Skip to content

Cyber Security

Security inside the pipeline, not after it

Everything that makes software safe to ship: the pipeline gates, the dependency supply chain, the APIs that now carry most traffic, and the developer enablement that makes the whole thing sustainable.

What we deliver

Services in this focus area

Every engagement is scoped to your environment - deploy a single capability or the full stack.

  1. 01

    Secure SDLC & DevSecOps Pipeline Engineering

    On-PremCloudHybridAdviseBuild

    Security gates inside the pipeline that developers do not route around, because they are fast and specific.

    • Pipeline assessment with control placement and latency budget
    • Automated gates with proportionate break-build and waiver policy
    • Findings routed to the owning team with in-workflow feedback
  2. 02

    Application Security Programme & Risk Tiering

    On-PremCloudHybridAdviseRun

    A managed function across the whole portfolio rather than a test per release.

    • Application inventory with business-criticality and exposure tiering
    • Testing cadence, standards and evidence requirements per tier
    • Security champions network, metrics and maturity reporting
  3. 03

    Threat Modelling as a Practice

    On-PremCloudHybridAdvise

    Design flaws found while they are still a whiteboard change.

    • Structured modelling per system, feature or trust-boundary change
    • Ranked threat and mitigation register linked to backlog items
    • Reusable templates and team-level enablement to run it without us
  4. 04

    SAST, DAST & IAST Implementation

    On-PremCloudHybridBuild

    Automated testing tuned to a signal level developers will act on rather than mute.

    • Tool selection, integration and baseline suppression strategy
    • Severity, gating and exception policy per application tier
    • Triage workflow into developer backlogs with SLA tracking
  5. 05

    Software Composition Analysis & SBOM

    On-PremCloudHybridBuildRun

    Know what is inside your software before a customer, an auditor or an advisory asks.

    • Dependency, transitive and licence risk analysis
    • SBOM generation, signing and distribution in standard formats
    • Vulnerable-component response process with reachability triage
  6. 06

    API Discovery, Security & Governance

    On-PremCloudHybridBuildRun

    Every API found - including the undocumented and deprecated ones - and policy placed in front of them.

    • Traffic-based and code-based API discovery and inventory
    • Authentication, authorisation, schema and rate-limit standards
    • Runtime protection, abuse detection and drift alerting
  7. 07

    Secrets Management & Credential Hygiene

    On-PremCloudHybridBuild

    Credentials out of repositories, images, pipeline variables and config maps.

    • Secret scanning across history, artefacts and running workloads
    • Vault or platform secret-store integration with dynamic issuance
    • Short-lived credential patterns and automated rotation on exposure
  8. 08

    Application Security Posture Management

    CloudHybridBuildRun

    One prioritised view of application risk across scanners, pipelines, repositories and runtime.

    • Finding consolidation, deduplication and correlation to code owners
    • Risk scoring weighted by exploitability, exposure and business criticality
    • Ownership routing, SLA tracking and executive reporting
  9. 09

    Container, Kubernetes & Supply Chain Security

    On-PremCloudHybridBuildRun

    The platform most new workloads land on, secured from build through admission to runtime.

    • Image scanning, provenance attestation and artefact signing
    • Admission control, RBAC, network policy and workload identity
    • Runtime detection, drift prevention and cluster benchmark hardening
  10. 10

    Secure Coding Enablement

    On-PremCloudHybridAdvise

    Training driven by the vulnerability classes your own code keeps producing.

    • Language- and framework-specific hands-on labs
    • Curriculum shaped by your finding trends and incident history
    • Secure coding standards, review checklists and reusable primitives

Technical deep dive

Closing broken object-level authorisation across an API estate nobody had inventoried

Applies to any platform whose APIs were built for a single first-party consumer and later opened to partners, mobile clients or an ecosystem.

What this is

An API security programme with three layers: discovery from live traffic and from code so the inventory is real, an authorisation model where object ownership is checked centrally rather than in each handler, and pipeline plus runtime controls that stop the class from returning.

