About Solusec

A small team, deliberately. The accreditation is the company’s, the work is delivered personally by a cyber security expert, not handed to a junior.

What we do

Cyber security isn’t one job, so we don’t sell one. Solusec works across the areas most organisations actually need — and joins them up, so you’re not stitching together three different suppliers:

Penetration testing is a large part of what we do, and where our research pedigree shows most clearly — but it’s one pillar of a broader practice. Whatever you come to us for, the same senior, plain-speaking standard applies.

Why we work this way

Solusec exists because of a pattern we kept seeing from the inside: organisations paying enterprise rates for work produced by someone three years into their career, with a senior name on the cover.

So we built the opposite. The accreditation is held by the company, independently audited, and the work is delivered personally by a cyber security expert. No account managers between you and the work, no junior analysts learning on your time, and no jargon that needs translating before anyone can act on it. As we grow, that standard holds: extra capacity and specialist skills come from a team of vetted senior experts, and increasingly our own hires, not anonymous or cut-price subcontracting.

We still cap what we take on, to protect quality. It is a deliberate trade, and it is why clients tend to stay with us for years rather than engagements.

Founder & Director

Daly Whyte

Founder & Cyber Security Consultant

Daly is the founder of Solusec, and leads the work it delivers. He started the company around a simple conviction: the expert who tests your systems should be senior, accredited and accountable, not a junior handed a scanner with someone else's name on the report. Everything about how Solusec runs follows from that.

Daly has worked both sides of the fence. Years spent breaking into systems on penetration tests, and years more building and leading the security programmes that defend them. Knowing how an attacker thinks is one thing; knowing what needs prioritising and the practical steps to fix it is another, and the two together are what make a report worth reading.

He has several CVEs to his name and is recognised for his responsible approach to vulnerability disclosure, with acknowledgements from organisations including SAP, Red Bull, Western Union, Carta and American Express. He is an active member of the Synack Red Team, an invitation-only group vetted on skill and trust, where he was inducted into the Acropolis in 2022 and has since earned Envoy, Hero, Olympian and Circle of Trust recognition.

Twenty-five years around computers, starting in development, moving through IT support, and into security, with the craft sharpened on CTFs, bug bounty work — over 500 valid findings to date — and thousands of hours of hands-on testing.

In practice it means Daly leads and stays accountable for every engagement, and you deal directly with the senior expert doing your work, from the first scoping call through to delivery and any retest. Where a job needs extra capacity or a particular specialism, it goes to one of the vetted senior experts on the team — never to a junior with a scanner, and never through an account manager in between.

Qualifications
PraCSP (Practitioner, UK Cyber Security Council), OSWE, OSCP, CREST CRT, CISSP, Centri CSOM, Centri BTL2, Security+, SecurityX and more: verify on Credly →
Disclosure
CVE-2024-48824, CVE-2024-48823, CVE-2024-48822, CVE-2024-48821, CVE-2024-46627, CVE-2024-45241, CVE-2026-82502, CVE-2026-82503, CVE-2026-82504 (pending publication)
Bug bounty
500+ valid findings across public and private programmes, over a 25-year career in technology
Recognition
Synack Red Team: Acropolis 2022, Envoy, Hero, Olympian, Circle of Trust

How we work with clients

Scoping conversations are free, and we would rather tell you that you need less than you asked for than sell you something you do not. If the honest answer is Cyber Essentials rather than a penetration test, or that you should fix your backups before commissioning anything, we will say so.

Retesting is included as standard, because identifying findings is only half the job. And where an engagement is annual (a contractual clause, a certification renewal), we diary it and contact you ahead of the anniversary rather than waiting to be chased.

Common questions

How big is Solusec?

Deliberately small and focused. Solusec is founded and led by Daly Whyte, working with a team of vetted, similarly-qualified experts we bring in as scope and specialism require, and growing it as we scale. We take on only what we can deliver properly, which is the point: you get an accredited senior expert rather than whoever happened to be available.

Who will actually do my work?

A named, suitably qualified expert before you commit, and the same person with you from the first call through to delivery. For a penetration test that's a CREST-qualified tester; for certification, a certified IASME assessor. Depending on scope and specialism it will be Daly or one of the senior experts on the team — never a junior, and never anonymous. You always know exactly who is doing your work.

Is the CREST accreditation held by the company or an individual?

The company. Solusec is CREST accredited at company level, which means our methodology, reporting, data handling and staff competence have been independently audited. You can verify it on the CREST marketplace. Individual certifications are held on top of that, not instead of it.

What happens if you are busy when I need you?

We will tell you honestly rather than take the work and squeeze it. Standard lead time is two to three weeks, often under a week at short notice for a contained scope. If your deadline is not achievable we say so on the first call.

Who do I contact about invoices or paperwork?

Daly, the same person who runs your engagement. Contracts, scheduling, invoicing, security questionnaires and technical questions all reach one place, so nothing gets lost between departments.

Related

Ready to talk?

Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.