Professional services

Practical security and SOC expertise, free where capacity allows.

Security Aid helps organisations improve monitoring, detection, incident readiness and security control architecture. Web application penetration testing is also available as a specific testing service. The limits on free work are eligibility, scope and available capacity.

How services are delivered

Clear gaps. Practical priorities. No product sales pitch.

Where Security Aid accepts a free request, the aim is to provide useful professional advice based on the organisation's controls, telemetry, processes and evidence. Outputs focus on material gaps, operational impact and proportionate next steps.

Security Aid only advertises penetration testing for web applications. Any web application test requires explicit written authorisation, an agreed scope and rules of engagement before testing begins.

Organisations that need guaranteed capacity, ongoing support, defined response expectations or platform features can use memberships. Membership revenue helps fund free work elsewhere.

Free support may be available

Security & SOC Advisory

Independent advice on SOC capability, security operations, monitoring, controls and practical security decisions.

Security Aid reviews how security is governed and operated across people, process and technology. Advice can cover SOC operating models, monitoring strategy, detection priorities, incident workflows, Microsoft and cloud security, control design and security roadmaps. Recommendations are intended to be evidence-led, proportionate and usable, not a product sales pitch.

Free advice depends on available capacity. Memberships provide reserved advisory access and defined support expectations.

Free support may be available

SOC, SIEM & Detection Reviews

Assess whether security telemetry, alerting, detections and operational workflows cover the threats that matter.

Reviews can examine SIEM architecture, log-source onboarding, telemetry quality, retention, detection use cases, alert fidelity, triage, escalation, tuning, threat coverage and engineering backlog. The output is a prioritised view of visibility and detection gaps, with practical actions for improving monitoring capability.

Free reviews are capacity-limited. Memberships can reserve ongoing review and detection-engineering time.

Free support may be available

Security Control Gap Analysis

Identify material gaps across identity, endpoint, cloud, monitoring, response, resilience and governance controls.

Security Aid can compare existing controls and evidence against the organisation's risks, operating model and relevant good practice. The review focuses on control effectiveness rather than checkbox compliance and produces risk-ranked gaps, quick wins, target-state recommendations and a proportionate improvement roadmap.

Free gap analysis is subject to scope and capacity. Memberships can provide recurring control reviews and progress tracking.

Free support may be available

Security Control Architecture Reviews

Review how security controls fit together and design a practical target state for monitoring and protection.

Security Control Architecture Reviews examine how identity, endpoint, network, cloud, data, logging and response controls work together. Security Aid can review proposed or existing designs, identify control gaps or duplication, define security requirements and produce phased target-state recommendations without assuming that more tooling is always the answer.

Free architecture support is subject to scope and capacity. Memberships can reserve ongoing architecture and advisory time.

Free support may be available

Microsoft Security Reviews

Review Microsoft 365, Entra ID and Defender controls, monitoring and remediation priorities.

Microsoft Security Reviews can cover identity, MFA, Conditional Access, privileged access, Defender products, attack surface reduction, mail protection, audit logging, alerting and incident workflows. The focus is evidence-led control effectiveness, detection coverage and clear remediation, not unnecessary tooling.

Free Microsoft review support depends on capacity. Memberships can include ongoing posture tracking and reporting.

Free support may be available

Incident Response Advisory & Readiness

Improve incident readiness, triage, containment decisions, evidence preservation and response coordination.

Security Aid can review incident plans, roles, escalation paths, logging readiness, containment options, evidence handling and communication priorities. During an incident, advisory support may help teams structure decisions and next steps, but free support cannot guarantee emergency availability or replace a contracted forensic response service.

Emergency availability is not guaranteed for free users and depends on capacity. Memberships can define response expectations.

Free support may be available

Supplier & Third-Party Security Reviews

Review third-party security controls, supplier evidence, monitoring expectations and outsourced IT risk.

Many SMBs rely on external IT providers, SaaS platforms and other critical suppliers. Security Aid helps review access control, MFA, logging, data handling, backup responsibility, breach notification, assurance evidence and the controls needed to monitor outsourced services.

Supplier review help is capacity-limited. Memberships can include deeper assurance workflow and reporting.

Free support may be available

Web Application Penetration Testing

Manual security testing focused specifically on web applications and realistic application-layer attack paths.

Where accepted into the free programme, web application testing can include scoping, written authorisation, rules of engagement, manual and authenticated testing where appropriate, evidence-led findings, remediation guidance and agreed retesting. Security Aid does not advertise general infrastructure penetration testing.

Free engagements are subject to eligibility, scope and available capacity. Memberships are for guaranteed capacity and ongoing support.

Free support may be available

Security Awareness Training

Reduce everyday risk with free role-aware training guidance that turns security advice into practical habits.

Security Aid can provide awareness guidance, phishing readiness material, executive briefings and staff playbooks for common threats such as business email compromise, ransomware, credential theft and data handling mistakes.

Free awareness support is available where capacity allows.

Free support may be available

Cyber Security Talks & Workshops

Free practical cyber security talks and workshops for SMBs, students and community groups.

Security Aid supports accessible cyber security talks, workshops and awareness sessions for SMBs, education groups and community audiences. Previous speaking experience includes presenting at the UK NCSC HQ and at Oxford University to STEM students. The aim is to widen access to practical cyber security understanding.

Community and SMB-focused sessions are provided free where capacity allows.

Free support may be available

Cyber Essentials Readiness

Guidance on understanding Cyber Essentials requirements, identifying gaps and preparing for certification.

Security Aid can help organisations understand Cyber Essentials requirements, identify gaps and build a practical remediation plan before certification. Security Aid does not present itself as a certification body.

Security Aid can help prepare for certification but does not claim to issue Cyber Essentials certification.