Certifications and specialisations
You want to know whether the specialist assessing your environment understands the technology. This requires technical knowledge and experience with the systems your organisation uses.
At SECWATCH, we combine technical training and certifications with practical experience. We investigate vulnerabilities and explain what the findings mean for your organisation. This helps you make informed decisions about which measures need attention.
Our team represents a range of specialisations. Below is a selection of the certifications and training completed by our specialists. For each assignment, we match the expertise and approach to your environment and assessment question.
Penetration testing
During a penetration test, we investigate how vulnerabilities could be exploited and which further steps an attacker could take. We document the findings with supporting evidence and remediation advice.
- Hack The Box Certified Penetration Testing Specialist (CPTS)
- Mile2 Certified Penetration Testing Engineer (CPTE)
- OffSec Certified Professional (OSCP)
- EC-Council Certified Ethical Hacker (CEH)
- EC-Council Certified Security Analyst (ECSA) and Licensed Penetration Tester (LPT)
- GIAC Penetration Tester (GPEN) and GIAC Exploit Researcher and Advanced Penetration Tester (GXPN)
Web applications
Assessing web applications requires knowledge of application logic and how data is processed. OSWE focuses on source code review and the technical demonstration of vulnerabilities.
- OffSec Web Expert (OSWE)
- GIAC Web Application Penetration Tester (GWAPT)
Microsoft and cloud
Knowledge of configuration and administration helps explain how access rights, accounts and settings interact. We combine this foundation with knowledge of attack techniques in Microsoft cloud environments.
- Pwned Labs Microsoft Cloud Red Team Professional (MCRTP)
- Microsoft Certified: Azure Security Engineer Associate
- Microsoft Certified Solutions Associate (MCSA): Office 365
- Microsoft Certified Solutions Associate (MCSA): Windows 10
- Microsoft Certified Solutions Associate (MCSA): Windows Server 2012
OT and industrial systems
Operational technology (OT) and industrial control systems (ICS) have their own technical and operational context. These courses cover how industrial systems work and the security issues involved.
- CambiOS Academy: Introduction to OT/ICS Fundamentals (OTCS-0103)
- CambiOS Academy: OT/ICS Fundamentals (OTCS-0201)
- CISA: Advanced Cybersecurity for Industrial Control Systems (ICS300)
Wireless networks and radio technology
Assessing wireless networks requires knowledge of the protocols and security settings in use. Amateur radio training adds knowledge of radio technology.
- OffSec Wireless Professional (OSWP)
- GIAC Assessing and Auditing Wireless Networks (GAWN)
- Radiozendamateur Novice (RZAM-N)
Additional expertise
Alongside technical assessments, our specialists have knowledge of information security management, privacy, threat intelligence and private investigation. Additional technical training supports further development of assessment methods.
- Certified Information Security Manager (CISM)
- Certified Information Privacy Manager (CIPM)
- Certified Information Privacy Professional/Europe (CIPP/E)
- Certified Threat Intelligence Analyst (CTIA)
- Private investigation (PDO)
- Advanced Penetration Testing (CAST 611) and Metasploit Advanced (CAST 617)
Working safely on site
Industrial sites also require attention to occupational safety and the applicable working instructions. The personal Basic Safety VCA diploma supports the knowledge needed to work safely.
- Basic Safety VCA (B-VCA)
We also use appropriate reference frameworks in our assessments, such as OWASP for web applications and IEC 62443 for industrial security.
What expertise does your environment require?
Tell us which systems and processes matter to your organisation. Together, we determine an assessment question and approach that fit.