FAQ
Questions we get asked a lot
If your question is not here, message the team — we would rather answer it directly than have you guess.
Certificates
It is issued by CyberKnight and lists the modules and lab work you completed, so it reflects what you actually did. It is not a substitute for vendor certifications like OSCP or CEH — it is evidence of practical work, which many employers weigh alongside them.
On completion of the course, including the assessed lab work. It is issued digitally and lists the specific modules covered.
Courses
Not for the beginner track. Cybersecurity Fundamentals assumes no prior security knowledge, no scripting and no certifications. Later courses build on it and state their prerequisites clearly.
Yes. They are isolated ranges we build and operate, segmented from the internet and from other students. You get real access to machines that exist to be compromised, and you can reset them to a clean state whenever you want.
On the remediation and the write-up at least as heavily as on the exploitation. Getting the flag is the start of the exercise, not the end — what we want is the fix you would ship and the reasoning behind it.
Payments
Message us and we will arrange the method that works for you. For engagements, fees and milestones are set out in the engagement contract before work begins.
If you have not started a course, contact us and we will deal with it reasonably. Once lab access has been issued and used, refunds are assessed case by case.
Security Testing
We take reasonable care and agree a testing window, and destructive tests are excluded unless you specifically ask for them. That said, security testing carries inherent risk, so have current backups before we start. Anything unexpected stops immediately — that is what the named contact is for.
No. We need authorisation from the owner. If you rent a platform or integrate with a third-party service, we can help you identify who needs to authorise what before any testing happens.
A scan lists things that might be vulnerable. A penetration test establishes what an attacker could actually do with them — including chains where several low-severity issues combine into full access. We use scans as one input; the work itself is manual.
Services
Yes, without exception. We require written authorisation from whoever owns the system, naming what is in scope, what is explicitly excluded, and the testing window. If that is not in place, the work does not start — regardless of deadline pressure.
WhatsApp and Telegram reach the team directly rather than a ticket queue, which is why we lead with them. For an active compromise, message us — we will tell you what to do in the next ten minutes before anything formal is agreed.
A written report with every verified finding, its severity based on real exploitability and impact, reproduction steps, and specific remediation guidance. Plus a call to walk through it, and a retest once you have made the fixes.
Yes — a lot of our work is with organisations that have no security team of their own. Scope can be sized to a sensible budget. We would rather assess three things properly than thirty superficially.
Support
For active incidents, as fast as we can — usually within the hour on WhatsApp or Telegram. For general enquiries, within one working day. A person reads every message; there is no autoresponder.
Anything involving access to systems, accounts, devices or data belonging to someone who has not authorised it — including recovering access to an account that is not yours, however the situation is described. The answer is always no, and we will not refer you to someone who would say yes.
Training
Yes. We build private lab ranges for internal security training, sized to your team's level and matched to the stack you actually run. Tell us both and we will propose a structure.
Course material is self-paced so you can fit it around work, with direct instructor support throughout — ask on WhatsApp or Telegram and a person answers, usually the same day. Private team training can include live sessions.