Skip to content
CATO & VEILINTELLIGENCE & INVESTIGATIONS
Expertise
All expertiseCybersecurity & investigationsAI IntelligenceTransnational Repression
Clients
All clientsBlack Card
PeoplePramana
Training
All trainingMinervaInvestigation & fieldcraftCyber crisis war roomSocial engineeringNarrative & evidenceAI deception & insider riskQuintilian mentorshipPrivate team training
Insights
Confidential enquiry

PENETRATION TESTING / VULNERABILITY ASSESSMENT / THREAT MODELLING

Cybersecurity & investigations

Penetration testing, source-code review, vulnerability scanning and threat modelling. Specialist technical assessment, connected with Cato & Veil’s investigative expertise.

Scope a security assessment ↗Explore technical services ↓

Application / Infrastructure / Threat assessment

Test the systems. Examine the exposure. Investigate the incident.

Commission a defined penetration test, vulnerability assessment or threat-modelling engagement. Where a concern extends beyond the system, our cyber investigations team connects technical findings with the people, relationships and information involved.

Technical assessmentScope / 01—06
01Web & APIAuthentication / Authorisation
02Source codeLogic / Data flows
03NetworksServices / Exposure
04CloudAccess / Configuration
05Supply chainDependencies / CI/CD
06PeoplePhishing / Verification
Threat model→Test & assess→Prioritise fixes
Each engagement is defined individually.

Technical cybersecurity services

Know what is exposed.
Establish what to fix.

Assessments are scoped to your systems, access requirements and objectives. Cato & Veil coordinates the relevant technical specialists and the reporting you need.

01

Penetration testing & source-code review

Web applications · APIs · Mobile

Test application security with an understanding of the code behind it. Source-code review and manual testing examine authentication, authorisation, data flows and business logic. Web, API and mobile assessments are scoped to the application and the access available.

Output Documented vulnerabilities, supporting technical evidence and remediation guidance for developers.

02

Vulnerability scanning & management

Discovery · Assessment · Prioritisation

Identify known weaknesses across the agreed systems and services. Scanning establishes broad coverage; assessment helps prioritise the findings. For ongoing programmes, define ownership, review cycles and remediation tracking around the organisation’s existing tools and resources.

Output Prioritised findings and a practical process for managing unresolved vulnerabilities.

03

Network, cloud & configuration assessments

Internal networks · External exposure · Cloud

Assess the security of agreed network and cloud environments. Examine exposed services, access arrangements and configurations, with the testing boundaries and access requirements established before work begins.

Output A technical account of identified weaknesses, affected systems and recommended changes.

04

Threat modelling

Architecture · Data flows · Trust boundaries

Work with development and architecture teams to identify important assets, plausible attack paths and gaps in security controls. A structured model helps prioritise design decisions and further testing as the system changes.

Output A documented threat model, prioritised risks and recommendations for the team responsible for the system.

05

Software supply-chain security

Dependencies · CI/CD · Integrations

Review the software components and delivery processes an application depends on. Assess dependency management, build pipelines, secrets handling and third-party integrations to identify where the supply chain introduces exposure.

Output Findings tied to the relevant dependencies, pipelines and integrations, with recommended improvements.

06

Phishing & social-engineering assessments

Agreed phishing simulations · Verification · Reporting

Use scoped phishing assessments to examine how staff and processes respond to deceptive communications. Connect the results with Cato & Veil’s understanding of impersonation, authority and trust to identify practical improvements to verification and escalation.

Output An assessment of the agreed exercise and recommendations for stronger processes and staff awareness.

From scope to remediation

A defined test.
Findings you can act on.

  1. 01 / Scope

    Agree the systems and objectives.

    Define applications, infrastructure, testing boundaries, access, timing and deliverables. Source-code-led testing requires access to the relevant code and environment.

  2. 02 / Assess

    Examine the relevant controls.

    Apply the agreed testing, scanning, code-review or threat-modelling methods. Record technical evidence, coverage and limitations.

  3. 03 / Prioritise

    Explain the fixes and their significance.

    Deliver prioritised findings and remediation guidance with a debrief. Follow-up testing and ongoing vulnerability management can be scoped around the work required.

Cyber investigations / The Cato & Veil approach

The technical finding
is part of the wider picture.

An access-control weakness, suspicious account activity or a deceptive payment instruction can raise questions about people, money and intent. A named investigation lead brings the relevant disciplines together from the outset.

Information theft & ransomware-related enquiries

Examine the available evidence of access, information loss and extortion alongside the organisation’s relationships and sensitive interests. Coordinate investigative enquiries with the technical response and the client’s advisers.

Insider concerns & misuse of access

Investigate suspected information leakage, concealed interests and misuse of permissions. Compare records, witness accounts and relevant relationships, testing compromised access, error and deliberate involvement as competing explanations.

Impersonation & cyber-enabled fraud

Connect deceptive communications, account activity and financial events. Examine how an instruction became credible, who acted on it and where the evidence leads.

Exposure & emerging concerns

Assess a suspicious sequence, supplier dependency or concern about sensitive information before the full picture is clear. Scope specialist security testing where a technical question needs examination.

Evidence / Context / Consequences

Connect the records.
Test the explanation.

Technical findings direct interviews and background enquiries. Human accounts are checked against system records and communications. Financial analysis can establish how a disputed instruction connects to a transaction.

We also examine the narrative the evidence could support: what exposed information establishes, how selective extracts might distort it and where it conflicts with the organisation’s assurances. This helps leadership distinguish a misleading impression from a substantive problem that needs addressing.

Findings support the client’s legal and communications advisers and identify practical improvements to access, supplier oversight and decision-making.

What you receive

Technical detail.
Clear priorities.

Deliverables are agreed around the engagement: a technical assessment for a defined security test, or an integrated evidence assessment where a wider investigation is required.

  • The systems examined, methods used and limits of the assessment.
  • Prioritised technical findings with supporting evidence and remediation guidance.
  • A documented threat model where threat modelling is commissioned.
  • For investigations, a chronology connecting relevant technical, human and financial evidence.
  • A debrief explaining the findings, outstanding questions and next steps.
Technical services ↑Discuss the scope ↗

A confidential first conversation

What do you need to test or investigate?

Tell us about the application, environment or incident. We will discuss the appropriate assessment, specialist team, access requirements and deliverables.

Discuss cybersecurity ↗
CATO & VEILGlobal intelligence & investigations.Part of Praetorian Global ↗
© 2026 Cato & Veil
CybersecurityAI corporate intelligenceAI talent intelligenceTransnational repressionCase studiesPeopleOur groupPramanaTrainingSpeakingThe Cato BriefPrivacyContact
London · Dubai · Hong Kong · Mumbai · Sofia