Security and compliance engineering, not a report you have to implement
Cybersecurity and compliance services are two purchases, not one: a programme that keeps a changing product compliant and able to prove it, and a point-in-time test that shows what an attacker could actually reach.
01Work
Four reasons this lands on someone's desk
Four starting points, and the first two arrive with somebody else's date attached. Which one you are in decides what to buy first, and how much of it.
A buyer sent a security questionnaire
A document from somebody else's security team, with somebody else's date on it. What it costs depends on how much of it is writing rather than building, and that is settled by reading the questionnaire, not by scoping a programme around it.
A framework became a condition of sale
ISO 27001, GDPR, HIPAA or PCI DSS, because a customer or a market now requires it. The requirement names the framework, so the open decision is not which one but how much of it is already true. HIPAA in healthcare, PCI DSS in e-commerce.
Something happened, or nearly did
An incident, a near miss, or a dependency alert nobody could assess. The useful output is not reassurance; it is knowing which of your assumptions was wrong and what else rests on it. If you want to start before you call anyone, we published a web application security checklist.
AI features widened the attack surface
Prompt injection, data leakage through model context, and access control over what a model may call. We ship AI products of our own, and we wrote the guide to securing MCP servers.
02Services
Two services here, and a third that lives next door
Two service pages under this heading, plus one row that belongs to the quality hub next door. The practice behind both of ours is one dedicated security engineer and a part-time senior security consultant, working in the teams that ship the code. A 24/7 monitoring desk, red teaming or a retained incident-response team is a dedicated security firm's product rather than ours.
| Service | What you are actually buying |
|---|---|
| Cybersecurity and compliance consulting | A framework, or a questionnaireISO 27001, GDPR, HIPAA and PCI DSS: what to secure first, the controls themselves, and the evidence trail that proves it to an auditor or an enterprise buyer. Written for a product that keeps changing after the assessment, and the remediation can be merged by the same people who found it rather than handed to your team as homework.Cybersecurity and compliance consultingOr book a meeting |
| Penetration testing | Evidence is the deliverableAn authorized attack on systems you name, including the AI surface, rather than a checklist held up against them. It ends in a ranked list of what to fix first, and whether we merge those fixes is a separate decision you take after the read-out.Penetration testingOr book a meeting |
| Security testing inside QA | It is continuousSecurity checks in the sprint rather than once a year, which is a third purchase and not a smaller version of either one above. It sits with the quality practice rather than here, where ISTQB-certified QA sits inside every sprint, on every engagement.Software testing and QAOr book a meeting |
03Fit
What a penetration test will not do for you
A penetration test tells you what an attacker could reach on the day it runs. It does not write the policy behind a control, and it closes nothing by itself. This category sells fear efficiently, so the useful question is not what you could buy but what you can safely not buy yet.
| Your situation | What we recommend instead |
|---|---|
| No patching discipline, and a pen test has been booked | Wrong orderYou will pay for a report listing what you already suspect. Get dependency updates and access review running first; the test is worth far more once it can find things you would not have found yourself. |
| A questionnaire whose answers are true but undocumented | Write, do not buildThe work here is writing, not building. A compliance-automation platform will collect and organise the evidence and stop there: it does not write a missing policy or fix the application behind it. Do the documentation first, and you find out how much engineering is genuinely left. |
| A certification wanted because it seems prudent | Wait for a reasonCertification is a real cost with an annual tail. Pursue it when a customer, a market or a regulator requires it, and let that requirement pick which one. Doing the underlying practices is valuable on its own and much cheaper. |
| An annual test, and a product that ships weekly | Continuous, not annualA yearly snapshot of a product that has shipped every week since is mostly historical. Security checks belong in the sprint, with the deeper test as a periodic addition rather than the whole programme. |
| A deal blocked on a customer's security review | Start hereThe clearest yes in this table, and the most time-bound. Consulting to triage the questionnaire into answerable, documentable and buildable, then engineering for the last group. |
| AI features live, and the new surface untested | Test itThese are exposures your existing testing was not designed to find, on a surface that did not exist the last time anyone looked. Test them as the attack surface they are rather than assuming the model is a black box nobody can reach through. |
What we hold, and what that covers
unicrew holds ISO 27001:2022 for information security and ISO 9001:2015 for quality management, both renewed through a multi-stage audit with Quay Audit UK, and we work to GDPR and NIS2. Helping a client reach a framework such as HIPAA or PCI DSS is a service we provide and is a different statement from holding that framework ourselves; we keep the two separate in writing, and we would expect you to ask any vendor to do the same. Three ways to be billed, as everywhere else at unicrew: time and materials, fixed price, or team extension per person per month. There is no minimum engagement period. Most engagements start within two to four weeks.
