Delivery Framework

Every engagement type Mitigence delivers — including activity type, timeline, phases, and deliverables. Understand the process before the first conversation.

17 engagement types across offensive security, engineering, compliance, and risk.

Offensive Security2–4 weeks

Penetration Testing

Adversary-simulated attacks exposing real exploitable paths before attackers find them.

5 phases · 6 deliverablesView →
Engineering / Architecture4–8 weeks

Cloud Security Engineering

Design and build security controls native to your cloud environment — not retrofitted from on-premises.

5 phases · 6 deliverablesView →
Identity Engineering4–6 weeks

Privileged Access Management

Control, audit, and enforce least-privilege access for every privileged account across your estate.

5 phases · 6 deliverablesView →
Risk & Compliance2–3 weeks

Third-Party Risk Assessment

Systematic evaluation of supplier and partner cyber risk before it becomes your incident.

5 phases · 6 deliverablesView →
GRC / Compliance8–16 weeks

Compliance Program

Build and sustain the controls needed to achieve and maintain regulatory certification.

5 phases · 6 deliverablesView →
Specialist Assessment2–3 weeks

Medical Device Security Assessment

Evaluate cyber risk in connected medical devices without disrupting clinical operations.

5 phases · 6 deliverablesView →
Risk Assessment1–2 weeks

Ransomware Readiness Review

Stress-test your defences and recovery capabilities against ransomware attack chains.

5 phases · 6 deliverablesView →
Identity Engineering4–8 weeks

Identity Security Engineering

Modernise identity infrastructure — authentication, authorisation, and lifecycle management.

5 phases · 6 deliverablesView →
Preparedness2–4 weeks

Incident Response Planning

Build the plans, playbooks, and capabilities to respond effectively when an incident occurs.

5 phases · 6 deliverablesView →
Compliance / GRC6–12 weeks

Security Accreditation Support

Expert-led preparation and support through formal security accreditation and certification processes.

5 phases · 6 deliverablesView →
Network Engineering4–8 weeks

Network Segmentation

Architect and implement network zones that contain breaches and eliminate lateral movement.

5 phases · 6 deliverablesView →
Risk Programme4–6 weeks

Insider Threat Program

Build detection, deterrence, and response capabilities for malicious and negligent insider scenarios.

5 phases · 6 deliverablesView →
Assessment2–4 weeks

Security Assessment

A comprehensive baseline evaluation of your organisation's security posture across people, process, and technology.

5 phases · 6 deliverablesView →
Engineering / Operations3–6 weeks

Endpoint Protection

Deploy and tune endpoint detection, response, and hardening controls across your entire estate.

5 phases · 6 deliverablesView →
Specialist Assessment2–4 weeks

OT Security Assessment

Assess cyber risk in operational technology environments without disrupting production systems.

5 phases · 6 deliverablesView →
Compliance Assessment3–6 weeks

PCI DSS Assessment

Scope, assess, and remediate against PCI DSS requirements for cardholder data environments.

5 phases · 6 deliverablesView →
Offensive Security / DevSecOps1–3 weeks

Application Security Testing

Uncover exploitable vulnerabilities in web, mobile, and API applications through targeted security testing.

5 phases · 6 deliverablesView →