Offensive security · Bristol & London

Penetration-grade scanning, triaged by AI you own.

We assess your estate with the same multi-engine tooling a red team uses, then have a private language model — running on hardware we control — prioritise every finding and map it to Cyber Essentials. No raw scanner dump. No data sent to a third party. A report you can act on and defend.

Every finding is hash-chained — chain-of-custody on your evidence chain verified · HMAC-SHA256
scope authorised
10.0.0.0/24 · cssltd
a1f4…7c0e
port sweep
masscan → nmap
9b22…d41a
finding
CVE · CVSS 9.8
3e8c…06f5
AI triage
priority · CE map
cc71…b9e3
report sealed
dual exec + technical
f0a9…1d77

Tamper with one line of the log and the chain breaks — the evidence is verifiable, not just printable.

Why now

Cyber Essentials just got stricter, and it's no longer optional.

From 27 April 2026 UK assessments run against the v3.3 requirements (the Danzell question set). The bar moved, and certification is increasingly a condition of doing business.

Auto-fail

MFA enforcement

Under v3.3, any internet-facing service that offers multi-factor authentication and hasn't enabled it is now an automatic failure — no warning, no pass.

14 days

Patch window

High and critical updates — including firmware — must be applied within 14 days across everything in scope. Unsupported software fails.

PPN 014

Public-sector tenders

Cyber Essentials is a baseline requirement on a growing list of UK government and enterprise contracts. No certificate, no conversation.

Supply chain

Insurers & clients

Cyber insurers and larger customers now ask for certification in due diligence. The NCSC's supply-chain guidance pushes it down to suppliers.

The engine

One assessment. Network and AI systems. Your hardware.

Most scanners hand you a wall of raw output and call it a report. We built an engine that does the hard part — fusing the scan, judging it, and tying it to the standard you're assessed against.

Multi-engine fusion

Breadth and depth

A fast full-range port sweep feeds precise service and vulnerability detection, alongside modern templated CVE, web and TLS checks. Coverage without the blind spots of a single tool.

Sovereign AI

Your data never leaves

Triage runs on a private model hosted on hardware we control — nothing is sent to a third-party API. The honest answer to the GDPR and confidentiality question your clients will ask.

Intelligent triage

Signal, not noise

The model flags likely false positives, ranks what to fix first, writes the business impact in plain terms, and maps each finding to the relevant Cyber Essentials control.

AI security testing

Red-team your LLM

Deploying a chatbot or AI feature? We probe it for jailbreaks, prompt injection and data leakage with industry red-team tooling — the attacker model stays local too.

Tamper-evident

Evidence you can defend

Every step of the assessment is cryptographically chained. The audit trail is verifiable end to end — defensible if a finding is ever challenged.

One dashboard

Mapped to the standard

Network findings and AI-security results land in a single Cyber Essentials view, with a clear status against each of the five controls and an honest note on what only a hands-on audit can confirm.

Priority · Phishing-resistant MFA

Hardware security keys — closing the control a scan can't.

Under Cyber Essentials v3.3, missing MFA on an internet-facing service is now an automatic failure — and the scheme actively pushes passwordless and FIDO2 passkeys. Passwords and SMS codes get phished; hardware keys are phishing-resistant by design. Deploying and supporting them is a core focus for us, from strategy to day-to-day lifecycle.

MFA strategy

Audit & rollout plan

We map where strong authentication is missing, choose the right key (YubiKey 5, Security Key, Bio) and design the rollout — privileged accounts first, then the whole team.

FIDO2 / WebAuthn

Go passwordless

We configure phishing-resistant, passwordless sign-in — passkeys, FIDO2, PIV/smartcard, OTP — aligned with the v3.3 MFA requirement and passkey direction.

IdP / SSO integration

Into your stack

Microsoft Entra ID, Okta, Google Workspace, VPN, SSH and secret managers. The key works everywhere your team signs in.

Lifecycle

Enrolment, recovery, break-glass

Issuance and return procedures, break-glass emergency accounts, policy, user training and lost-key support. Security that holds up in daily use.

