TIS // CAPABILITIES

Capability

Cyber Assurance & Testing

Independent testing that produces evidence which stands up to inspection — not just a certificate for the wall.

We test what you actually need tested — and we tell you if you're asking for the wrong thing.

Our testing services are tailored to your organisation. At the outset we make sure the testing you're seeking is actually what you need to assess your risk — not just the test you were told to buy.

Types of testing

  • Penetration testing — infrastructure and estate-level testing against real attacker techniques.
  • Web application testing — OWASP-aligned assessment of the applications your business runs on.
  • Wireless testing — your airspace, audited.
  • Mobile application testing — MAST-aligned assessment for iOS and Android estates.
  • Phishing testing — measured, ethical campaigns that turn your people into a control.
  • Red team testing — objective-driven exercises that test detection and response, not just prevention.

The testing roadmap — how we run every engagement

Transparent from NDA to data destruction. This is the process every TIS test follows:

  1. NDAs and scoping

    We exchange Non-Disclosure Agreements, then hold a scoping call to introduce the testers and support staff who will work on your test.

  2. Your objectives

    You explain what you want from the test and where it fits into your overall security management.

  3. History review

    We ask about previous testing, its impact, and the remediation steps you have taken since.

  4. Bespoke test plan

    We develop a test plan around your requirements, leveraging industry guidelines and standards including CSA CCM, MAST and OWASP.

  5. Scheduling

    We agree dates and times for the testing activity, and the timeline for report and debrief delivery.

  6. Testing, with live escalation

    We keep you informed throughout — and contact you immediately if we discover a critical vulnerability or evidence of exploitation.

  7. Hot wash-up

    When the testing phase completes we conduct a hot wash-up, then draft your report and presentation materials.

  8. Secure delivery and debrief

    Your report and debrief materials are delivered securely (never by email), with executive summaries and action plans, followed by a debrief session.

  9. Free retest

    Pay your invoice within 15 days and we retest any medium-or-above finding and up-issue the report to confirm closure.

  10. Three-month follow-up

    We follow up three months after completion to ensure remediation is progressing.

  11. Data destruction

    At the six-month point we destroy all test data — scan results, reports, everything — unless you ask us to retain it for planned further work.

Our data-handling discipline is policy, not preference: all test data is destroyed at six months, and reports are never delivered by email.
CSA CCMMASTOWASPRED TEAMFREE RETEST

Contact

Start a conversation in confidence.

No forms to qualify you, no sales sequence. Tell us what you're carrying and we'll tell you honestly whether we can help.

Contact TIS

hello@tisglobal.co.uk  ·  07385 292925  ·  London · Cheltenham · Corsham