Work with me
Offensive security, and nothing else. I take a small number of engagements at a time.
Security work
Continuous security
Recurring hands-on cycles, monthly or quarterly, feeding a living picture of your attack surface: what has been looked at, what held up, what changed, where the open issues are. A report is extractable whenever you need one.
Continuous is a cadence. Availability is written into the agreement.
A scoped penetration test
Fixed scope, fixed window. Web and API, mobile, cloud, external perimeter, OT. Findings as I find them, a report you can hand to a customer or an auditor, and a retest once the fixes land.
Red teaming
Objective-based adversary simulation. Initial access, persistence, lateral movement, and whether the thing that actually matters is reachable. Your detection and response get measured on the way.
Assumed breach and purple team as well, starting from a foothold and working next to your defenders. For a team that has never been tested, that is usually the better first exercise.
Secure code review
Reading the source instead of probing the surface. Smart contracts included, and firmware and binaries when the interesting part sits below the source. Findings come tied to the line and to the design decision behind them.
Secure development
Short builds, where I threat-model my own output.
What you can expect
- A working proof of concept with every finding, or it is labelled a hypothesis and priced as one.
- Root cause. Where the flaw came from in the design, so the fix holds.
- Severity you can argue with. The reasoning sits next to the rating.
- Findings reach you as I find them. Anything critical the same day.
- A retest closes the loop. A finding is done when it is fixed and I have confirmed it.
- You talk to the person who did the work. Every time.
- Scanner output does not count as a finding.
- I'll tell you what I didn't get to. Coverage gaps and dead ends are in the report.
How I work
I use automation to cover ground, AI tooling included. It runs under my hand, never on its own, and nothing reaches you that I have not read and understood. Human led, AI assisted.
How scoping works
- A call. You describe the system and what worries you. No charge, no obligation.
- A written scope and rules of engagement: what's in, what's out, what I'm allowed to do, who to call if something breaks. Nobody starts testing before both of us have signed it.
- The work, with findings flowing to you as they appear.
- A retest, and a decision about whether an ongoing cadence makes sense.
Rates depend on the surface and the depth. Ask on the first call.
Who this is for
- Teams who treat security as a continuous discipline rather than an annual event.
- People who will act on what comes back.
- Systems with something interesting about them: serious web and cloud estates, OT, firmware, smart contracts.
- Anyone who'd rather be told the uncomfortable thing early.
Who this isn't for
If what you need is a PDF that satisfies an auditor and nothing more, we're a bad match, and I'd rather say so on the first call.
I also turn down work where the scope makes a real result impossible: too little time to understand the system, or rules of engagement so narrow that the honest answer would be "I found nothing, because I wasn't allowed to look."
Getting started
Mail helloREMOVE@handsonzero.com with a couple of sentences about the system and what's on your mind. You'll get a reply within two working days, from me.