The problem being solved

A record endpoint accepts an identifier and returns the full object. Identifiers are sequential. The endpoint verifies that the caller holds a valid partner token - it never verifies that the requested object belongs to that partner. There is no rate limit, because it was written for one first-party client making one call at a time. A partner key issued years earlier, never scoped and never rotated, is used to walk the identifier range from a rotating residential address pool over a weekend. Nothing alerts: every request is authenticated, well-formed and individually unremarkable.

Why it is hard

  • Object-level authorisation cannot be enforced at the gateway alone. The gateway knows the caller; only the service knows what the object is and who owns it.
  • The estate is unknown. Undocumented, deprecated and internal-only endpoints outnumber the documented ones, and you cannot protect what is not in the inventory.
  • The abuse is behaviourally distinct but individually legitimate. Detection has to be sequence-aware - enumeration is a property of the series, not of any single request.

Reference architecture - step through it

all
CLIENTSEDGEAUTHORISATIONSERVICES & ASSURANCEFirst-party clientscoped, short-lived tokenPartner integrationscoped per accountEnumeration clientrotating source addressesCI pipelinebuild-time assuranceAPI gatewayauthN, schema, rate limitAPI discoverytraffic + code derivedRuntime protectionsequence-aware abuse detectionSchema registrycontract is the source oftruthAuthorisation servicecentral policy decisionOwnership resolverobject → owning tenantPolicy bundleversioned, tested, signedPipeline gatescontract, authZ and abusetestsRecord serviceno bespoke authZ logicData storetenant-scoped queries onlyDetection pipelineenumeration and drift alertsPosture managementfindings correlated to ownersauthenticatedundocumented → registrytune
Ownership checked centrally, enumeration scored behaviourallytext
# 1 ─ authorisation policy: object ownership, decided centrally
package api.authz

default allow := false

allow if {
  input.action == "read"
  input.object.type == "consignment"
  input.object.owner_tenant == input.subject.tenant     # the missing check
  input.subject.scopes[_] == "consignment:read"
}

# cross-tenant access requires an explicit, audited delegation
allow if {
  input.action == "read"
  d := data.delegations[input.object.owner_tenant][input.subject.tenant]
  d.active
  time.now_ns() < d.expires_ns
  input.object.type in d.object_types
}

deny_reason := "cross_tenant_object_reference" if {
  input.object.owner_tenant != input.subject.tenant
  not allow
}

# 2 ─ contract: the registry rejects anything undeclared
paths:
  /v2/consignments/{ref}:
    get:
      auth: partner_token
      authorization: object_level          # required field; build fails if absent
      object: {type: consignment, ref_format: opaque_ulid}
      rate_class: partner_read             # 120/min burst 40, per credential
      deprecated_alias: /v1/shipment/{id}  # legacy route, now proxied + logged

# 3 ─ runtime: enumeration is a property of the series
rule ENUM-002:
  window: 10m
  per: credential
  signals:
    distinct_object_refs      > 500
    not_found_ratio           > 0.35        # walking a range produces misses
    monotonic_ref_progression == true
    breadth_vs_baseline       > 20x
  ignore: [source_ip]                        # rotating pools defeat address logic
  action: throttle → challenge → suspend_credential
  notify: partner_account_owner + detection_pipeline

Measured change

MeasureBeforeAfter
Documented API surface84 endpoints312 discovered, 312 registered
Endpoints with object-level authorisationhandler-by-handler, unverified100% via central decision
Time to contain the live abuseN/Asame day, policy-level virtual patch
Enumeration detectionnonesequence-scored, source-independent
New routes shipped without an authZ modelroutine0 - build fails

The fix that mattered was structural: authorisation stopped being something each handler had to remember and became something the platform decides. The inventory made the problem visible; the central decision made it non-recurring.

Talk to an application & product security specialist.

Schedule a free consultation and our team will connect within 12 hours to understand your environment and map out the right approach.

We respond within 12 hours