Security Monster

Security that holds up in production

Security Monster is an independent cyber security consultancy based in the EU. We design, build and run security for organisations where it has to work: financial market infrastructure, public administrations, international institutions and global enterprises.

Talk to us

Services

From the design review to the terminal

We cover the whole security stack, and we stay until it runs: designs that get built, platforms delivered as code, and documentation your own teams can operate from.

Security architecture

High-level and detailed designs, security requirements and reviews for new platforms and large changes, aligned with your risk appetite.

SABSA, defence in depth, hub-and-spoke, zero trust

Cloud and edge security

Protection for public-facing and internal web applications: web application firewalls, reverse proxies, DDoS protection and next-generation firewalling, in Azure, at the edge and on-premises.

WAF and WAAP, OWASP, Azure, Cloudflare, Fortinet, Imperva, Apache

Identity, PKI and cryptography

Public key infrastructures, HSMs, smart cards and certificate lifecycle automation, and the authentication that depends on them.

SAML, OAuth, OpenID Connect, mTLS, key management, Let's Encrypt

Security engineering and DevSecOps

Security platforms built and operated as code, with automated pipelines and hardened infrastructure, so changes are repeatable and reviewable.

Terraform, Ansible, Kubernetes, Docker, Azure DevOps, Python, Go

Governance, risk and compliance

Risk assessments, audits, accreditation and security processes that translate technical risk into decisions the business can take.

ISO 27001 and 27005, NIS2, GDPR, COBIT, PCI DSS

AI in cyber security

AI works on both sides. We protect organisations against AI-driven threats, and we use AI to detect and counter attacks. For the past three years AI has also been part of our own security engineering: automation, infrastructure as code, reviews and documentation.

AI threat protection, AI-assisted defence, secure AI adoption

Experience

Thirty years of engagements

For more than 30 years we have designed, built and assured security for organisations in Europe and the United States, in these sectors.

  • Financial market infrastructure
  • Public administration
  • European institutions
  • International defence
  • Smart card and identity technology
  • Telecommunications
  • Automotive
  • Industry

Approach

Security is managing risk

Effective security needs deep technical knowledge and a clear view of the business around it. We are as comfortable in a design review as in a terminal or a boardroom.

Risk first

Every control should reduce a risk that matters. We start from what you need to protect and what it may cost.

Built, not just advised

We design it, build it and hand it over working, with the code and documentation to run it.

Independent

No product to sell. Decades of hands-on experience with many vendors lets us pick what fits.

Credentials

Certified and current

Certifications
CISSP, CISA, PCI QSA
Frameworks
SABSA, ISO 27000 series, NIS2, GDPR, COBIT, PRINCE2, Scrum
Cloud
Azure, AWS, Cloudflare, Hetzner, OVH, Scaleway
Platforms
Linux, Windows and networking, Kubernetes, Docker

Software

We also build software

Besides our security services, Security Monster builds and operates software products under the purplegreen.ai brand, with security designed in from the start.

MartialBook

The all-in-one app for martial arts clubs: attendance, ranks and belts, progress booklets, plans and payments.

purplegreen MDMPilot preparation

Device management for company-owned Android tablets that run as unattended kiosks. Being prepared for its first pilot; access on request.

DaedalusComing soon

A time tracker for Mac and iPhone that proposes your day's time entries from git commits, project folders and AI coding sessions.

Contact

Tell us what you need to protect

Describe the platform, the question or the deadline. We reply by e-mail, usually within one working day.