AssuranceLaneConsulting

Home / Services

Find what is exploitable. Prove the fix held.

Five practices, one throughline. Every engagement ends in a report you can hand to a customer, a regulator, or an assessor without translating it first.

Cloud security assessment

Hands-on review of Azure and AWS environments against the running configuration, not a questionnaire: identity and privilege paths, network boundaries, secrets handling, tenant and workload isolation, logging and detection coverage, and the infrastructure-as-code that produces all of it.

Findings are ordered by what an attacker would reach first, with the specific resource and the specific change named.

AzureAWSIdentity and privilegeIaC reviewDetection coverage

For platform and security teams ahead of a customer security review, an audit, or funding diligence.

AI security

Security testing for AI-enabled applications: prompt injection and instruction-boundary failures, tool and agent permissions, retrieval pipelines that leak across tenants, output handling that reaches a shell or a database, model and dependency supply chain, and the cost and abuse surface of an exposed inference endpoint.

Testing maps to the OWASP Top 10 for LLM Applications; governance work maps to the NIST AI Risk Management Framework and ISO/IEC 42001, so the result is usable in a security review and a compliance one.

LLM applicationsRAG pipelinesAgent permissionsOWASP LLM Top 10NIST AI RMFISO/IEC 42001

For teams shipping LLM features, retrieval over customer data, or agents with real write access.

Penetration testing

Application, network, and cloud-native penetration testing, manual-first and scoped to your architecture rather than a scanner's default profile. Engagements are executed against recognised methodology and written to OWASP and NIST SP 800-53 expectations, including testing scoped to support FedRAMP and other formal assessment programs.

Every finding is reproducible, with evidence, severity, and remediation. Fixed items are retested and the report updated to reflect it.

Web and APIInternal and external networkCloud-nativeSocial engineeringRetest included

For software and cloud providers with an annual testing requirement, or a customer demanding one.

Audit readiness

A dry run of the audit before the auditor arrives. We walk your controls the way a reviewer will: pull the population, select the sample, request the evidence, and tell you which items would have drawn an exception and why.

You get a control-by-control readiness position, the evidence gaps named specifically, and a remediation order that puts the items with the longest lead time first. Written by someone who has issued the reports, so the evidence expectations are the real ones rather than a vendor checklist.

SOC 1 and SOC 2ISO/IEC 27001HITRUST CSFNIST CSFNIST SP 800-53Evidence and sampling review

For teams with an audit already scheduled, or a first SOC 2 or ISO certification ahead of them.

Virtual CISO

Standing security leadership without a full-time hire: risk assessment, policy and control ownership, vendor and third-party review, security questionnaire response, and roadmap sequencing against the frameworks you are held to.

We also sit in front of auditors and customers on your behalf, which is usually the part teams most want to hand over.

Risk assessmentPolicy and controlsVendor reviewQuestionnaire responseCustomer and auditor liaison

For teams carrying a security program without a security leader, or through a compliance push.

How an engagement runs

The same four stages whichever service you start with.

  1. Scope

    Objectives, boundaries, constraints, and what a good outcome looks like — agreed in writing before work starts, so there is no argument about scope later.

  2. Assess

    The work itself, against your real environment and your real people. Regular contact throughout; anything urgent reaches you the day we confirm it, not in the final document.

  3. Report

    An executive summary a board can read and detail an engineer can act on, in one document, ordered by what to fix first. A read-out call walks your team through it.

  4. Verify

    We re-check what you changed and reissue the deliverable with the outcome, so what you hand to a customer, an auditor, or a board reflects where you actually stand.

Tell us what you need to prove, and to whom.

hello@assurancelaneconsulting.com

Send a short description of the system, the framework, and your timeline — that is enough for us to come back with scope and a realistic sequence.