Discretion by design
Need-to-know access, restrained data handling, and deliberate communication are part of the engagement, not an afterthought.
About sec-review
We lean on hard-earned judgment, then apply it with current tools, current methods, and an unsentimental view of what works.
Why we exist
Some cybersecurity projects need a different operating model. Fewer people. Senior attention. Fast context building. Careful handling. A willingness to say what the evidence supports, even when the answer is inconvenient.
sec-review is structured for that work. We focus on short, consultancy-driven engagements where experience and technical depth can change the outcome.
We do not sell volume. We accept work selectively and stay close to delivery.
Operating principles
Need-to-know access, restrained data handling, and deliberate communication are part of the engagement, not an afterthought.
We optimize for useful decisions and defensible work, not activity, presentation volume, or fashionable language.
We use AI agents and current technical methods where they add leverage. Human practitioners define the question and own the answer.
Core expertise
Security Operations: reviews and decision support grounded in how security teams actually detect, investigate, escalate, and improve.
AI Security: practical security thinking for AI adoption, models, agents, data paths, controls, and failure modes.
Incident Response: preparation, active support, and honest post-incident learning focused on the decisions that matter.
Threat Intelligence: focused research and assessment connected to a specific risk, question, or action.
Good fit
A defined problem. A trusted room. A useful answer.
The best engagements begin with a real decision and a clear owner. If the work is sensitive, bounded, and important enough to deserve experienced attention, we should talk.