1. Home
  2. About
About us

Small, independent, and hard to sell to

PB Sec exists because most security advice available to a growing company is either too expensive, too generic, or quietly for sale. We built the consultancy we wished our clients could hire.

Why we exist

Security advice should not be a sales channel

The most common problem we are called in to fix is not a missing product. It is a sequence problem: a platform bought before the risk was understood, a compliance framework implemented as paperwork, a penetration test commissioned to satisfy a customer rather than to find anything.

So we work the other way round. Understand the environment, find what actually matters, fix it in the order that reduces risk fastest, and only then talk about tooling — if there is anything left to buy.

What we are not

  • A reseller — we take no vendor commission
  • An audit firm — we prepare you, we do not certify you
  • A body shop — you work with the people who did the work
  • A 24/7 SOC for everyone — we quote coverage honestly
Vendor-neutralNo resale, no commission, no referral fees — ever.
Offence-ledEvery technique that works against you becomes a detection.
Remote-firstWorking alongside teams across multiple time zones.
How we behave

Six things we hold to

These are not aspirations. They are the constraints we accept, including when they cost us work.

Independent by design

We do not resell licences and we take no vendor commission. Our only product is judgement, which is worth very little if it is for sale.

Offence informs defence

Our testers and our defenders sit in the same room. A technique that works against you becomes a detection rule the same week.

Plain language, always

If a finding cannot be explained to the person who has to fund the fix, it is not finished. Jargon is usually a way of hiding uncertainty.

Honest about limits

We say when we do not know, when a control is theatre, and when a cheaper option would do the job just as well.

Built for the long haul

Security is a programme, not a project. We scope retainers in days per month so the work continues after the report lands.

Small on purpose

You work with the people who did the work. No account managers relaying messages, no juniors quietly learning on your estate.

How we think

Five working principles

01

Sequence beats spend

Most security budgets fail because the work happens in the wrong order — a platform bought before the problem is understood. Fix the order and a modest budget goes a long way.

02

Test what you actually shipped

The build in the app store, the API in production, the model with its real guardrails. Testing a sanitised copy produces findings you cannot act on and misses the ones you can.

03

A finding without a fix is a complaint

Every issue we report comes with the specific change we recommend and a way to verify it worked. If we cannot suggest a fix, we say so and explain why.

04

Measure what you fixed, not what you own

A tool count is not a security posture. We report on findings closed, attack paths removed and detection coverage gained — the things that actually changed.

05

The report is not the deliverable

A document that sits unread has protected nobody. The deliverable is a change in your environment, and the report is just how we explain it.

Let us look at what you have.

Thirty minutes, no pitch deck. We will tell you the three things worth doing first — and whether you need us at all.

Book a security review