Picket Recce · One day, external, authorised

Picket Recce: one day, five pages, a fix plan.

One authorised day looking at what your organisation has exposed to the internet, two or three short conversations with the people who run it, and a five page report in your hands within a week. It answers one question: what are you exposed to, and which of it actually matters?

Founding rate · first five clients

The fee counts in full towards whatever comes next.

Reserve a founding-rate slot →

What you get

  1. 01What we did, and did not doThe exact scope, the authorisation it ran under, and the honest limits of a one day external look.
  2. 02What is visible from outsideYour estate as an attacker enumerates it: the hosts, the certificates and their issuers, the technologies and versions, anything reachable that should not be.
  3. 03The five that matter, and whyFindings ranked on severity, exploit probability and how much the affected asset matters to your business, each with an analyst’s judgement on why it matters here.
  4. 04Where this leaves youWhere you stand against the question you are actually being asked, whether that is a Defence Cyber Certification level, a CAF outcome, ISO 27001 or an insurer’s renewal form.
  5. 05What we would do nextWhat your own team can act on this week, with or without us.

How it runs

  1. 01Before we startYou sign a scan authorisation naming every asset in scope. That letter, and a technical contact, are all we need to begin.
  2. 02Day 1An authorised, rate-limited external assessment, and two or three short conversations, twenty to thirty minutes each. About an hour of your people’s time in total.
  3. 03Within 5 working daysA five page report in your hands, with a short call to walk through it.

We scan only what you authorise in writing. Nothing is touched before that letter is signed, and nothing outside the list on it is touched at all. That is the difference between an authorised assessment and an offence, and we hold ourselves to it.

What a one day external look can, and cannot, tell you

A Recce is external and unauthenticated. No credentials, no internal access, no agent on any host. It describes the day we looked, not a certification and not a penetration test, and we hold no CHECK or CREST accreditation and claim none. An internal assessment would see different things, and probably more.

We do not promise a number of findings before we start. On a clean estate the report says so plainly, and that is a real answer worth having.

If your contracts sit at Cyber Risk Profile Level 0, the honest next step is a certification body, not us, and we will say so in the report and point you at one.

Why this lands on a desk now

The question turns up from a different direction depending on who is asking it.

Defence supply chain. DEFCON 658 contracts sit under Cyber Security Model v4, and Def Stan 05-138 Issue 4 asks for monthly vulnerability scanning and a documented risk treatment plan at Cyber Risk Profile Level 1 and above.
Def Stan 05-138 Issue 4, Table 1.

Cyber Essentials Plus. Recertification requires internet-facing vulnerabilities scoring 7 or above to be fixed within 14 days, which is difficult to evidence without a dated scan.
IASME Cyber Essentials Plus requirements.

ISO 27001. Annex A control A.8.8 asks you to identify, evaluate and act on technical vulnerabilities, not just find them.
ISO/IEC 27001:2022, Annex A, control A.8.8.

Cyber insurance renewal. Insurer proposal forms increasingly ask how often you scan your perimeter and how quickly you patch by severity. An assertion is worth less at renewal than a dated document, and considerably less after a claim.
Renewal proposal forms, for example Hiscox and CFC.

Why the first five are at a founding rate

Picket is a new service. We have run this kind of work for years inside government and for existing clients, but not yet, under this name, for a company like yours.

The first five Recces run at a founding rate because we want three things from them: the evidence that the method holds outside government, a short anonymised case note we can show the next client, and you as one of our first five. In return you get the same day, the same brief and the same people, at half the standard fixed fee.

Ben Brand helped build and ran the MOD’s Vulnerability Management Support Team, and still does equivalent work inside UK Government today.

What we ask in return: a thirty-minute debrief within two weeks of the brief, and permission to write a short anonymised case note (sector, size, what the brief showed) that names nothing that identifies you.

Start with a conversation, not a contract.

Reserve a founding-rate slot →