Under attack right now? Start here

We break in first,
so no one else does.

Stonegate Defense is an offensive security and incident response practice. We test your systems the way a real attacker would, tell you plainly what we found, and stay on the line until it is actually fixed.

Offense
Network, web, API, cloud, wireless, and social engineering assessments.
Response
Containment, forensics, and eradication when an intrusion is already underway.
Resolution
Root cause, a remediation plan with owners and dates, then a free retest.
Principal
Twenty years in technology. NITRO-certified. You work with him directly.

Capabilities

Three reasons firms call us.

Most of our work starts in one of these three places. It usually ends somewhere else, because a good test finds the thing nobody scoped for.

01

Offensive testing

Adversary simulation against a defined scope, with written authorization and rules of engagement agreed before anything is touched.

  • External and internal network penetration tests
  • Web application and API assessments
  • Cloud configuration and identity review
  • Wireless and physical access testing
  • Phishing and social engineering campaigns
Engagement types

02

Incident response

Something is already inside. The priority order is stop the bleeding, preserve the evidence, then work out how far it got.

  • Triage and containment, around the clock
  • Host, network, and cloud forensics
  • Persistence and malware eradication
  • Ransomware recovery support
  • Briefings your counsel and your board can use
Response process

03

Post-incident resolution

The part most firms leave you to do alone. A report is not an outcome; a closed finding is.

  • Root-cause analysis, not just symptom lists
  • Remediation roadmap with owners and dates
  • Logging and detection engineering
  • IR plan authoring and tabletop exercises
  • Verification retest, included
What resolution means

Method

How an engagement actually runs.

No black boxes and no surprise invoices. You know the scope, the timing, and the escalation path before we start — and you hear from us the same day if we find something that cannot wait for the report.

The sequence below follows established public methodology rather than a proprietary one, so your auditors and your insurers recognise it.

Full service detail

Authorization

Scope and rules of engagement

Targets, exclusions, testing windows, escalation contacts, and a signed authorization to test. Nothing is touched before this exists in writing.

Discovery

Reconnaissance and mapping

We build the same picture of your organization an attacker would — exposed services, forgotten hosts, leaked credentials, third-party footprint, and the people named on your website.

Execution

Exploitation and lateral movement

Validated exploitation only: we prove impact rather than forward a scanner's guess. Where a finding chains into something worse, we follow the chain and document each hop.

Deliverable

Report and walkthrough

An executive summary a non-technical board can read, and a technical body with reproduction steps, evidence, and a fix for every finding. Then a live walkthrough with the engineers who have to do the work.

Resolution

Remediation support

Findings prioritized by real-world risk, with owners and target dates. We stay available to your team while they close them.

Verification

Retest and attestation

Once the fixes land we test them again and issue a clean-state attestation letter you can hand to a client, an auditor, or an underwriter.

Standards we work to

Recognised methodology, not a house secret.

Testing is mapped to public frameworks so findings translate cleanly into whatever regime you already answer to.

  • PTES
  • OWASP WSTG
  • OWASP Top 10
  • OWASP API Top 10
  • NIST SP 800-115
  • NIST SP 800-61 IR Lifecycle
  • NIST CSF 2.0
  • MITRE ATT&CK
  • CIS Controls v8
  • PCI DSS 4.0 · Req. 11.4
  • HIPAA Security Rule

Adam Austin, founder and principal consultant of Stonegate Defense Adam Austin · Founder

Who you get

The person who scopes it is the person who tests it.

Stonegate Defense is led by Adam Austin, a twenty-year technology veteran and NITRO-certified practitioner. There is no bench of juniors behind the proposal — the consultant you meet in the scoping call is the one running the engagement and writing the report.

That matters most in the hours after a breach, when the useful thing is not a ticket queue but somebody who has seen this before, picking up the phone.

  • Twenty years in technology — spanning systems, networks, and security operations.
  • NITRO-certified — formal certification maintained in current practice.
  • Direct engagement — one accountable principal from scoping through retest.
  • Written authorization always — no testing begins without a signed scope and rules of engagement.

More about the practice

Emergency

Already in the middle of one?

Do not wipe the machine. Do not pay anything yet. Isolate what you can, leave it powered on, and get us on the line — the first two hours decide how much of this you can prove later.

Next step

Tell us what you're worried about.

Scoping starts with a conversation, not a questionnaire. Describe the environment and the concern; we will tell you what a useful test looks like — including when the honest answer is that you do not need one yet.