Cybersecurity Consultants Who Help Engineering Teams Ship Secure Products

Why is building a Secure Product so hard? It doesn’t have to be.

Who We Are…

Devious Plan is a hands-on cybersecurity consultancy that embeds with your engineering team to design, build, and pressure-test secure products. We guide development teams on their security journey with Security Architecture, Threat Modelling, Securing the public cloud, Security Training, and Penetration Testing.

We enjoy crafting solutions to interesting and tough problems through collaboration and information sharing.

Find Security Peace of Mind

1

We analyze
your situation

2

We create a
playbook for you

3

We help you execute
on the Playbook

Learn More

DEVIOUS PLAN SERVICES

All our services under one roof

DevSecOps

Devious Plan can support your DevSecOps methodology with experience in automation, continuous security testing, and fostering a culture of security awareness among all team members in an agile methodology.

Learn More

Threat Modelling

Threat Modelling during the design process helps developments teams design in compliance and Defence-in-Depth by proactively identifying potential security threats, threat actors, attack surfaces, and key targets.

Learn More

Security Architecture

Our experience in systematic security control design and implementation protects your organization's information, assets, and resources from evolving threats.

Learn More

Training

We have extensive experience sharing security domain knowledge crafted to individual team needs. Whether its tailored training to fill a skills gap after a pentest, secure coding workshops, or teaching your development team the “Dark Side”, we have the demonstrable experience to level up your team.

Learn More

Cloud Security

Devious Plan has demonstrated capabilities securing cloud infrastructures to create a resilient and secure cloud infrastructure that meets compliance requirements and safeguards against evolving cyber threats.

Learn More

Red Team Engagement

Our experience in industry-leading penetration testing methodologies (OWASP), including white-box, black-box, and grey-box testing simulate real-world cyber attacks on an organization's systems, applications, or networks.

Learn More

AI Security

We offer hands-on AI security testing for agentic systems, LLM apps, and “skills” marketplaces covering prompt injection, tool abuse, data leakage, and supply chain risk. Get a clear risk report, exploit proof-points, and practical fixes your engineers can ship. We can even help your team with their vibe coded creations.

DEVIOUS PLAN CLIENTS

Hear what our Partners have to say

Adam Lomas, CRISC

Head of Information Security,
Trust & Compliance
ManagedRisk

“Working with Devious Plan has meant access to the right skills at the right time, reducing the pressure to find and staff experts internally without compromising on speed, quality, or communication. From Security Assessments to Threat Modelling and risk-prioritized security roadmapping support tailored to the realities of each unique environment, Devious Plan has quickly and consistently delivered actionable ‘no nonsense’ insights focused on cost effective cyber-risk reduction.”

Blake Mitchel

Lead Consultant and Founder
Fevor Consulting

“I have collaborated closely with the Devious Plan team for over two years, consistently observing their exceptional work and significant impact on their clients and the industry. I am confident in their proficiency in guiding development teams through the complex cybersecurity landscape.”

Andrew Wilder

Regional CISO, Americas, Asia, & Europe

“Devious Plan provided a pragmatic, common-sense approach that found business value to deliver exceptional solutions. Their approach supported and helped upskill team members and others across the organization based on their deep security knowledge.”