Grey Fox Security
Offensive testing and defensive hardening. We attack your systems the way a real adversary would, under written authorisation, then show you exactly how to close what we found. Every finding is reproduced, risk-rated and paired with a fix your team can actually apply.
Services
Penetration testing
External, internal, web application, API and cloud testing against an agreed scope.
Vulnerability assessment
Authenticated scanning with manual validation, so the report is findings, not noise.
Hardening & configuration review
Servers, endpoints, Microsoft 365, firewalls and cloud tenants measured against recognised benchmarks.
Cyber Essentials readiness
Gap analysis and remediation support ahead of a Cyber Essentials or Cyber Essentials Plus assessment.
Phishing & social engineering
Controlled campaigns that measure real behaviour and feed straight into training.
Incident response support
Containment, triage and recovery guidance when something has already gone wrong.
Before you ask
Is testing safe for live systems?
Scope, timing and risk limits are agreed in writing first. Destructive and denial-of-service techniques are excluded unless you specifically ask for them in a test environment.
Do you need authorisation?
Always. We only test systems you own or have written permission to test, and we will ask for proof. No signed authorisation, no testing.
Ready when you are
Email us the outcome you need. We will tell you honestly whether we are the right fit.