Independent by design
We do not resell licences and we take no vendor commission. Our only product is judgement, which is worth very little if it is for sale.
PB Sec exists because most security advice available to a growing company is either too expensive, too generic, or quietly for sale. We built the consultancy we wished our clients could hire.
The most common problem we are called in to fix is not a missing product. It is a sequence problem: a platform bought before the risk was understood, a compliance framework implemented as paperwork, a penetration test commissioned to satisfy a customer rather than to find anything.
So we work the other way round. Understand the environment, find what actually matters, fix it in the order that reduces risk fastest, and only then talk about tooling — if there is anything left to buy.
These are not aspirations. They are the constraints we accept, including when they cost us work.
We do not resell licences and we take no vendor commission. Our only product is judgement, which is worth very little if it is for sale.
Our testers and our defenders sit in the same room. A technique that works against you becomes a detection rule the same week.
If a finding cannot be explained to the person who has to fund the fix, it is not finished. Jargon is usually a way of hiding uncertainty.
We say when we do not know, when a control is theatre, and when a cheaper option would do the job just as well.
Security is a programme, not a project. We scope retainers in days per month so the work continues after the report lands.
You work with the people who did the work. No account managers relaying messages, no juniors quietly learning on your estate.
Most security budgets fail because the work happens in the wrong order — a platform bought before the problem is understood. Fix the order and a modest budget goes a long way.
The build in the app store, the API in production, the model with its real guardrails. Testing a sanitised copy produces findings you cannot act on and misses the ones you can.
Every issue we report comes with the specific change we recommend and a way to verify it worked. If we cannot suggest a fix, we say so and explain why.
A tool count is not a security posture. We report on findings closed, attack paths removed and detection coverage gained — the things that actually changed.
A document that sits unread has protected nobody. The deliverable is a change in your environment, and the report is just how we explain it.
Thirty minutes, no pitch deck. We will tell you the three things worth doing first — and whether you need us at all.