
SCORA
Security posture assessment without the consultant invoice
A security, compliance and risk assessment platform that scores an organisation against NIST CSF 2.0, ISO 27001:2022 and an SME health check, then returns a prioritised action plan.
A defensible account of what happened, how far it reached, and what to change — evidence handled to a standard that holds up outside the IT department.
When something goes wrong on a network of this size, the first casualty is certainty. Logs disagree, people remember events differently, and the pressure to restore service immediately competes directly with the need to preserve what actually happened.
Scope is the hard question. Establishing whether an incident touched one machine or four hundred, and whether anything left the organisation, cannot be answered by inspecting the obvious endpoint — it requires sweeping an estate of over 1,100 employees for the same indicators.
And the findings had to survive scrutiny. An internal summary is not sufficient where legal, regulatory or HR consequences may follow; the evidence has to be acquired and handled so that its integrity can be demonstrated later.
Forensically sound acquisition of the affected systems with documented chain of custody, taken before remediation begins. Restoring a machine first destroys the answer to what happened on it.
Disk and memory artefacts correlated against authentication, endpoint and network logs to build a single defensible sequence of events, rather than a set of disagreeing partial accounts.
Indicators recovered from the initial systems were swept across the wider environment covering all 1,100+ employees, to establish the true blast radius instead of assuming the first system found was the only one affected.
Findings delivered in two registers — a technical account with the supporting evidence, and an executive summary stating what happened, what was affected, and what to do — suitable for legal, regulatory and HR use.
Forensically sound acquisition and documented chain of custody across affected systems.
Disk, memory and mobile device forensic analysis.
Log correlation and full timeline reconstruction of the incident.
Malware and artefact analysis to establish mechanism and persistence.
Estate-wide indicator sweep across an organisation of 1,100+ employees to determine scope.
Root cause analysis with a prioritised remediation roadmap.
Expert reporting prepared to withstand legal and regulatory scrutiny.
A single defensible timeline replacing conflicting partial accounts
True scope established across 1,100+ employees rather than assumed
Evidence handled so its integrity can be demonstrated later
Root cause identified with a prioritised remediation roadmap
Findings usable in legal, regulatory and HR proceedings

Security posture assessment without the consultant invoice
A security, compliance and risk assessment platform that scores an organisation against NIST CSF 2.0, ISO 27001:2022 and an SME health check, then returns a prioritised action plan.

End-to-end encrypted messenger with integrated payments
Privacy-first messaging with self-destructing messages, encrypted calls and built-in cryptocurrency payments.

AI golf swing analyser with a 10-position engine and in-app coach
Upload one swing from a phone and get a 10-position breakdown, 50+ metrics, and the single fix worth practising next.