About
Practitioners first.
Laneden is a UK offensive-security firm founded in 2021. We test like attackers because that’s the work we do every day — and we hold ourselves to independently assessed standards.
Who we are
Laneden is a boutique UK offensive-security firm, founded in 2021. The team comes from information-security, threat-intelligence, vulnerability-management, secure-development and penetration-testing backgrounds — people who have defended networks as well as attacked them.
Between them, our engineers have held industry qualifications including CTM and CTL (CHECK), CSTM and CSTL (Cyber Scheme), CEH, SANS SEC642 and OSCP — or their equivalents — alongside the firm-wide CREST accreditation that governs how we work.
We build tooling as well as test. Gravitas, the attack-surface intelligence platform we co-own and lead, means we work with breach data, stealer logs and attacker infrastructure every day — and that keeps our testing grounded in what attackers actually do, not what a checklist says they might.
CREST accredited
CREST is the international accreditation body for offensive security. Accreditation means Laneden’s methodologies, technical capability and ethical standards are independently assessed against rigorous criteria — not self-declared.
What that means for you
- Methodology reviewed against internationally recognised standards
- Qualified, ethics-bound testing personnel
- Defined complaint and escalation routes
- Ongoing reassessment — accreditation is maintained, not won once


Before we start
Three documents, agreed in this order, so the work is scoped, priced and lawful before anyone touches a system.
Service Engagement Document
Methodology, approach and NDA — agreed before any work starts.
Proposal
Scope, deliverables and a single total price for the agreed scope — not an open-ended day-rate engagement.
Authorisation Form
Formal written consent, so testing is always lawful and in-scope.
While we test, and after
What actually happens once an engagement starts — how we communicate, what you receive, and what we do when you have fixed things.
While we test
Open lines, and nothing sat on.
- A named lead security engineer runs your engagement, and stays the point of contact throughout
- Open communication for the duration — if any aspect of the assessment is impeded or the scope needs to change, you hear it at the time rather than in the report
- Findings are notified by severity as they are confirmed — a critical issue reaches you promptly rather than waiting for the write-up. The bands and what each triggers are set out below
- Internally, engagement detail is need-to-know: only engineers on your test, over encrypted channels, with anyone else cleared by the lead engineer first
- Where a technical obstacle outside our control blocks part of the scope, we tell you at the time and agree how to handle it with you — it is never quietly dropped
What you receive
Written for two audiences, delivered securely.
- An executive summary your board can act on, and technical detail your engineers can reproduce — in the same report
- An overall risk rating for the engagement, plus a comparative rating showing how your results stand against other organisations
- A sector-based risk score, benchmarking you against your own industry rather than against everyone
- A findings table ordered by severity, with the evidence and remediation for each
- Delivery through an access-controlled repository: the download link is issued to named contacts and requires a one-time code sent to their email
- A debrief call once the report lands, covering the key findings, the actions they imply, and any questions your team has
After the report
The engagement does not end at delivery.
- A remediation check confirming the fixes you have made, free of charge and subject to the size of the assessment, for three months from delivery*
- A revised report reissued after that check, confirming what has been closed — the artefact you hand to an auditor
- A full re-assessment available as a separately quoted option where you want fresh eyes rather than a confirmation
- Your Technical Account Manager stays reachable after the engagement, for guidance on anything the assessment uncovered
* Free remediation retesting applies to penetration testing engagements. It is subject to the size of the assessment and available for three months from delivery of your report. A web application test is typically covered; a large engagement — an internal test across hundreds of systems, for example — is scoped and quoted, and a full re-assessment is always chargeable.
You do not need an open engagement to ask us something.
Every client has a named Technical Account Manager — a security engineer who knows your estate, not an account handler who has to go and ask one.
If a supplier has sent you a questionnaire you cannot answer, a board paper needs a sanity check, something odd has turned up in your logs, or you simply want to think out loud about an idea before committing budget to it, that is what they are for. There is no meter running on a conversation. We would far rather talk it through early than read about it later.
How we rate what we find
Every finding is scored against CVSS and carries a severity band. The band decides how quickly you hear about it, not just how it reads in the report.
- CriticalCVSS 9.0 – 10.0
Reported promptly to your assigned contact, to expedite remediation and help you identify any exposure.
Immediate action to limit further exposure.
- HighCVSS 7.0 – 8.9
Your assigned contact is notified at the end of the day, where that is appropriate.
Plan remediation in the short term.
- MediumCVSS 4.0 – 6.9
Summarised to your assigned contact on the last day of the assessment, with full detail in the report.
Plan remediation on a reasonable timescale.
- LowCVSS 0.1 – 3.9
Summarised to your assigned contact on the last day of the assessment, with full detail in the report.
Address as part of routine maintenance.
- InformationalCVSS 0
Summarised to your assigned contact on the last day of the assessment, with full detail in the report.
Consider, and act where appropriate.
| Severity | CVSS | When you hear about it | What it asks of you |
|---|---|---|---|
| Critical | 9.0 – 10.0 | Reported promptly to your assigned contact, to expedite remediation and help you identify any exposure. | Immediate action to limit further exposure. |
| High | 7.0 – 8.9 | Your assigned contact is notified at the end of the day, where that is appropriate. | Plan remediation in the short term. |
| Medium | 4.0 – 6.9 | Summarised to your assigned contact on the last day of the assessment, with full detail in the report. | Plan remediation on a reasonable timescale. |
| Low | 0.1 – 3.9 | Summarised to your assigned contact on the last day of the assessment, with full detail in the report. | Address as part of routine maintenance. |
| Informational | 0 | Summarised to your assigned contact on the last day of the assessment, with full detail in the report. | Consider, and act where appropriate. |
How we use AI
Selectively, and never in place of an engineer. Every engagement is led and performed by qualified security engineers.
- AI is an assistive aid to our engineers. It augments expertise and never replaces it — nothing in an assessment is left to AI alone
- Every AI-assisted observation is independently reviewed, validated and verified by an engineer before it informs testing or appears in a deliverable
- AI is never used to autonomously exploit a system, to make risk-rating decisions, or to determine the outcome of an assessment
- Where it does help is breadth and speed: accelerating research, surfacing patterns across large volumes of data, suggesting further avenues to investigate, and drafting report content an engineer then owns
- We minimise what client information reaches AI tooling, and we do not submit client credentials to it
How we handle your data
- Engagement data encrypted at rest (AES-256) with full-disk encryption on all testing devices
- Data encrypted in transit with TLS 1.2 or higher, to and from access-controlled storage
- Access restricted to personnel on your engagement, enforced by role-based access control and multi-factor authentication
- Every member of Laneden staff signs a confidentiality agreement on joining
- Report data securely erased from testing devices once uploaded and delivered
- Reports retained for six months, then automatically deleted
Ready to test your defences?
Tell us what you need secured — we'll come back with a scoped proposal within two working days.
Free remediation retesting* to confirm your fixes (subject to assessment size).