Offensive security
London · Dubai

Attackers do not
book a slot.

So we do not test to a calendar. CHMS runs continuous penetration testing, red teaming and social engineering across your entire estate for one annual fee. Not one week in March.

Scroll
Offensive security and private AI deployment
60+
UK local authorities protected by a platform we deploy
10yrs+
Offensive security experience in the founding team
2regions
Operating across the United Kingdom and the UAE
0
Per engagement fees on an unlimited agreement
02The problem

Why the model is wrong

A yearly test tells you about a company that has since changed.

The report lands in April. By June you have shipped two new services, onboarded a supplier with access to your file store, and replaced half the laptop fleet. None of it was in scope, because none of it existed when the scope was written.

The industry has trained buyers to think of testing as an event. It is a procurement cycle, a scoping call, a week of work and a PDF. Attackers experience your business as a continuous surface. The two models do not match, and the gap between them is where incidents happen.

The point of testing is not the report. It is the window of time in which you are wrong about your own estate.

03How the engagement runs

Repeated, not scheduled

One agreement. Testing that never stops.

The same sequence a competent attacker follows, run against your estate on repeat rather than once.

  • 01MapWe build and maintain a live picture of everything you expose: domains, hosts, cloud accounts, third party integrations, staff. It is rebuilt continuously, not captured once at kick off.
  • 02TestManual testing against that surface, plus automated coverage between passes. New asset appears on Tuesday and it is tested on Tuesday. You do not raise a change request.
  • 03EscalateWhere a finding is exploitable we prove it. Chained access, privilege escalation, lateral movement and impact, demonstrated rather than described in a severity table.
  • 04ReportFindings reach you as they are confirmed, with reproduction steps and a fix. There is no six week wait for a document, because the document is not the deliverable.
  • 05RetestYou fix it, we verify it, and it stays on the list until it is closed. Retesting is included, which removes the commercial reason to stop looking.
04Commercial model

One annual fee

What changes when the meter stops running.

Traditional testing is priced per engagement, so every question costs money and every question therefore gets asked less often. Unlimited removes that.

Traditional
Scoped once, priced by the day, delivered as a report
CHMS
Scoped once, priced annually, delivered continuously
Retesting
Usually billed again. Included here.
New assets
Usually out of scope until the next cycle. In scope on the day here.
Urgent request
Usually a change request and a lead time. Included here.
Report
Usually the end of the engagement. Here it is a running record.
05Selected work

Invision Protect

The on premise layer beneath a platform serving 60+ UK councils.

Invision Protect delivers continuous, evidence led penetration testing to UK local authorities and public services. Some of those organisations cannot allow their data to sit in anyone else's environment, whatever the assurances attached to it.

CHMS provides the deployment that solves it: the full platform, installed and running inside the organisation's own infrastructure, under their own control.

For organisations that require everything inside their own environment, a fully self-hosted, on-premise deployment is available via CHMS Cyber Sec.

Invision Protect
Civic architecture in the United Kingdom
60+ UK local authorities run on the platform. CHMS provides the deployment for those that cannot use anyone else’s environment.
06Next step

No obligation

Find out what a scoping call costs you.

Nothing. Half an hour, an honest read on your exposure, and a fixed annual number if it is a fit.