Skip to content
Epic IT Support

Partner capability

Security engineering and offensive testing, under your brand

Cyber insurance renewals and customer security questionnaires are pushing your clients to ask for penetration tests and posture evidence you may have no way to produce. We deliver the testing, the assessment, and the remediation engineering behind it — reported in your branding, with authorization documented before anything starts.

  • External, internal, web application, and cloud penetration testing
  • Written authorization and rules of engagement before any test
  • Findings prioritized by exploitability, not raw CVSS
  • Microsoft 365 and Entra ID posture assessments
  • Defender, Sentinel, Splunk, and Elastic deployment and tuning
  • Remediation and retest, not just a report

What we deliver

Penetration testing

Authorized, scoped testing against agreed targets, with findings your client can act on rather than a tool dump.

  • External network testing against the internet-facing perimeter
  • Internal network testing modeling an assumed-breach starting position
  • Web application and API testing aligned to the OWASP methodology
  • Cloud configuration testing across Azure and AWS tenancies
  • Findings prioritized by exploitability and business impact, with remediation steps

Vulnerability management

The recurring discipline that closes the gap between knowing about a CVE and having fixed it.

  • Authenticated and unauthenticated scanning across the estate
  • CVE prioritization by real exploitability rather than raw CVSS score
  • False-positive triage so your technicians are not chasing noise
  • Remediation tracking with evidence of closure
  • Recurring scan cadence delivered as a retained service under your brand

Security posture assessment

A structured review of what is configured against what the client believes is configured.

  • Microsoft 365 and Entra ID security posture assessment
  • Microsoft Defender licensing, coverage, and policy review
  • Conditional access, MFA coverage, and privileged access gap analysis
  • Cyber insurance questionnaire mapped to concrete configuration findings
  • Prioritized remediation roadmap costed into deliverable phases

Detection and response engineering

Making sure someone would actually notice — and building the stack that tells them.

  • Microsoft Defender for Endpoint, Identity, and Office deployment and tuning
  • SIEM deployment and log source onboarding in Sentinel, Splunk, or Elastic
  • Detection rule development and alert tuning to cut false positives
  • EDR and XDR policy configuration and rollout
  • Network segmentation design, including OT and SCADA DMZ separation

Platforms we work in

Named platforms, not categories — so you can tell at a glance whether we already know your environment.

Microsoft security
  • Defender for Endpoint
  • Defender for Identity
  • Defender for Office 365
  • Microsoft Sentinel
  • Microsoft Purview
SIEM & logging
  • Microsoft Sentinel
  • Splunk
  • Elastic
  • Syslog
  • Windows Event Forwarding
Assessment
  • Nessus
  • OpenVAS
  • Burp Suite
  • Nmap
  • CIS Benchmarks
  • OWASP
Network & OT
  • Fortinet
  • Palo Alto
  • SCADA DMZ segmentation
  • VLAN isolation
Identity controls
  • Entra ID
  • Conditional Access
  • Duo
  • Privileged access tiering

How it runs

From first call to sign-off

Every engagement is governed by a written statement of work naming deliverables, assumptions, and who is responsible for what.

  1. Scope and written authorization

    Targets, methods, timing, and rules of engagement agreed in writing with the asset owner before any testing begins. No exceptions.

  2. Testing inside the agreed window

    Executed against the authorized scope only, with an escalation contact live throughout in case anything needs to stop.

  3. Findings and prioritization

    A written report ordered by exploitability and business impact, with reproduction detail your technicians can follow and concrete remediation steps.

  4. Remediation support and retest

    We can hand the report to your team, or stay on to remediate and retest so the client receives closure evidence rather than an open list.

Questions

What people ask

Security engineering and offensive testing, under your brand — questions

Can we resell penetration testing under our own brand?

Yes — this is one of the most common white-label requests we get, because clients increasingly need a test for cyber insurance or a customer security questionnaire and most MSPs have no offensive capability in house. Reports are delivered in your branding, and we can join the findings presentation as your security team or stay entirely behind you.

What authorization do you require before testing?

Written authorization from the party that owns the assets, naming the in-scope targets, the permitted methods, and the testing window. If the environment is hosted, provider authorization may also be required and we will tell you when it is. We do not begin testing on a verbal go-ahead.

Is a vulnerability scan the same as a penetration test?

No, and the difference matters when a client is buying to satisfy an insurer. A scan enumerates known vulnerabilities from a signature database. A penetration test involves a human attempting to chain findings into actual access. Many questionnaires specifically require the latter, and clients who bought the former find that out late.

Do you help remediate, or only report?

Either. Some partners want the report and will remediate with their own team. Others want us to fix what we found and retest so the client gets documented closure. The engineering capability behind the remediation is the same team that does our Linux, cloud, and identity work.

Can you assess Microsoft 365 specifically?

Yes. A Microsoft 365 security posture assessment covering Entra ID configuration, conditional access and MFA coverage, Defender licensing and policy, and data protection settings is a well-defined, repeatable engagement — and it very often surfaces the gaps behind a failed insurance questionnaire.

Do you work in OT or SCADA environments?

We have done network segmentation and DMZ design work for SCADA environments in the utility sector. We are deliberately conservative there: on operational technology the priority is isolation and design review rather than active testing against live control systems.

A client just asked for a penetration test

Tell us the environment and what triggered the request — an insurer, an auditor, or a customer questionnaire. The trigger usually determines what the test actually needs to cover.