Penthropic Security

Ready to scope an engagement?

Book a Discovery Call

Advisory · London

People do the thinking.
The platform keeps checking.

Fixed-fee assessments, third-party risk design, threat modelling sprints and fractional vCISO. A consultant writes a report and leaves. Here the work can land in a platform that carries on testing it, so a control that regresses raises a finding instead of waiting for next year's review.

Fixed-fee or retainer Start within 2 weeks Reply within 1 business day

The handover

The report is the start of the work, not the end of it.

Every advisory engagement here stands on its own. You can take the report and walk away, and plenty of clients should. If you run the Penthropic platform as well, the findings go into the same Risk Register the platform works from, and the checks behind them keep running.

A finding written in March is a claim about March. A finding the platform re-tests is a claim about today.

Assessment finding · after handoverIllustration
signed offGap assessment closed. Findings, owners and dates written into the Risk Register.
rankedSecurity Score and the Top actions list are built from those same findings.
re-testedThe control is checked again on a cadence, against what is actually exposed.
regressed Open. The check that passed at handover no longer passes.
approvalA fix is proposed and waits. Nothing runs until a named approver says yes.
auditProposal, decision, tool call and outcome appended to a hash-chained log.
The shape of the loop. The content is drawn, not measured, and is not a client record.
Assessment
Gap findings against NIST or ISO 27001:2022 land in one Risk Register with a live Security Score and a ranked Top actions list, so the remediation plan has a running state rather than a spreadsheet that ages.
Threat model
Crown jewels and attack paths line up with AI Attack-Path Review, which reasons over the network the Sentinel appliance or the endpoint agent mapped and names the one choke-point fix that breaks the most paths.
TPRM design
The operating model you design is the one the platform runs. The AI reads the SOC 2 report, ISO certificate, policies and DPA a vendor uploaded, cross-checks every high-stakes questionnaire answer against that evidence citing the page, and flags drift when the vendor resubmits.
vCISO roadmap
Board Packs and the Evidence Vault are built from the same register the findings sit in, so a quarterly board update is drawn from the evidence rather than rewritten from memory.
Remediation
Anything the platform proposes waits in the Approvals queue. Endpoint fixes run through the Penthropic agent with a verify step after the change. Cloud fixes use an opt-in, write-scoped role you grant. Nothing acts on its own.

How an engagement runs

Four steps. The fee is agreed before anything starts.

No lengthy procurement and no retainer surprises. A straight path from where you are to where you need to be, with a named lead and a fixed end date.

  1. Discovery call

    Thirty minutes. We listen first, work out what you are actually being asked to prove, and say honestly whether we are the right people for it.

    Free · No obligation
  2. Scoped proposal

    A fixed-fee proposal with the deliverables, the dates and the outputs written down. Nothing starts, and nothing is billed, until you approve the scope and the fee.

    Your approval · The gate
  3. Delivery

    Weekly status, a named lead and a shared channel. Practical outputs your team can work from, not a 200 page report that sits on a shelf.

    Fixed scope · Fixed end date
  4. Ongoing support

    Optional in every direction. Fractional vCISO, quarterly reviews, vendor oversight, or the platform carrying the findings forward. None of it is a condition of the first engagement.

    Optional · Flexible

Advisory disciplines

Six disciplines. One partner who stays reachable.

From a baseline assessment through to active threat operations. Each one is scoped and priced on its own, and each one produces something the platform can keep checking if you want it to.

Baseline

Assess

Understand where you stand before you build. Expert-led visibility into the gaps and the exposure, written so an auditor and a board can both read it.

Programme

Build

Turn findings into working programmes. We design the processes, policies and controls the business will actually run, not the ones that read well in a binder.

  • TPRM operating model design
  • Vendor due diligence frameworks
  • Information security policies
  • Risk register and control design
  • OneTrust implementation support
Leadership

Run

Strategic security leadership without the cost of a full-time hire. A named person who turns up, owns the roadmap and answers to your board.

  • Fractional vCISO retainer
  • Ongoing vendor risk reviews
  • Security strategy roadmaps
  • Board-level reporting
  • Incident response advisory
Operations

Cyber Operations

Active security operations, from attack surface management to red team coordination. We test your defences before somebody else does.

  • External attack surface monitoring
  • Penetration test scoping and management
  • Threat hunting and IOC analysis
  • EDR and XDR advisory and tuning
  • Purple team exercises
  • SOC integration and playbook design
Analysis

Threat Modelling

Structured, methodology-driven threat analysis. We map what an attacker would target, how they would reach it, and what each scenario costs the business.

  • STRIDE and MITRE ATT&CK threat models
  • Crown jewels and critical asset mapping
  • Attack path analysis
  • Product and architecture threat reviews
  • Threat scenario development
  • Risk-based control prioritisation
Monitoring

Dark Web Monitoring

Continuous watch on criminal forums, paste sites and breach markets. Know when your data, your credentials or your brand appear, and what to do about it.

