Simor Assurance
AI security assessments and governance readiness.
Independent verification — because the team that builds a system cannot be the team that certifies it.
OWASP
LLM Top 10 coverage baseline
3
Regulatory frameworks mapped
100%
Findings shipped with remediation plans
01 Capabilities
What this division does
Adversarial testing
Red-team exercises probing your AI system for prompt injection, jailbreaks, data exfiltration, and indirect attack vectors. We use the OWASP LLM Top 10 as a baseline and go beyond it.
Governance readiness
Gap assessments against ISO 42001, EU AI Act, and UK AI Code of Practice. We produce evidence packages and remediation roadmaps — not just audit findings.
Threat modelling
Structured threat modelling sessions mapping your AI architecture to adversarial surfaces. We identify attack paths before they become incidents.
Compliance preparation
Translating regulatory requirements into engineering tasks. NCSC guidelines, EU AI Act obligations, and sector-specific rules mapped to concrete controls you can implement.
02 Approach
How this division works
Independence is non-negotiable. We do not certify systems built by other Simor divisions. This separation of duties is a deliberate governance choice.
Testing is adversarial and realistic. We use the same techniques as real attackers, not academic checklists.
Every finding includes a remediation path with effort estimates and priority ranking. We do not hand you a list of problems and walk away.
03 Use cases
Where this division delivers
Pre-deployment security review
Full adversarial assessment of a production AI system before launch: prompt injection testing, data exfiltration probing, supply-chain review, and OWASP LLM Top 10 coverage with remediation roadmap.
ISO 42001 readiness
Gap assessment against the AI Management System standard, evidence package preparation, and remediation plan prioritised by certification timeline.
EU AI Act classification
Risk-tier classification of your AI systems, obligation mapping, and technical documentation preparation for high-risk system compliance.
04 Lifecycle
Position in the lifecycle
Simor Group covers the full AI infrastructure lifecycle. This division operates at the Verify stage.
05 Services
Full service list
- AI security assessments and threat modelling
- Adversarial testing and red-teaming
- Penetration testing of AI systems (OWASP LLM Top 10)
- ISO 42001 (AI Management System) readiness assessments
- EU AI Act compliance preparation
- UK AI Cyber Security Code of Practice alignment
- NCSC guidelines mapping
- AI governance framework design
Governance note
Simor Assurance provides readiness assessments and evidence preparation. It does not formally certify systems built by another Simor division. This separation of duties is a deliberate governance choice.
07 Engage
Work with Assurance
Tell us about your system, your timeline, and your constraints. We will come back with a scoping conversation — not a sales pitch.