← All case studies

Shaping offensive security integration for an investor-backed group

A confidential advisory engagement with a private equity-backed cyber security group bringing together specialist pentest and red-team businesses.

By Simon Chapman

Broader integration priorities

People, delivery and technology were considered together when shaping how the acquired businesses should operate.

Documented risks and actions

Specific staff-retention and delivery risks were documented with concrete leadership actions.

A position on AI and tester oversight

A detailed paper set out how AI could support the pentest lifecycle while retaining experienced human control.

Simon's account of an advisory engagement, based on engagement notes and a paper he produced. The client is anonymised for confidentiality.

I was brought in to advise a private equity-backed cyber security group as it planned the integration of specialist pentest and red-team businesses. Offensive security was a core capability within the wider group, and the acquisition strategy was already clear.

My work focused on helping the leadership team shape how the acquired businesses would operate together: service delivery, technical staff retention, sales enablement and the supporting technology. The aim was to anticipate integration problems before they became embedded.

Preserving the capability being acquired

The businesses brought different delivery methods, tools, cultures and levels of maturity. Bringing them together created choices about what to standardise, what to preserve and how much change the teams could absorb while continuing to serve clients.

I identified that the integration risk extended beyond systems. Retaining experienced pentesters and keeping delivery stable were central to preserving the capability the group was acquiring.

The risks included unclear leadership, excessive utilisation, unstable scheduling, weak sales handovers, poorly defined scopes and missing client prerequisites. These were risks to address in the operating model, rather than a claim that every acquired business had each problem.

I pushed for visible leadership and early engagement with technical teams, with practical attention to progression, workload and the friction consultants encountered in delivery.

Choosing what to standardise

My recommendation was to standardise the things that materially improved delivery while avoiding an over-complex common platform at the outset.

Shared technology needed to serve the work. The question was which capabilities would help teams deliver and support sales, and which decisions could wait until the requirements were clearer. For portals and tooling, I advocated a pragmatic combination of buying and building, starting with the minimum useful capability.

That approach still left important choices for the leadership team. It required a view of where consistency would help, where specialist practices should remain distinct and how shared services would interact with the acquired businesses.

My advisory responsibility

I advised the leadership team on offensive security integration, technical staff retention, service delivery, sales-to-delivery interaction, tooling and portal strategy. I helped shape the proposed operating model and how the acquired capabilities could support cross-selling.

My role was advisory, focused on shaping decisions and the proposed operating model with an operational and technical perspective.

I also produced a detailed paper examining the existing pentest process and how AI could support tooling, analysis and reporting throughout the testing lifecycle.

My position was that AI should augment experienced testers while preserving their judgment and oversight. Scope control, interpretation and the ability to challenge incorrect outputs remained essential. Tool selection therefore needed to consider the tester’s role and the implications of using client data as well as the potential for automation.

What the work contributed

The integration discussion broadened to consider people, delivery and technology together. Specific staff-retention and delivery risks were documented with concrete leadership actions, and the AI paper gave the group a documented position on supporting the pentest lifecycle while retaining human control.

As the engagement developed, discussions became more specific about portal capability, structured findings, workflow automation, AI-assisted testing, pricing expectations and data strategy.

Decisions still to resolve

The final operating model, the extent of tooling standardisation, longer-term portal build-versus-buy choices and the data implications of AI use remained open.

The work gave those decisions a clearer operational basis: how to preserve specialist capability and dependable client delivery while building a wider business.

Discuss the decisions ahead.

Tell us about the practice and the changes you are considering. We can discuss the responsibilities, evidence and support the situation needs.