Skip to content
BigTree108

Cybersecurity and penetration testing services

Cybersecurity and penetration testing services: penetration tests of web and mobile applications, APIs, networks and cloud accounts, application security and secure code review, cloud security posture, security monitoring and incident response, and the technical side of ISO 27001, SOC 2 and PCI DSS, with dedicated security engineers and penetration testers for your team.

Security services we provide

  • Web application penetration tests

    Authentication, sessions, access control, business logic and injection tested by hand against the OWASP Web Security Testing Guide, with automated scanning as a starting point rather than the result.

  • Mobile and API penetration tests

    iOS and Android apps tested against the OWASP MASVS, and REST, GraphQL and gRPC APIs against the OWASP API Security Top 10: object-level authorisation, mass assignment, rate limits and tokens that outlive their purpose.

  • Network and Active Directory penetration tests

    External perimeter and internal network tests, Active Directory and Entra ID attack paths mapped with BloodHound, Wi-Fi testing, and phishing simulations when you ask for them, each run under written authorisation.

  • Application security and secure code review

    Threat models for new features, manual review of the authentication, authorisation and data-handling code, static analysis in CodeQL or Semgrep tuned until developers trust its findings, and secure-coding training built on the issues found in your own code.

  • Cloud security posture

    AWS, Azure and Google Cloud accounts checked continuously with Security Hub, Defender for Cloud, Security Command Center, Prowler or Wiz for public storage, over-broad roles, long-lived keys and logging that is switched off, with the fixes written as infrastructure as code.

  • Security monitoring and SOC

    Logs from cloud, identity, endpoints and applications collected in Microsoft Sentinel, Splunk, Elastic Security or Wazuh, detection rules mapped to MITRE ATT&CK, EDR on every device, and alerts triaged by analysts on a rota you agree.

  • Incident response

    Containment, evidence preserved for forensics, the root cause found and systems restored from clean backups, then a written report and the detection that would have caught it sooner. Tabletop exercises test the plan before it is needed.

  • Compliance automation

    The technical side of ISO 27001, SOC 2, PCI DSS, HIPAA, NIS2 and DORA: controls built into your systems, evidence collected from them automatically through Vanta, Drata or your own scripts, and access reviews, backups and change control proved from records rather than screenshots.

  • Hardening

    Servers, containers, clusters and laptops brought to CIS Benchmarks and industrial control networks segmented into IEC 62443 zones, with settings applied by code and checked on a schedule so they do not drift back.

Hire security engineers and penetration testers

  • Dedicated security engineers and penetration testers

    Security engineers and penetration testers who join your team full time, work in your tools and process, and report to your lead. You interview them; we carry the Ukrainian contract, payroll, invoicing and leave.

  • Security engineering projects

    A defined piece of security engineering with a scope, a fixed plan and a named lead on our side who owns the result and reports progress in your channels.

  • Ongoing security engineering

    Security engineering as a continuing service: the same people every month, a backlog you prioritise, and hours you can see in our portal and on the invoice.

The dedicated team page explains how specialists join your team, and the outsourcing page covers project delivery, take-overs and how we charge.

Who works on your security engineering

  • Penetration testers

    Web, mobile, API, network and cloud testing

  • Application security engineers

    Secure code review, threat models and pipeline scanning

  • Cloud security engineers

    Posture, identity and fixes as infrastructure as code

  • SOC analysts and incident responders

    Detection, triage and response

  • Compliance engineers

    ISO 27001, SOC 2 and PCI DSS controls and evidence

How we work on security

Every test starts with a written scope: which systems and accounts, which hours, who to call if something breaks, and written authorisation from the owner of each system. Testing runs against staging wherever it can, each finding is reported with its severity, a reproduction and a fix, and a retest after the fixes confirms each one is closed.

Findings are fixed where they live: code changes by developers, cloud and network changes as infrastructure as code, and a regression test or a detection rule for each, so a closed finding stays closed. We hold our own systems to the same standard: our laptops are checked by an agent we wrote in Rust against our security baseline, on Windows, macOS and Ubuntu, with checks mapped to ISO 27001, CIS, Cyber Essentials, Essential Eight and SOC 2.

Other cloud, DevOps and security services

Cloud, DevOps and security overview

Questions about cybersecurity and penetration testing

Which industries do your security engineers work in?

Mostly cybersecurity product companies, on detection content, product testing and security research; fintech and banking, under PCI DSS and DORA; industrial and energy companies, separating control networks from office IT; e-commerce, protecting checkout and customer accounts; SaaS companies preparing for SOC 2 audits and customer security reviews; and hosting and telecom providers and public-sector systems.

What does a penetration test report contain?

A summary for management, then every finding with its CVSS severity, the affected system, the steps to reproduce it, the evidence and a recommended fix. After your team deploys the fixes, a retest records which findings are closed.

Can you get us ISO 27001 or SOC 2 certified?

Certification is issued by an accredited certification body, and a SOC 2 report by an independent audit firm, so no supplier can promise either. We do the technical side: implement the controls the auditor will test, fix the gaps a readiness review finds, and keep the evidence ready to export.

Will testing disrupt our production systems?

Not by default. Testing runs against staging where one exists. Where production has to be tested, it happens in an agreed window, at an agreed rate, without destructive payloads, and with a named contact on each side.

How quickly can security engineers and penetration testers start?

When the right security engineer is available, the start is gated only by your interview and the NDA and IP assignment. Otherwise we run a search, which typically produces candidate profiles within two to three weeks, and nobody starts until you have said yes.

How do we hire security engineers and penetration testers through BigTree108?

Tell us the work, the seniority and the hours you need. We propose one or two people with their profiles, you interview them the way you would interview your own hire, and you sign one agreement with BIG TREE 108 LLC and receive one invoice a month.

Who owns the work they produce?

You do. Every specialist has a signed contract with BigTree108 that assigns all work product to the company, and our agreement with you assigns it onward. Code, designs and documents are delivered into your own repositories and tools, not kept where only we can change them.

Need a penetration test or security engineers?

Tell us which systems are in scope, where they run and any audit date you are working towards. You get an answer within one business day: a proposed scope, a test plan, or candidate profiles.