AL Cyber.

Services

Nine services across
security and engineering.

Grouped, not padded. Each one is work the principal consultant delivers directly, with partner support noted where it applies.

Security

Adversarial testing, detection and response, and the governance work that turns findings into something a board and an auditor can both act on.

01Security

Offensive Security

Adversarial testing that produces evidence, not a scanner export. Every finding is reproduced by hand, rated for real exploitability in your environment, and retested after you fix it.

  • Penetration testing, network, web application, wireless, external and internal
  • Vulnerability assessment with manual validation of every finding
  • OSINT, digital footprint, exposed credentials and attack-surface mapping
  • Social engineering and phishing simulation
  • Red team engagements

Full-scope red team exercises are delivered with specialist collaboration partners.

02Security

Defensive Security

Detection and response built around what your team can realistically operate. Hardening reviewed against vendor baselines and the ACSC Essential Eight, not a generic checklist.

  • Security monitoring and threat detection design
  • Incident response and digital forensics
  • Security hardening and configuration review
  • Firewall, endpoint and network security assessment
  • Security awareness training for staff
03Security

Governance, Risk & Compliance

Risk work that survives contact with a board paper and an auditor. Registers your executives will actually read, and policies your staff can follow without a workaround.

  • Risk assessment and risk register development
  • Policy and procedure development
  • Compliance gap analysis, Essential Eight, ISO 27001, Privacy Act
  • Third-party and vendor risk assessment
  • Security audit and control testing

Sector-specific regimes assessed where they apply to you, including HIPAA where a US nexus exists.

04Security

ISO 27001 Advisory

An ISMS scoped to your actual risk, not a template with your logo dropped on it. Advisory only, by design: the accreditation rules require your certification auditor to be independent of your consultant.

  • Gap analysis against ISO 27001 controls
  • ISMS design and implementation guidance
  • Internal audit support
  • Certification readiness assessment

Formal certification is referred to an accredited certification body. A consultancy cannot audit the ISMS it helped you build, verify the impartiality rules before engaging anyone who offers both.

Engineering

Software built by someone who also does the security review, so authentication and access control are designed in rather than bolted on afterwards.

05Engineering

Custom Web Development

Dashboards, client portals, internal tools and full products, built by someone who also does the security review, so authentication and access control are designed in rather than bolted on.

  • Operational dashboards and reporting interfaces
  • Client and partner portals with role-based access
  • Internal tooling to replace spreadsheet processes
  • End-to-end product build and handover
06Engineering

Cross-Platform Mobile & Desktop

One codebase, real native behaviour. Customer-facing apps through to field-team tools that have to work offline in places with no signal.

  • iOS and Android applications with React Native
  • Desktop applications with Tauri
  • Offline-first field and inspection tooling
  • App store submission and release management

Platform choice is made per project, Tauri and React Native have different maturity on mobile, and that shapes the recommendation.

07Engineering

E-Commerce Engineering

Storefronts that hold up during a campaign spike. Headless builds where the catalogue is large enough or the workflow odd enough that a template will fight you.

  • Headless commerce architecture and build
  • Payment gateway integration and reconciliation
  • Inventory and ERP synchronisation
  • Performance tuning for high-catalogue and high-traffic stores
08Engineering

API Design & Integrations

Making systems talk that were never designed to. Documented, versioned contracts and integrations that fail loudly instead of silently corrupting your data.

  • REST and GraphQL API design and documentation
  • CRM, payment provider and logistics integration
  • Legacy system integration and staged migration
  • Webhook, queue and event pipeline architecture
09Engineering

Website, Performance & SEO Engineering

Sites built to ship almost no JavaScript, measured against Core Web Vitals on mid-tier mobile hardware rather than a fast desktop. Technical SEO as an engineering concern, not a content add-on.

  • Astro and React builds with headless CMS
  • Core Web Vitals remediation, LCP, CLS and INP
  • Technical SEO, structured data, crawlability, indexation
  • Accessibility remediation toward WCAG 2.2 AA
010Method

Every one of them runs the same way.

  1. 01

    Discover & Scope

    Direct engagement with the lead practitioner. We define target boundaries, clear constraints, and success criteria. Fixed scope and fixed price confirmed in writing before technical work begins.

  2. 02

    Execute & Validate

    Hands-on assessment or technical build. Critical vulnerabilities and blocking issues are flagged immediately, not withheld for the deliverable date.

  3. 03

    Remediate & Guide

    Actionable findings or deployment plans written for the engineers who execute them. Guidance is prioritized by real-world risk reduction and operational impact rather than raw CVSS metrics.

  4. 04

    Verify & Certify

    Retesting and confirmation that remediations hold. You receive clean, audit-ready documentation suitable for leadership, regulators, or external auditors.

Start here

Not sure which of these you need?

Describe the problem rather than the service. A scoping call is usually enough to produce a fixed-price proposal with stated exclusions.

Remote engagements are delivered directly across Oceania, Asia, Europe, North America. Work requiring an onsite or in-country presence is delivered with collaboration partners in that jurisdiction.