About

We got tired of
watching good teams lose to a phone call

AwareXone is a security consultancy built around the part of the attack surface that everyone acknowledges and almost nobody defends properly: the people.

fig. 01The attack surface that answers
01The gap

Walk into most organisations and you will find real money spent on detection, identity and response, alongside a security awareness module people click through once a year. Then read the incident reports. Almost every one starts the same way: somebody was convinced.

02What changed

That gap was survivable for a long time, because convincing people at scale was expensive and attackers had to choose their targets. That constraint is gone. A model now writes a flawless, personalised pretext for every one of your employees, clones a voice from a webinar recording, and joins a video call wearing a face your finance team trusts.

03Where we sit

AwareXone exists for that shift. We attack organisations the way this generation of adversary does, rebuild the judgement those attacks depend on defeating, and harden the systems standing behind the person who picks up the phone. Penetration testing, advisory and exposure removal are not a separate business line - they are the rest of the same attack path.

04Why part of it is free

The organisations targeted hardest are often the ones least able to pay anybody, so we fund an open source program alongside the consultancy: tools, playbooks, research and free sessions, released without a catch. It is the only part of this work that scales past the clients we can personally serve.

What we believe

Four positions everything else follows from

01

People are not the weakest link

They are the most targeted one, which is a different claim. Systems fail silently; people notice things and report them. Treat staff as sensors to be equipped rather than liabilities to be trained at, and the numbers move.

02

Blame destroys security

The moment somebody fears the consequence of admitting a mistake, your detection time collapses. Every part of our reporting is designed so that owning up is the easiest available option.

03

Evidence beats assertion

We would rather show a client a working attack chain than assign a severity rating to a hypothetical. If something we predicted does not reproduce, it does not go in the report.

04

Defence should not be a luxury

The groups least able to absorb a fraud loss are targeted the hardest. Reserving engineering time for free tooling is not marketing for us, it is a condition of the work being worth doing.

What we are not

The short list

  • We do not resell products or take vendor commission.
  • We do not sell a platform subscription and call it a program.
  • We do not send a junior to deliver what a partner sold.
  • We do not name individuals who fail a simulation.
  • We do not manufacture severity to justify an invoice.
  • We do not test anything without written authorisation.
How we operate

The practical details

Engagement modelRemote-firstOn-site for workshops, physical testing and executive briefings
LanguagesMulti-lingualSimulations and training localised to the workforce being tested
Sector focusFinance, health, educationPlus any organisation where one approval moves real money
Minimum size20 peopleBelow that, our free community program is usually the better fit

Start with the uncomfortable part

A free thirty-minute review of what an attacker can already learn about your organisation, and the pretexts that follow from it.

Start the review