Depth you can audit. Not just claim.
Every engagement follows OWASP WSTG, PTES, and NIST SP 800-115, executed by testers holding OSCP, CREST, and OSCE credentials. Here is how we work, phase by phase.
The frameworks we execute against.
Not a marketing checkbox. Every applicable check from every listed standard is performed and traceable in the report.
OWASP WSTG
Web Security Testing Guide is the backbone of every web-app engagement — every applicable check is executed and documented.
OWASP MASVS
Mobile Application Security Verification Standard drives our iOS and Android practice, covering all L1 and L2 controls.
PTES
Penetration Testing Execution Standard structures the engagement phases from pre-engagement through post-exploitation.
NIST SP 800-115
NIST guide to technical assessment shapes our reporting format and evidence documentation practice.
MITRE ATT&CK
Every red team technique is mapped to an ATT&CK tactic and technique ID so your blue team can align detections.
CIS Benchmarks
Cloud configuration reviews are baselined against the relevant CIS Benchmark for AWS, Azure, and GCP.
Eight phases, every engagement, every time.
Same rigour whether you are testing one web app or twenty.
Pre-engagement
Mutual NDA, scope confirmation, credential exchange via secrets manager, engagement letter, shared Slack channel.
Reconnaissance
Passive OSINT plus active enumeration to map every endpoint, role, integration, and reachable service before touching an exploit.
Threat modelling
Assets ranked by business impact. Attack paths hypothesised against your architecture before testing prioritises them.
Vulnerability identification
Manual review supported by targeted automation. Every finding gets validated by a second engineer before it lands in the report.
Exploitation
Confirmed exploitability, end-to-end. Business logic chains and multi-step abuse cases where they apply — not just proof-of-concept payloads.
Post-exploitation
Where scoped and consented: lateral movement, privilege escalation, and data-access proofs demonstrate real impact.
Reporting
Executive summary, full technical report with CVSS, evidence artifacts, remediation guidance, and framework-specific packs.
Retest
Once fixes ship, testers verify each finding and reissue the report with an updated status log. Included within 90 days.
Depth you can audit, not just claim.
Every engagement follows OWASP WSTG, PTES and NIST SP 800-115, executed by testers who hold OSCP, CREST CRT or OSCE.
Scope confirmed, credentials exchanged, NDA in place.
Manual testing. Confirmed findings published as they land.
Evidence-ready report with remediation per finding.
We verify your fixes and reissue the report.

An authenticated user can access invoice records belonging to other tenants by substituting their own resource identifier in the URL path. The ownership check is absent server-side — the API returns data for any valid integer ID regardless of the caller's tenant.
- 1. Authenticate as Tenant A. Retrieve any invoice: GET /api/v2/invoices/1842
- 2. Replace the ID with a known Tenant B value: GET /api/v2/invoices/1843
- 3. Server returns 200 OK with Tenant B billing data.
Complete tenant isolation bypass. Any authenticated user can enumerate and exfiltrate invoice data, payment terms, and line items for every customer in the system.
Who actually shows up on your engagement.
Certifications are the floor, not the ceiling. Every SecureBlock tester holds these credentials at minimum.
Hands-on offensive certification requiring a 24-hour practical exam. Baseline for every SecureBlock tester.
Independent industry credential recognised by regulators in the UK, EU, and Australia.
Advanced exploitation credential held by senior testers who lead complex engagements and red team exercises.
Web-focused advanced credential held by the leads on our web/API practice.
Read the methodology in a real engagement.
Every SecureBlock report opens with a methodology section referencing the specific standards used on that engagement.
