Dimension scores are derived from public data and fields; weighted into the composite. Reference only.
Tough Times Consulting positions itself as a provider of “practical security testing and IT consulting,” helping organizations identify exploitable paths before attackers do. Rather than offering a standalone tool, it delivers human-led security assessments and consulting across web applications, external attack surface, cloud and identity risk, adversary simulation, pre-release validation, retesting, and ongoing assurance.
In terms of protection focus, Tough Times Consulting leans toward offensive validation and risk confirmation. Its web application penetration testing covers APIs, authentication, authorization, sessions, and custom business logic. External infrastructure testing includes internet-facing systems, VPN portals, email security controls, and exposed services. Cloud and identity reviews focus on identity providers, conditional access, privileged roles, exposed storage, and misconfigurations. Delivery is service-based and can be arranged as project-based work, quarterly validation, or embedded consulting, with support for black-box, gray-box, and white-box approaches. For management and alerting, the official site emphasizes direct communication during testing, concise updates when significant risks are found, and reports that include an executive summary, technical reproduction steps, impact analysis, and prioritized remediation recommendations, along with retesting to confirm fixes.
The official site does not disclose pricing, packages, or payment methods, so it appears to use scope-based custom quotes. Suitable customers include SaaS and software product companies, financial and regulated environments, healthcare and data-sensitive organizations, public-sector bodies, mission-critical service providers, as well as private equity due diligence and post-acquisition validation scenarios. It is a good fit for teams that need more than compliance checkbox testing and want to validate real-world attack chains.
Its strengths are that scoping is built around business risk, trust boundaries, and attack paths; reports are useful for both engineering teams and management; and retesting creates a closed remediation loop, reducing the common problem of “delivery ends with the report.” The main limitation is the lack of public information: there is no visible detail on compliance certifications, staff credentials, SLAs, sample reports, pricing, or tool/platform integration capabilities. For organizations that require local compliance endorsements or fixed-price procurement, the upfront communication burden may be relatively high.
Access from mainland China is not discussed in the main content, and payment methods are also unknown. For cross-border procurement, buyers should additionally confirm contract terms, invoicing, time-zone communication, and data export requirements. Domestic alternatives in China include security service providers such as 奇安信, 启明星辰, 绿盟科技, 安恒信息, and 长亭科技. For international red teaming and high-end consulting, NCC Group, Bishop Fox, and Mandiant are worth comparing.
⚠ This review is compiled from public sources and does not constitute a purchase recommendation. Verify all facts on the vendor's official site. Verify on toughtimes.se official site.
toughtimes.se is an Sweden Security provider. TG4G tracks its product information, an overall rating of 6.0/10, and a China-accessibility score of Workable. Click "Visit Official Site" to reach toughtimes.se directly.