Skip to content
Safestorm
Menu

About Safestorm

Practical security, clearly communicated

Safestorm is a founder-led UK cybersecurity consultancy focused on realistic testing and useful outcomes.

Why Safestorm exists

Help organisations understand which weaknesses can actually be exploited, what those weaknesses mean and what to fix first—through independent, founder-led testing.

Security philosophy

Testing should reflect realistic attacker behaviour while remaining controlled, authorised and proportionate. Clear evidence matters more than finding counts.

Professional approach

Scope, communications and safety boundaries are agreed before testing. Findings are handled sensitively and shared only with authorised stakeholders.

Founder

Felix is the founder of Safestorm, a UK cybersecurity consultancy providing practical, evidence-led penetration testing and offensive security assessments. He has more than six years of experience across red teaming, adversary simulation, enterprise infrastructure, Active Directory, web applications, cloud environments and security-control validation. His approach focuses on realistic attack techniques, manual validation and identifying weaknesses that could genuinely be exploited. Findings are translated into clear evidence, business context and practical remediation guidance. Felix holds the OSCP and OSEP certifications. In 2025, he presented research at BSides London on the risks created by under-monitored IPv6 environments within corporate networks. He founded Safestorm to provide technically rigorous, founder-led testing with clear communication, professional delivery and a strong focus on measurable security improvement.

Technical profile

Experience that follows the whole attack path

Identity and enterprise systems

Active Directory, Kerberos, NTLM, directory permissions, delegation, certificate services, endpoint privilege, network segmentation and lateral movement.

Applications and cloud

Web applications, APIs, authentication, authorisation, business logic, cloud IAM, service identities, exposed data and control-plane attack paths.

Adversary-informed testing

Red teaming, adversary simulation and security-control validation inform assessments that test how weaknesses combine—not just whether they exist.

Research and communication

OSCP and OSEP certified. Speaker at BSides London 2025 on the risks created by under-monitored IPv6 in corporate networks.

Founder experience includes identifying high-impact weaknesses in healthcare environments. Details remain confidential.

From finding to fix

Reports pair reproducible technical evidence with prioritised remediation. A technical debrief and optional retesting support teams after delivery.