive-security arm, attacks what's left to see if it holds.
How it fits
No single layer is the whole answer.
DNS filtering does not stop a stolen password. Training does not fix an API that trusts the client. Each layer covers what the others cannot.
-
People
Staff who recognise phishing and report problems early.
Skull Solutions · cyber-safety training
-
Network & devices
Filtering, segmentation, updates and sensible defaults.
Skull Solutions · IT & networking
-
Accounts & access
Multi-factor authentication, access reviews and account hygiene.
Skull Solutions · security reviews
-
Application design
Architecture review, threat modelling and secure code review.
Skull Solutions · application security
-
Adversarial testing
Someone attacks the application by hand to find what the other layers missed.
SkullSploit · penetration testing
Services
What Skull Solutions does.
-
Employee cyber-safety training
Practical sessions that teach staff to spot phishing, protect accounts and report problems early.
More about Cyber-safety trainingRequest a quotation -
Application security consulting
Architecture review, threat modelling and secure code review: how an application was designed, and what it should defend against.
What's included
- Security architecture review
- Threat modelling
- Secure code review
- Attack surface review
- Fixing security findings in your codebase
Assessment required -
Security reviews & hygiene
Accounts, access, devices and configuration checked against the basics that stop most incidents.
What's included
- Access-control reviews
- Account and password hygiene
- Multi-factor authentication rollout
- Device security configuration
- Infrastructure security guidance
- DNS filtering
Assessment required -
Penetration testing through SkullSploit
Manual testing of web applications and APIs by SkullSploit, our offensive-security arm.
Visit skullsploit.comRequest a quotation
SkullSploit · offensive security
Need someone to break it?
SkullSploit is the offensive-security arm of Skull Solutions, focused on finding vulnerabilities in applications, APIs and systems.
Web application penetration testing
Someone tries to break into your application the way an attacker would, by hand, as each kind of user.
API penetration testing
The API behind your app, tested directly — including the requests your own app never makes.
Authentication & authorisation testing
Whether every account can reach only what it is meant to reach.
Business logic testing
Your own rules on prices, limits, approvals and ownership, bent on purpose.
In development, not for sale yet: Security research · Exploit development · Deeper offensive-security work
SkullSploit doesn't write the fixes for what it finds. Testing and fixing are kept apart on purpose, and the engineering that closes findings happens at Skull Solutions.
Where this is going
Direction, not a price list.
These are areas we are building towards. None of them is sold as a service today, and we will not pretend otherwise until they are.
Contact
Worried about something specific?
You don't need to know which service you need. Describe what's going on, and working out the rest is our job.
-
Start a project
Software to build, a network to set up, a system to fix. Tell us what you're trying to do.
Email us to start a project -
Request a quote
Installations, CCTV, health checkups, filtering. Say what you need and where.
Email us to request a quote -
Ask about a service
Not sure it's something we do? Ask. The answer is quick either way.
Email us to ask about a service
Not sure what to write?