Home / Services

The full security lifecycle, delivered

Twelve services, one operating model: the engineers who build CFC deliver the work, and every engagement runs out of CFC — scoped, executed and reported on the same platform your analysts already live in.

Full catalogue

Twelve services, offensive to audit

From adversarial testing to compliance evidence — each service stands on its own, and all of them feed the same Fusion Floor.

SVC / 01

Penetration Testing

Authorised adversarial testing against web applications, APIs, internal networks and cloud environments. Every engagement closes with CVSS-scored findings and a remediation roadmap.

SVC / 02

Managed SOC

24/7 security operations combining analyst expertise with Argus-assisted triage. SLA-backed detection, investigation and escalation, delivered from the Fusion Floor.

SVC / 03

Threat Intelligence

Curated indicator feeds, dark-web monitoring and geopolitical threat briefings tailored to your sector and asset profile — fused into detection by Argus-TIAID.

SVC / 04

Incident Response

Rapid containment and eradication for active breaches. Forensic-grade evidence handling, stakeholder communications and post-incident reporting, end to end.

SVC / 05

Red Team Operations

Full-scope adversary simulation — from phishing and social engineering to physical access attempts and multi-stage C2 campaigns against your real defences.

SVC / 06

Vulnerability Management

Continuous scanning, prioritisation and remediation tracking across your on-prem, cloud and OT/ICS infrastructure — ranked by real exposure, not raw severity.

SVC / 07

Cloud Security

Architecture review, misconfiguration scanning and continuous posture management for AWS, Azure and GCP environments.

SVC / 08

Compliance & Audit

ISO 27001, NIST CSF, NCA ECC, SOC 2 — gap analysis, control mapping and evidence packs ready for auditors before they ask.

SVC / 09

Secure Development

SAST/DAST integration, code review, secure SDLC training and threat modelling for development teams shipping under pressure.

SVC / 10

Security Awareness & Training

Phishing simulations, hands-on learning modules and role-based training programmes designed to change behaviour, not just tick a box.

SVC / 11

Digital Forensics & IR

Memory acquisition, disk imaging, log analysis and expert witness support for post-incident investigations, with chain of custody preserved throughout.

SVC / 12

AI Security Consulting

Adversarial ML assessment, LLM red-teaming and AI governance frameworks for organisations deploying AI systems in production.

One operating model

How services and the platform meet

A service you buy and a platform you run shouldn't be two different worlds. At CFC they're the same one.

LINK / 01

Engagements run in CFC

Every engagement — pentest, hunt, audit — is scoped, tracked and delivered inside the platform. You follow progress in the CFC console, not in a PDF that arrives weeks later.

LINK / 02

Findings land on the agent bus

Results don't sit in a report. Pentest findings, hunt outcomes and IR artefacts publish to the agent bus, where Argus-CORE routes them and Argus-TITAN and Argus-TIAID correlate them against your live telemetry and intelligence.

LINK / 03

Evidence sealed by Argus-PACT

Every deliverable becomes a sealed evidence chain mapped to the frameworks you answer to — so the same engagement that fixes your exposure also stands up in front of your auditors.

Get started

Scope an engagement.

Talk to a CFC engineer. We'll map your current exposure and recommend a targeted service plan — no sales pitch, just precision.