04Order
The order to work in when a deal is waiting
Four steps, sequenced by what a waiting customer actually needs rather than by what is most thorough. Each one names what it needs from you.
- Triage the questionnaire into three pilesTrue and evidenced, true but undocumented, and not yet true. Only the third needs engineering, and the sorting is what tells you whether the deadline you were given is real. From you: the questionnaire itself and the date on it.You getA triaged questionnaire
- Close the documentation gapPolicies, access records, and the evidence that a control operates rather than merely exists. Where one questionnaire is the whole problem, this is the whole engagement, and a fixed-scope readiness sprint is the smallest way to buy it. From you: the people who know how things actually work today.You getAn evidence pack
- Fix the real gaps, in risk orderThe engineering work, sequenced by exposure rather than by how it reads in a report. Which items your own engineers keep is your call, and it is a decision you make here rather than at the start. From you: access to the repository, and somebody who can approve a merge.You getRemediation, highest risk first
- Make it hold without youDependency updates, access review and security checks in the sprint. Without this the same assessment produces the same findings next year, which is how security work becomes an annual expense rather than an improvement. From you: a named owner with time in their week.You getControls in the delivery process
When a deal is blocked on a security review, the instinct is to buy the biggest thing available, usually a penetration test. Sort the questionnaire into three piles first: what is true and you can prove, what is true and you cannot, and what is not true yet. In most companies I have looked at, the middle pile is the largest and the last one is small. That is a fortnight of writing, not a security programme.
Vuhar MamedovManaging Partner, Europe, unicrew05Proof
Three builds where security shaped the architecture
HealthcareCancerDocs: HIPAA compliant Healthcare Software DevelopmentDevelopment in accordance with HIPAA Security Rules within a medical project.
SecurityMulti-factor authentication platform: Data architecture refactoringSolus Connect is an innovative multi-factor authentication platform that uses 3D facial authentication and machine learning to track down fraudulent behavior.
Knowledge ManagementSaaS for Digital ResearchesA SaaS solution that helps knowledge workers streamline research work involving a substantial amount of information.
06Questions
What teams ask when a review is blocking a deal
Yes. unicrew holds ISO 27001:2022 for information security and ISO 9001:2015 for quality management, both renewed through a multi-stage audit with Quay Audit UK, and we work to GDPR and NIS2. A security review that asks us for the certificates gets current ones. Our QA engineers are ISTQB certified.
Yes. Cybersecurity consulting covers ISO 27001, GDPR, HIPAA and PCI DSS: the assessment, the controls, and the evidence an auditor or an enterprise buyer will ask to see. The difference from a pure advisory is that we are engineers, so the remediation can be merged rather than handed to you as a list. For an offensive test, that is penetration testing.
No, and it is worth stating plainly rather than leaving you to infer it from a list. We hold ISO 27001:2022 for information security and ISO 9001:2015 for quality management, both current and both audited by Quay Audit UK. They certify a management system rather than being an attestation report, so they answer a different question from SOC 2 rather than standing in for it. Reaching SOC 2 readiness is separate work and a separate claim.
Yes. AI features add prompt injection, data leakage through model context and access control over what a model may call, and a test suite written before the feature will not find any of it. We ship AI products of our own. Penetration testing is where that surface gets attacked; cybersecurity consulting is where the access and data-flow design gets decided.
We scope before we quote, because the size of this work is set by how much of the gap is documentation rather than engineering, and that is unknown until the questionnaire is triaged. The shape we can give you now: time and materials, fixed price, or team extension per person per month. There is no minimum engagement period, and most engagements start within two to four weeks. Nothing here requires a change of stack or tooling; we work inside the setup you already run.
What teams usually pair this with
All servicesSend the questionnaire, or the deadline
Either is enough to start. You get a triage of what is genuinely required, what is documentation and what has to be built, before anybody quotes you for the third.