LSCP Challenging Cyber Resilience

Services

One accountable expert, a written process, insurance behind the signature, and a public record behind the work.

Typical workflows

Generally, we have three choices – and they come down to who does the pulling.

Reactive support

A question about a vendor at 9 a.m., a strange feeling about an employee at 9 p.m. – you ask, I answer, all year. That's Advisory: one annual budget, paid monthly, covering everything a security person should cover. How the year works →

Proactive research

I test your named assets on my own initiative, whenever I have time, and bring findings whole – you decide about payment each time. That's the Private Bug Bounty. The model →

Standard process

A bounded project with a scope and a report, re-tests agreed separately: penetration testing first among them, and a whole shelf of others below. The pentest page →

Pick the shape, and the rest is details. Not sure which fits? That's a fine question to discuss.

A standard process that isn't a pentest?

Here's the shelf. The left column is what a client asks for; the right column is a real engagement already delivered in that area. The list keeps growing – and it can grow with the service you need.

Ask forAlready delivered
Web application pentestA decade of full-cycle testing, from scoping to exploitation and remediation validation; OSWE-backed white-box depth.
Mobile application pentest (iOS / Android)App and binary testing including reverse engineering, mapped to OWASP MASTG / MASVS; GMOB.
API pentestOWASP API Top 10, a standard part of full-cycle engagements.
Network, Active Directory & infrastructureLarge enterprise networks with BloodHound attack-path mapping and AV/IDS/IPS evasion; an engagement inside one of Europe's largest telecom providers.
Cloud pentest (AWS / Azure / GCP)All three major platforms, in client engagements.
Secure source-code reviewJava, Python, Go, Node.js, PHP, .NET, Erlang; two half-year review engagements on a national healthcare system, plus many smaller ones.
Enterprise PKI & cryptography assessmentA production post-quantum rollout delivered – ML-DSA (FIPS 204), design advisory plus post-implementation audit; two penetration-testing engagements for a central-bank-grade financial regulator; a B.S. in Applied Cryptology.
Red team / adversary emulationEmulation mapped to MITRE ATT&CK; built and ran a Big-4 offensive security practice – 10+ testers, ~200 engagements a year.
AI / ML red teamingApplication-layer testing mapped to MITRE ATLAS – prompt injection, model evasion – on production ML-powered platforms.
Real-time communications (WebRTC / VoIP)Original WebRTC Top-10 research, presented at OWASP Columbus – recorded.
IoT / hardware device testingHands-on device work; technical mentor at an IoT Village CTF.
Configuration reviewCIS Benchmarks up to DoD STIG level, under NIST 800-37.
Phishing & social engineeringCampaigns designed and run inside long-term client engagements.
Incident responseEnd-to-end casework: DarkGate malware, business email compromise, a production platform incident.
Exploit & vulnerability research12+ CVEs, published 0-day write-ups, the "MakeSense" Hack The Box machine, OffSec lab content – the Responsible Disclosure Lab.

Standing commitments

Already have a security vendor? Keep them. A split test settles it better than any pitch: your vendor tests, I test, the two reports land side by side. The rest is your call.

Pricing

An old joke first. A banker tells a hacker: "Break into my bank." Five minutes later the hacker says, "Done." "Well done," says the banker, "go to accounting and tell them: worked five minutes."

It's really hard to predict the hourly rate. The American Fund for Ukrainian Reconstruction receives my help for free. Another commercial business pays me $5,000.00 for the three hours of an urgent investigation when they need me most. Standard penetration testing engagements usually cost between $3,000.00 and $15,000.00 – about $1,000.00 for a well-structured, predictable day. The Private Bug Bounty brings issues in at $1,000.00 to $3,000.00 apiece.

The best price prediction works on the Advisory package, which is optimized for annual budgeting, usually between $36,000.00 and $96,000.00 a year. It creates a firm, reliable structure that stays intact no matter what kind of urgency comes up during the contract.

Book a consultation