About NullSec

We find what is not there.

The safeguard nobody switched on. The old server nobody switched off. The setting someone meant to fix and never did. Break-ins tend to live in the gaps — the things that were never there — and that is exactly the blind spot routine testing walks straight past.

Who’s behind it

A young company, run by people who aren’t new to this.

NullSec has spent two years working in this industry — a small, focused firm with no layers between you and the person actually testing your systems.

The founders are not two years into the field. They come from years on both sides of the fight — breaking into production systems as testers and red-teamers, and defending them from the inside — long before starting NullSec. That experience is the bar every engagement here is held to.

So whoever picks up your project has done this work for a living, not read about it in a course. The company is young on purpose; the people running it are not.

2 years

in the industry as NullSec

Founder-led

senior hands on every engagement

Both sides

offensive and defensive backgrounds

No middlemen

you talk to the tester, not an account manager

What we believe

Four things we will not compromise on.

If we can’t prove it, we don’t report it.

Every weakness we flag comes with a clear demonstration of how we got through. No padding a report to look busy, and no scary-sounding items we can’t actually back up.

A tool can’t replace a person trying to break in.

We run the automated scanners on day one, then get to work. The findings that matter are the ones only a curious human spots — the odd assumption, or the small bug that turns serious once it’s chained with two others.

A report nobody understands is a report nobody fixes.

One in-depth report: an executive summary the budget-holders can follow, then the technical detail your engineers act on — clear enough to fix straight from.

Done means done.

We recheck your fixes at no extra cost. The job isn’t finished — and any certificate we issue isn’t issued — until the problem is genuinely gone.

A look inside

How the work actually happens.

Two testers reviewing findings together at a workstation
Source code and a request being inspected by hand
An engineer mid-engagement, headphones on, deep in a target
0+
Security tests completed
0+
Weaknesses found and reported
0%
Fixes that passed our recheck
0 days
Typical wait for your report

The team

Qualified, and still hands-on.

Certificates get us in the room; the work is what keeps us there. Our testers hold the qualifications below and are judged on what they deliver, not on what’s framed on the wall.

CEH badgeOffensive

Certified Ethical Hacker

Broad offensive methodology and tooling across the attack lifecycle (EC-Council).

eJPT badgeOffensive

eLearnSecurity Junior Penetration Tester

Hands-on entry-level penetration testing fundamentals (INE).

CPTS badgeOffensive

Certified Penetration Testing Specialist

Hands-on, report-driven penetration testing end to end (Hack The Box).

CPENT badgeOffensive

Certified Penetration Testing Professional

Advanced pentesting: pivoting, evasion, IoT and OT targets (EC-Council).

LPT badgeOffensive

Licensed Penetration Tester (Master)

Expert-level, multi-stage exploitation under time pressure (EC-Council).

CRTP badgeOffensive

Certified Red Team Professional

Active Directory attacks and red-team tradecraft (Altered Security).

OSCP badgeOffensive

Offensive Security Certified Professional

Hands-on network and web exploitation — a 24-hour practical exam.

CISA badgeAudit

Certified Information Systems Auditor

Auditing information systems, controls, and processes (ISACA).

ISO 27001 LA badgeAudit

ISO/IEC 27001 Lead Auditor

Auditing an information security management system (ISMS).

ISO 9001 LA badgeAudit

ISO 9001 Lead Auditor

Auditing a quality management system (QMS).

ISO 20000-1 LA badgeAudit

ISO/IEC 20000-1 Lead Auditor

Auditing an IT service management system (ITSMS).

ISO 42001 LA badgeAudit

ISO/IEC 42001 Lead Auditor

Auditing an AI management system (AIMS).

Talk to the person who’d do the work.

Not a salesperson with a script — the tester who would actually run your project, answering your questions directly.

Book a scoping call