Cyber Security Consultancy
Security that
thinks ahead
SecIQ tests what you have built, tells you plainly what we found, and helps you fix it — before somebody less friendly finds it first.
Who we are
An independent security consultancy
SecIQ is an independent cyber security consultancy based in High Wycombe, England, serving organisations across EMEA and the United States. We provide penetration testing, security audits, incident response, compliance consulting, security awareness training and managed security services.
Named platforms, named benchmarks
We test the platforms you actually run — VMware vSphere 8, NetApp ONTAP, ServiceNow, Microsoft 365, Azure and AKS, Windows and macOS builds — and measure each against the benchmark that applies to it: DISA STIG, CIS, CISA SCuBA, OWASP. You know what was tested and what it was tested against.
Attack chains, not just a list
Individual findings are rated with CVSS v4.0. Attack chains from a realistic starting position to a business outcome are rated on cumulative impact, and a report can carry a Critical-rated chain with no single Critical finding in it. Remediation is sequenced to break the chain, not to empty severity buckets.
Validated, non-destructive, retested
Every finding is proved or disproved before it is reported, with evidence, reproduction steps and timestamps. Impact is demonstrated without destructive exploitation. Anything actively exploitable is issued as an interim notice during testing, and the retest is written into the engagement rather than sold afterwards.
Services
Where we help
Six service lines that cover finding the problems, proving the impact, fixing the cause, and demonstrating control to the people who ask.
Penetration Testing
Web applications, APIs, internal and external infrastructure, cloud environments and mobile. Manual testing with proof of exploitability, not a scanner report with a logo on it.
Explore → 02Security Audits
A structured review of controls, architecture, configuration and policy against a recognised framework, ending in a prioritised roadmap rather than a wall of observations.
Explore → 03Incident Response
Support during a live incident — triage, containment, eradication, recovery — and the preparation beforehand that decides how badly the live incident goes.
Explore → 04Compliance Consulting
ISO 27001, GDPR, PCI DSS, SOC 2 and NIS2 — gap analysis, control design, evidence preparation and support through the audit itself.
Explore → 05Security Awareness Training
Role-based training and phishing simulation designed to change behaviour, aimed separately at general staff, developers and executives — because the risks are not the same.
Explore → 06Managed Security Services
Continuous monitoring, vulnerability management and on-call advisory for organisations that need a security function without building one from scratch.
Explore →Platform experience
The platforms we have tested
SecIQ has assessed Microsoft Azure and Entra ID, VMware vSphere 8, NetApp ONTAP, ServiceNow, Microsoft 365, Kubernetes, IPC Unigy and Windows and macOS corporate builds, each against the benchmark that applies to it. We name platforms rather than categories because testing a hypervisor control plane is not the same skill as testing a REST API.
Our approach
How an engagement runs
The same four phases whether the work is a two-week application test or a year-long certification programme. No surprises in the middle, and no change to the price without a change to the scope agreed in writing.
PHASE 01
Understand
What the system does, who it matters to, and what would actually hurt if it failed. Scope follows risk — not the other way round.
PHASE 02
Test
Hands-on assessment against a recognised methodology, with tooling used to cover ground and human judgement used to find what tooling misses.
PHASE 03
Report
Findings ranked by business impact, each with evidence, reproduction steps and a remediation route. Delivered in a walkthrough, not just a PDF.
PHASE 04
Verify
Once you have fixed things, we re-run the original attack and confirm it no longer works. A finding is not closed until it is proven closed.
Insights
Security guides, written properly
Long-form, vendor-neutral technical writing on the problems we are asked about most. Free to read, no registration wall, and free to cite.
Guide
How to Scope a Penetration Test
Test types, rules of engagement, environments and credentials — and the questions to ask a provider before you sign anything.
Read the guide →Guide
ISO 27001 Readiness
Scope, Statement of Applicability, the four Annex A control themes, and what Stage 1 and Stage 2 auditors actually ask to see.
Read the guide →Guide
API Authentication Methods
OAuth 2.0 flows, client credentials, service accounts, token versions and JWT validation — with the failure modes that cause real breaches.
Read the guide →Common questions
Before you get in touch
What does SecIQ do?
SecIQ is an independent cyber security consultancy. We provide penetration testing, security audits, incident response, compliance consulting, security awareness training and managed security services to organisations across EMEA and the United States. We are vendor-neutral: we do not resell security products, so our recommendations are not shaped by what we would earn from them.
How big does an organisation need to be to work with SecIQ?
There is no minimum. The scope of work changes with size, not the standard of it. A ten-person software company shipping one application and a multinational with a large estate need different engagements, but both get the same methodology, the same evidence standard and the same directness in the report.
How long does a security engagement take?
It depends entirely on scope. A focused application penetration test is commonly measured in days to a couple of weeks including reporting. A full security audit typically runs over several weeks. An ISO 27001 certification programme is usually measured in months, because the standard requires the management system to have been operating for a period before an auditor can certify it. We give a firm estimate after scoping, before any work is agreed.
Do you work with clients outside the UK?
Yes. SecIQ is registered in England and serves clients across EMEA — Europe, the Middle East and Africa — and the United States. Most assessment work is delivered remotely; where an engagement genuinely requires being on site, such as physical or internal network testing, that is agreed during scoping.
What happens to our data during an engagement?
Engagements begin with a written agreement covering confidentiality, data handling and rules of engagement. Findings, evidence and any data encountered during testing are handled under that agreement, retained only as long as needed to deliver and verify the work, and destroyed on the agreed schedule. We will tell you before an engagement exactly what we expect to access and why.
We think we are being attacked right now. What should we do?
Do not wipe or rebuild the affected systems yet — that destroys the evidence needed to work out how far the attacker got. Isolate affected hosts from the network rather than powering them off, preserve logs, and contact us at info@seciq.co.uk with a description of what you are seeing. Our incident response playbook sets out the first-hour actions in detail.
Next step
Talk to a security consultant
Tell us what you are building, defending or certifying. We will tell you plainly what we would test first, what it takes, and whether you need us at all.