Why Safestorm exists
Help organisations understand which weaknesses can actually be exploited, what those weaknesses mean and what to fix first—through independent, founder-led testing.
Security philosophy
Testing should reflect realistic attacker behaviour while remaining controlled, authorised and proportionate. Clear evidence matters more than finding counts.
Professional approach
Scope, communications and safety boundaries are agreed before testing. Findings are handled sensitively and shared only with authorised stakeholders.
Founder
Felix is the founder of Safestorm, a UK cybersecurity consultancy providing practical, evidence-led penetration testing and offensive security assessments. He has more than six years of experience across red teaming, adversary simulation, enterprise infrastructure, Active Directory, web applications, cloud environments and security-control validation. His approach focuses on realistic attack techniques, manual validation and identifying weaknesses that could genuinely be exploited. Findings are translated into clear evidence, business context and practical remediation guidance. Felix holds the OSCP and OSEP certifications. In 2025, he presented research at BSides London on the risks created by under-monitored IPv6 environments within corporate networks. He founded Safestorm to provide technically rigorous, founder-led testing with clear communication, professional delivery and a strong focus on measurable security improvement.
Technical profile
Experience that follows the whole attack path
Identity and enterprise systems
Active Directory, Kerberos, NTLM, directory permissions, delegation, certificate services, endpoint privilege, network segmentation and lateral movement.
Applications and cloud
Web applications, APIs, authentication, authorisation, business logic, cloud IAM, service identities, exposed data and control-plane attack paths.
Adversary-informed testing
Red teaming, adversary simulation and security-control validation inform assessments that test how weaknesses combine—not just whether they exist.
Research and communication
OSCP and OSEP certified. Speaker at BSides London 2025 on the risks created by under-monitored IPv6 in corporate networks.
Founder experience includes identifying high-impact weaknesses in healthcare environments. Details remain confidential.
From finding to fix
Reports pair reproducible technical evidence with prioritised remediation. A technical debrief and optional retesting support teams after delivery.