Specialized Solutions
Cyntia Security

A report nobody checks again is a PDF.

Security is the part of Cyntia that is people rather than software: we review applications, harden what runs them, and sit in the room before things get built. The findings come back ordered by what they would cost you, somebody fixes them, and then we look again — because a finding is not closed when it is written down, it is closed when it is gone.

What a review actually is

The arrow that comes back is the whole thing. Anybody can hand over a list of findings; the work is ordering them by what they would really cost, watching them get fixed, and checking the fix. Without that last step nothing was closed — it was just described.

The application Review Findings Fixed and it gets reviewed again
  • The findings come ordered by what they would cost you
  • Hardening is the fixing, not the list
  • And it is checked again, or nothing was closed

The same finding, on either side of the release

release Found after it was already running

Found afterwards

Nothing about the finding changes. What changes is that by the time somebody saw it, the application had been running with it for months — so now it is not only a fix, it is working out what happened while it was open, and telling somebody.

release The same finding, found before

Found before

The same finding, in a review, with nothing running yet. It costs what it costs to fix and nothing else. That gap is the entire argument for reviewing before instead of after, and it is why the cheapest engagement is the one that starts early.

Where we usually come in

Sometimes before anything is built, sometimes with the application already live, sometimes because a client or an auditor asked. The work is different in each case; what does not change is that it ends with somebody checking that what was found is no longer there.

Before it is built An application already live A client or an auditor asked Security Review Hardening Advisory

These are the ones we get asked for most, not the whole list. If what you need is not here, it is worth asking.

What we do

Named by what gets delivered, not by what gets opened: there is no screen to log into here.

  • 01

    Application review

    Going through what you built looking for what it lets somebody do that it should not. Findings come back ordered by what they would cost you, not by how clever they were to find.

  • 02

    Hardening

    The fixing, not the list. Configuration, permissions, exposure, everything left on by default that nobody meant to leave on.

  • 03

    Advisory

    Being in the room before it is built, which is the cheapest hour anybody buys from us. Most of what a review finds was decided months earlier.

  • 04

    Re-checking

    Looking again after the fix. It is the step people skip, and skipping it means the report was the deliverable — which it never should be.

Tell us what you are about to release.

Or what has been running for two years without anybody looking at it. Either is a fine place to start; the first one is just cheaper.

Talk to us