Cyber Security Consultancy

Security that
thinks ahead

SecIQ tests what you have built, tells you plainly what we found, and helps you fix it — before somebody less friendly finds it first.

Independent & vendor-neutral EMEA & United States Registered in England

Who we are

An independent security consultancy

SecIQ is an independent cyber security consultancy based in High Wycombe, England, serving organisations across EMEA and the United States. We provide penetration testing, security audits, incident response, compliance consulting, security awareness training and managed security services.

Named platforms, named benchmarks

We test the platforms you actually run — VMware vSphere 8, NetApp ONTAP, ServiceNow, Microsoft 365, Azure and AKS, Windows and macOS builds — and measure each against the benchmark that applies to it: DISA STIG, CIS, CISA SCuBA, OWASP. You know what was tested and what it was tested against.

Attack chains, not just a list

Individual findings are rated with CVSS v4.0. Attack chains from a realistic starting position to a business outcome are rated on cumulative impact, and a report can carry a Critical-rated chain with no single Critical finding in it. Remediation is sequenced to break the chain, not to empty severity buckets.

Validated, non-destructive, retested

Every finding is proved or disproved before it is reported, with evidence, reproduction steps and timestamps. Impact is demonstrated without destructive exploitation. Anything actively exploitable is issued as an interim notice during testing, and the retest is written into the engagement rather than sold afterwards.

Platform experience

The platforms we have tested

SecIQ has assessed Microsoft Azure and Entra ID, VMware vSphere 8, NetApp ONTAP, ServiceNow, Microsoft 365, Kubernetes, IPC Unigy and Windows and macOS corporate builds, each against the benchmark that applies to it. We name platforms rather than categories because testing a hypervisor control plane is not the same skill as testing a REST API.

Microsoft Azure VMware vSphere 8 NetApp ONTAP ServiceNow Microsoft 365 Kubernetes Entra ID Windows & macOS builds

Our approach

How an engagement runs

The same four phases whether the work is a two-week application test or a year-long certification programme. No surprises in the middle, and no change to the price without a change to the scope agreed in writing.

PHASE 01

Understand

What the system does, who it matters to, and what would actually hurt if it failed. Scope follows risk — not the other way round.

PHASE 02

Test

Hands-on assessment against a recognised methodology, with tooling used to cover ground and human judgement used to find what tooling misses.

PHASE 03

Report

Findings ranked by business impact, each with evidence, reproduction steps and a remediation route. Delivered in a walkthrough, not just a PDF.

PHASE 04

Verify

Once you have fixed things, we re-run the original attack and confirm it no longer works. A finding is not closed until it is proven closed.

Common questions

Before you get in touch

What does SecIQ do?

SecIQ is an independent cyber security consultancy. We provide penetration testing, security audits, incident response, compliance consulting, security awareness training and managed security services to organisations across EMEA and the United States. We are vendor-neutral: we do not resell security products, so our recommendations are not shaped by what we would earn from them.

How big does an organisation need to be to work with SecIQ?

There is no minimum. The scope of work changes with size, not the standard of it. A ten-person software company shipping one application and a multinational with a large estate need different engagements, but both get the same methodology, the same evidence standard and the same directness in the report.

How long does a security engagement take?

It depends entirely on scope. A focused application penetration test is commonly measured in days to a couple of weeks including reporting. A full security audit typically runs over several weeks. An ISO 27001 certification programme is usually measured in months, because the standard requires the management system to have been operating for a period before an auditor can certify it. We give a firm estimate after scoping, before any work is agreed.

Do you work with clients outside the UK?

Yes. SecIQ is registered in England and serves clients across EMEA — Europe, the Middle East and Africa — and the United States. Most assessment work is delivered remotely; where an engagement genuinely requires being on site, such as physical or internal network testing, that is agreed during scoping.

What happens to our data during an engagement?

Engagements begin with a written agreement covering confidentiality, data handling and rules of engagement. Findings, evidence and any data encountered during testing are handled under that agreement, retained only as long as needed to deliver and verify the work, and destroyed on the agreed schedule. We will tell you before an engagement exactly what we expect to access and why.

We think we are being attacked right now. What should we do?

Do not wipe or rebuild the affected systems yet — that destroys the evidence needed to work out how far the attacker got. Isolate affected hosts from the network rather than powering them off, preserve logs, and contact us at info@seciq.co.uk with a description of what you are seeing. Our incident response playbook sets out the first-hour actions in detail.

Next step

Talk to a security consultant

Tell us what you are building, defending or certifying. We will tell you plainly what we would test first, what it takes, and whether you need us at all.