About NullSec
We find what is not there.
The safeguard nobody switched on. The old server nobody switched off. The setting someone meant to fix and never did. Break-ins tend to live in the gaps — the things that were never there — and that is exactly the blind spot routine testing walks straight past.
Who’s behind it
A young company, run by people who aren’t new to this.
NullSec has spent two years working in this industry — a small, focused firm with no layers between you and the person actually testing your systems.
The founders are not two years into the field. They come from years on both sides of the fight — breaking into production systems as testers and red-teamers, and defending them from the inside — long before starting NullSec. That experience is the bar every engagement here is held to.
So whoever picks up your project has done this work for a living, not read about it in a course. The company is young on purpose; the people running it are not.
2 years
in the industry as NullSec
Founder-led
senior hands on every engagement
Both sides
offensive and defensive backgrounds
No middlemen
you talk to the tester, not an account manager
What we believe
Four things we will not compromise on.
If we can’t prove it, we don’t report it.
Every weakness we flag comes with a clear demonstration of how we got through. No padding a report to look busy, and no scary-sounding items we can’t actually back up.
A tool can’t replace a person trying to break in.
We run the automated scanners on day one, then get to work. The findings that matter are the ones only a curious human spots — the odd assumption, or the small bug that turns serious once it’s chained with two others.
A report nobody understands is a report nobody fixes.
One in-depth report: an executive summary the budget-holders can follow, then the technical detail your engineers act on — clear enough to fix straight from.
Done means done.
We recheck your fixes at no extra cost. The job isn’t finished — and any certificate we issue isn’t issued — until the problem is genuinely gone.
A look inside
How the work actually happens.
The team
Qualified, and still hands-on.
Certificates get us in the room; the work is what keeps us there. Our testers hold the qualifications below and are judged on what they deliver, not on what’s framed on the wall.
OffensiveCertified Ethical Hacker
Broad offensive methodology and tooling across the attack lifecycle (EC-Council).
OffensiveeLearnSecurity Junior Penetration Tester
Hands-on entry-level penetration testing fundamentals (INE).
OffensiveCertified Penetration Testing Specialist
Hands-on, report-driven penetration testing end to end (Hack The Box).
OffensiveCertified Penetration Testing Professional
Advanced pentesting: pivoting, evasion, IoT and OT targets (EC-Council).
OffensiveLicensed Penetration Tester (Master)
Expert-level, multi-stage exploitation under time pressure (EC-Council).
OffensiveCertified Red Team Professional
Active Directory attacks and red-team tradecraft (Altered Security).
OffensiveOffensive Security Certified Professional
Hands-on network and web exploitation — a 24-hour practical exam.
Certified Information Systems Auditor
Auditing information systems, controls, and processes (ISACA).
AuditISO/IEC 27001 Lead Auditor
Auditing an information security management system (ISMS).
AuditISO 9001 Lead Auditor
Auditing a quality management system (QMS).
AuditISO/IEC 20000-1 Lead Auditor
Auditing an IT service management system (ITSMS).
AuditISO/IEC 42001 Lead Auditor
Auditing an AI management system (AIMS).
Talk to the person who’d do the work.
Not a salesperson with a script — the tester who would actually run your project, answering your questions directly.
Book a scoping call