About NullVector

Built to close the gap between security theatre and real protection

Most organisations have security tools. Far fewer have security programmes that would actually withstand a determined adversary. NullVector exists to bridge that gap, through honest assessment, practitioner-led delivery, and work that holds up under scrutiny.

We are a specialist firm. We do not try to be everything to everyone. We focus on three disciplines, managed security operations, offensive testing, and cloud hardening, and we do them to a standard we'd stake our reputation on.

10+
Years practitioner experience
247+
Organisations protected
0
Production incidents caused

The security industry has a habit of selling complexity and calling it capability. We think the opposite is true, clarity about what's exploitable, honest reporting on what matters, and no padding to justify the invoice.

// NullVector, founding principle
Our values

What we stand for

These are not aspirational statements. They are the filters through which we take on engagements, write reports, and advise clients.

01
Honesty above comfort

We tell clients what we find, not what they want to hear. If your security posture is poor, we say so clearly and explain why. If a proposed engagement won't give you useful information, we'll tell you that too, even if it costs us the work.

02
Practitioners do the work

Every engagement is executed by the same senior practitioners who scoped it. We do not use client engagements as training ground for junior staff. If a task requires a specific skill, the person with that skill is the one who performs it.

03
Scope is a commitment, not a ceiling

We scope precisely and price in writing before work begins. We do not expand scope mid-engagement to inflate the invoice. If we encounter something significant outside scope, we flag it immediately and discuss whether to include it, before we touch it.

04
Reports that drive action

A finding that cannot be acted on is not a finding, it is noise. Every vulnerability we report includes a prioritised, specific remediation step. We write separately for technical teams and for leadership, because the same words do not serve both audiences.

05
No conflicts, no vendor lock

We do not take referral fees from technology vendors. We do not recommend tools because they benefit us. Our advice is based solely on what is right for your environment, your team, and your threat model. We are agnostic by design.

06
Knowledge stays with you

Dependency on an external security firm is not a security posture, it is a liability. We aim to leave every client more capable than when we arrived. Our reports explain the 'why' behind every finding so your team understands the risk, not just the fix.

How we work

Our approach to every engagement

The security industry has made a habit of mystifying its own processes. We do the opposite. Every engagement follows a clear, documented sequence, and clients are kept informed at every stage.

01

Understand before proposing

We begin every engagement with a scoping conversation, not a sales call. We ask about your environment, your concerns, your existing controls, and what a good outcome looks like for you. Only then do we propose a specific scope and price.

02

Fixed scope, fixed price

You receive a written proposal defining exactly what will be tested, how, by whom, and for what price. There are no variable rates, no "time and materials" ambiguity, and no scope that expands without a signed amendment.

03

Transparent during the work

You are never left wondering what is happening. For ongoing engagements, you receive regular status updates. For incident response, you receive real-time communication. We do not disappear and emerge with a report three weeks later.

04

Reporting that earns its place

Our reports are written to be read and acted on, not filed. Executive summaries are genuinely concise. Technical findings include reproduction steps, business impact, and remediation guidance. We do not pad reports to make them look thorough.

05

Debrief and knowledge transfer

Every engagement closes with a live debrief, separately for your technical team and your leadership where appropriate. We walk through findings, answer questions, and make sure your team understands the underlying risk, not just the CVE number.

06

Post-engagement availability

Our responsibility does not end when we deliver the report. For 30 days following any engagement, our team is available to answer questions about findings as your engineers work through remediation. No additional charge.

Our commitments

What clients can expect

These are concrete, measurable commitments, not brand promises.

🔒
Strict confidentiality

All engagement data, findings, and client information is handled under strict NDA. We do not use client environments as case studies without explicit written consent. Client data is never retained beyond the engagement period.

⚖️
Fully authorised operations

Every offensive engagement is conducted under a signed rules of engagement document. We operate strictly within defined scope and carry professional indemnity insurance, operating within Australian legal and regulatory frameworks at all times.

📋
No padding, no inflation

We do not inflate severity ratings to make our work appear more valuable. A low-severity finding is reported as low severity. We do not manufacture urgency to drive additional spend. Our recommendations are based on your actual risk profile.

🎯
Right-sized engagements

We will tell you honestly if you do not need what you are asking for, even if that means a smaller engagement. A penetration test on a system with no sensitive data is not the right use of your budget. We will say so.

🌐
Vendor-agnostic advice

We have no commercial relationships with technology vendors. Tool recommendations are based entirely on fit for your environment. We will tell you when a free or open-source tool is the right choice over a commercial product.

📞
Accessible when you need us

Retainer clients have direct access to their assigned practitioner, not a helpdesk queue. For active incidents, our response SLA is under one hour at any time of day. You will not be triaged by a tier-one analyst in a security incident.

Credentials

Team certifications

Our practitioners hold industry-standard certifications across offensive security, detection engineering, and cloud security architecture.

OSCPOffensive Security Certified Professional
CISSPCertified Information Systems Security Professional
CISMCertified Information Security Manager
CEHCertified Ethical Hacker
GPENGIAC Penetration Tester
GCIHGIAC Certified Incident Handler
CCSPCertified Cloud Security Professional
AWS-SPAWS Security Specialty

Ready to work with a team that tells you what you actually need?

Start with a free 45-minute conversation. We'll give you an honest view of your current exposure, no obligation, no pitch.

Get in touch →