Home / Services
Find what is exploitable. Prove the fix held.
Five practices, one throughline. Every engagement ends in a report you can hand to a customer, a regulator, or an assessor without translating it first.
Cloud security assessment
Hands-on review of Azure and AWS environments against the running configuration, not a questionnaire: identity and privilege paths, network boundaries, secrets handling, tenant and workload isolation, logging and detection coverage, and the infrastructure-as-code that produces all of it.
Findings are ordered by what an attacker would reach first, with the specific resource and the specific change named.
For platform and security teams ahead of a customer security review, an audit, or funding diligence.
AI security
Security testing for AI-enabled applications: prompt injection and instruction-boundary failures, tool and agent permissions, retrieval pipelines that leak across tenants, output handling that reaches a shell or a database, model and dependency supply chain, and the cost and abuse surface of an exposed inference endpoint.
Testing maps to the OWASP Top 10 for LLM Applications; governance work maps to the NIST AI Risk Management Framework and ISO/IEC 42001, so the result is usable in a security review and a compliance one.
For teams shipping LLM features, retrieval over customer data, or agents with real write access.
Penetration testing
Application, network, and cloud-native penetration testing, manual-first and scoped to your architecture rather than a scanner's default profile. Engagements are executed against recognised methodology and written to OWASP and NIST SP 800-53 expectations, including testing scoped to support FedRAMP and other formal assessment programs.
Every finding is reproducible, with evidence, severity, and remediation. Fixed items are retested and the report updated to reflect it.
For software and cloud providers with an annual testing requirement, or a customer demanding one.
Audit readiness
A dry run of the audit before the auditor arrives. We walk your controls the way a reviewer will: pull the population, select the sample, request the evidence, and tell you which items would have drawn an exception and why.
You get a control-by-control readiness position, the evidence gaps named specifically, and a remediation order that puts the items with the longest lead time first. Written by someone who has issued the reports, so the evidence expectations are the real ones rather than a vendor checklist.
For teams with an audit already scheduled, or a first SOC 2 or ISO certification ahead of them.
Virtual CISO
Standing security leadership without a full-time hire: risk assessment, policy and control ownership, vendor and third-party review, security questionnaire response, and roadmap sequencing against the frameworks you are held to.
We also sit in front of auditors and customers on your behalf, which is usually the part teams most want to hand over.
For teams carrying a security program without a security leader, or through a compliance push.
How an engagement runs
The same four stages whichever service you start with.
Scope
Objectives, boundaries, constraints, and what a good outcome looks like — agreed in writing before work starts, so there is no argument about scope later.
Assess
The work itself, against your real environment and your real people. Regular contact throughout; anything urgent reaches you the day we confirm it, not in the final document.
Report
An executive summary a board can read and detail an engineer can act on, in one document, ordered by what to fix first. A read-out call walks your team through it.
Verify
We re-check what you changed and reissue the deliverable with the outcome, so what you hand to a customer, an auditor, or a board reflects where you actually stand.
Tell us what you need to prove, and to whom.
hello@assurancelaneconsulting.comSend a short description of the system, the framework, and your timeline — that is enough for us to come back with scope and a realistic sequence.