  • Domain and brand monitoring
  • Credential leak detection
  • Executive and VIP exposure alerts
  • Ransomware group intelligence
  • Breach data verification and triage
  • Monthly dark web intelligence reports

The practice

Specialist expertise. No generalist fluff.

Penthropic Security is a boutique London practice with one job: helping regulated and fast-growing businesses build security programmes that hold up when somebody checks them.

We work with fintechs, SaaS companies, media firms and PE-backed businesses that need expert security leadership without the overhead of a full in-house team.

We do not sell days. We sell the outputs: an audit-ready programme, a risk process people actually run, and a strategy written in the terms a board reads. Then, if you want it, a platform that keeps testing all three.

In scope

Frameworks we work against

ISO 27001:2022 SOC 2 DORA NIS2 GDPR FCA

How we engage

CISSP · CCSP certified practice Fixed-fee or retainer Start within 2 weeks Reply within 1 business day London and UK-hosted

Project pricing

Fixed-fee engagements.
No surprise invoices.

Project work is scoped and priced upfront. The vCISO retainer below is monthly. Bespoke programmes available, get in touch.

TPRM

TPRM Health Check

£5,000

A rapid review of your current third-party risk posture with actionable findings and prioritised recommendations.

  • 2–3 week engagement
  • Executive summary report
  • Risk-ranked findings
  • Remediation roadmap
Get Started
Threat Modelling

Threat Model Sprint

£6,500

An intensive 1-week structured threat modelling exercise using STRIDE and MITRE ATT&CK, producing actionable attack path documentation.

  • 1-week intensive sprint
  • Crown jewels identification
  • Full STRIDE threat model
  • ATT&CK-mapped attack paths
  • Risk-prioritised control gaps
Book a Sprint
Cyber Ops

Cyber Operations Engagement

From £8,500

Scoped offensive and defensive operations, attack surface review, pen test management, threat hunting, and purple team exercises.

  • Scoped to your environment
  • Coordinated pen test management
  • EDR/XDR review & tuning
  • Threat hunting engagement
  • Full findings report
Scope an Engagement
Run

Fractional CISO

From £3,000/mo

Ongoing strategic security leadership. Your dedicated vCISO attends meetings, advises your team, and keeps you audit-ready.

  • Monthly retainer
  • Regular security reviews
  • Board reporting support
  • Incident response advisory
  • Vendor risk oversight
Get Started
Dark Web

Dark Web Monitoring

From £750/mo

Continuous monitoring of criminal markets, breach databases, and paste sites for your domains, credentials, and executive profiles.

  • Monthly retainer
  • Real-time breach alerts
  • Domain & brand surveillance
  • Executive exposure monitoring
  • Monthly intelligence report
Start Monitoring

All engagements are fixed-fee and scoped upfront. Operational tooling lives on the platform page, bespoke programmes available, get in touch.

Advisory FAQ

The questions we hear on every discovery call.

Still unsure? Drop us a message, we reply fast.

Probably not yet. Most mid-sized firms can't justify a full-time CISO at £120k, £180k all-in. A fractional vCISO gives you the same strategic expertise, board reporting, vendor oversight, incident response advisory, at typically 10–20% of the cost of a hire. We'll be honest with you on the discovery call about whether you've grown past needing fractional and into needing a permanent hire.

Our sweet spot is 30–300 employees, precisely because firms this size face real regulatory and customer scrutiny but can't absorb a full security function. If you're smaller, a one-off assessment might be all you need. We'll tell you honestly what's proportionate; we'd rather lose a sale than push you into a programme you don't yet need.

A standard audit looks at your own internal controls. Third-party risk management (TPRM) is about the risk your suppliers and partners introduce to your business. Under DORA, FCA guidelines, and most enterprise procurement requirements, both matter, but TPRM is the gap most firms have. We design TPRM operating models that are actually run, not the questionnaire-and-shelf model.

Typically within 1–2 weeks of a signed engagement. If you have an urgent audit or deadline, FCA, DORA, customer security review, or insurer demand, contact us directly; we've mobilised in under a week for clients with pressing timelines.

Kick-off call, document review and stakeholder interviews, findings analysis, then a structured output, report, risk register, or programme design depending on the engagement. We work remotely with occasional on-site visits and give weekly status updates throughout. You'll have a named lead, a Slack channel (or Teams if you prefer), and a fixed end date.

Yes, always. We operate under mutual NDA and provide a DPA as standard. We follow our own information security policies on every engagement, and can sign your supplier security questionnaire ahead of kickoff if your procurement requires it.

Yes. Advisory engagements (NIST, TPRM, vCISO, threat modelling) stand on their own, you can take the report and walk away. The platform is there if you want continuous operations after the project, but it's never a condition of working with us.

Get in touch

Let's talk about
your security programme.

Whether you are preparing for an audit, designing a TPRM programme, or looking for ongoing security leadership, tell us what you are being asked to prove.

  • hello@penthropic.ai
  • London, United Kingdom
  • We reply within one business day
  • No sales pressure, ever
  • Discovery call is always free