CUSTOMER PATHWAY
Application readiness for exposure
We are launching a portal or API.

THE LOGIC
Address the cause.
Then build the capability.
Design then test; remediate before publication against agreed acceptance criteria.
A POSSIBLE SEQUENCE
Select the steps
that fit your situation.
The starting point, sequence and scope depend on existing controls and evidence. Services remain separately scoped.
01 / APP-01
Threat modelling and secure design
Examine an application before or during design to identify sensitive assets, trust boundaries and abuse scenarios. The aim is to select appropriate controls before architectural mistakes become expensive to fix.
02 / APP-05
API architecture and security implementation
Design or fix API controls so each client accesses only authorised data and actions. The project covers identity, business authorisation, validation, quotas and traceability.
03 / APP-03
CI/CD security and DevSecOps integration
Integrate security controls into development and deployment with understandable blocking and exception rules. The project also protects the software delivery chain itself: accounts, runners, secrets and permissions.
04 / PEN-03
Web application penetration testing
Testing browser-based applications for weaknesses, particularly in authentication, authorisation and business workflows.
05 / PEN-04
API penetration testing
Testing the interfaces applications use to exchange data, with particular attention to object-level permissions and abusive usage.
06 / NET-06
Published application protection — WAF and API gateway
Add controls in front of exposed applications and APIs: request filtering, access restrictions and usage limits. This complements secure code without automatically fixing business-logic flaws.
START A CONVERSATION
Let’s scope your route.
Bring the business objective, your current environment and the constraints. We will help define the next useful step.