We're a deployment and technical-support partner for hardware security keys — we advise on selection and procurement; key hardware is costed per model and headcount.

Cyber Essentials v3.3

The five controls, scored against your real estate.

We map findings to each control and tell you the truth about coverage: an external scan can evidence some controls directly, while others need a hands-on audit or the questionnaire. We never tick a box the scan can't support.

1
Firewalls & routersboundary protection, admin exposure, default credentials
scan-evidenced
2
Secure configurationhardening, TLS, exposed services, weak defaults
scan-evidenced
3
Security update managementoutdated versions, known CVEs, the 14-day window
scan + verify
4
User access controlMFA, admin separation, account hygiene
audit & SAQ
5
Malware protectionendpoint controls, allowlisting
audit & SAQ

Controls marked “audit & SAQ” can't be confirmed by an external scan alone — we flag them for hands-on verification rather than overstating readiness.

Engagements

Premium, fixed-scope engagements. We don't discount security.

These are senior-level offensive-security engagements, priced accordingly. We confirm exact scope and a fixed quote before any work begins — the price is the price. When it comes to security, the cheapest assessment is the one that misses what matters.

Starting point

CE Gap Analysis

from £1,950 + VAT
  • Multi-engine scan of agreed scope
  • AI triage: priorities & false-positive filtering
  • Mapping to all five CE v3.3 controls
  • Plain-English remediation report
  • Tamper-evident audit trail
Start here
Most chosen

Full Assessment + CE Support

from £6,500 + VAT
  • Everything in Gap Analysis
  • Manual review by a red-team consultant
  • CE / CE Plus readiness & evidence pack
  • Guided support through certification
  • Remediation re-test included
Book this
AI systems

AI Security Gap Analysis

from £4,500 + VAT
  • Red-team of your LLM / chatbot
  • Jailbreak, injection & leakage probes
  • Mapped to OWASP-LLM categories
  • Runs fully local — sovereign
  • Findings in the same dashboard
Assess my AI
Priority · MFA

YubiKey / FIDO2 Rollout

from £3,200 + VAT + hardware
  • MFA audit & strong-auth strategy
  • FIDO2 / WebAuthn / passwordless setup
  • Entra ID / Okta / Google integration
  • Enrolment, break-glass, policy
  • Team training & ongoing support
Roll out keys
Stay certified

Managed Assurance

from £950 / mo + VAT
  • Recurring scheduled scans
  • Drift & new-exposure alerts
  • Renewal preparation
  • Quarterly posture review
  • Priority remediation guidance
Talk to us

Each engagement is scoped and fixed before work begins; the floor prices above reflect senior-level work and are not discounted. Final price depends on the size and complexity of the in-scope environment. CyberSentinel Solutions Ltd provides Cyber Essentials readiness, assessment and remediation support; certification is issued by an IASME-accredited Certification Body.

How it works

From scope to certificate-ready, in a clear line.

Scope & authorise

We agree exactly what's in scope and capture written authorisation. The scope is the first link in the audit chain — assessment only ever runs against what you've approved.

Scan

Multi-engine discovery and vulnerability detection across hosts, services, web and TLS — plus AI-system red-teaming where relevant.

AI triage

A private model prioritises findings, filters noise, writes the business impact and maps each issue to the right Cyber Essentials control.

Report

You receive a dual report — an executive summary for the board and a technical breakdown for whoever fixes it — plus the consolidated CE dashboard.

Remediate & certify

We support the fixes, re-test, and walk you through certification with an accredited body. You end up certified, not just scanned.

Who we are

A UK offensive-security practice, not a checkbox factory.

16019829
Companies House registered, England & Wales
Bristol & London
UK-based, working with Polish & UK clients
Red-team led
SANS UK CTF top-15 placement, hands-on pentest background
AI-native
Specialists in securing AI systems and self-hosted inference

Find out where you stand — before an assessor does.

Send us your rough scope and we'll come back with a fixed quote and a date. Most gap analyses are scoped within a day.