One authorised day looking at what your organisation has exposed to the internet, two or three short conversations with the people who run it, and a five page report in your hands within a week. It answers one question: what are you exposed to, and which of it actually matters?
Founding rate · first five clients
The fee counts in full towards whatever comes next.
Reserve a founding-rate slot →We scan only what you authorise in writing. Nothing is touched before that letter is signed, and nothing outside the list on it is touched at all. That is the difference between an authorised assessment and an offence, and we hold ourselves to it.
A Recce is external and unauthenticated. No credentials, no internal access, no agent on any host. It describes the day we looked, not a certification and not a penetration test, and we hold no CHECK or CREST accreditation and claim none. An internal assessment would see different things, and probably more.
We do not promise a number of findings before we start. On a clean estate the report says so plainly, and that is a real answer worth having.
If your contracts sit at Cyber Risk Profile Level 0, the honest next step is a certification body, not us, and we will say so in the report and point you at one.
The question turns up from a different direction depending on who is asking it.
Defence supply chain. DEFCON 658 contracts sit under Cyber Security Model v4, and Def Stan 05-138 Issue 4 asks for monthly vulnerability scanning and a documented risk treatment plan at Cyber Risk Profile Level 1 and above.
Def Stan 05-138 Issue 4, Table 1.
Cyber Essentials Plus. Recertification requires internet-facing vulnerabilities scoring 7 or above to be fixed within 14 days, which is difficult to evidence without a dated scan.
IASME Cyber Essentials Plus requirements.
ISO 27001. Annex A control A.8.8 asks you to identify, evaluate and act on technical vulnerabilities, not just find them.
ISO/IEC 27001:2022, Annex A, control A.8.8.
Cyber insurance renewal. Insurer proposal forms increasingly ask how often you scan your perimeter and how quickly you patch by severity. An assertion is worth less at renewal than a dated document, and considerably less after a claim.
Renewal proposal forms, for example Hiscox and CFC.
Picket is a new service. We have run this kind of work for years inside government and for existing clients, but not yet, under this name, for a company like yours.
The first five Recces run at a founding rate because we want three things from them: the evidence that the method holds outside government, a short anonymised case note we can show the next client, and you as one of our first five. In return you get the same day, the same brief and the same people, at half the standard fixed fee.
Ben Brand helped build and ran the MOD’s Vulnerability Management Support Team, and still does equivalent work inside UK Government today.
What we ask in return: a thirty-minute debrief within two weeks of the brief, and permission to write a short anonymised case note (sector, size, what the brief showed) that names nothing that identifies you.