TLP:CLEAR  ·  distribution unlimited
Security Assessment Report

Target: Craig Donkin

An independent assessment of one cyber security consultant. Testing conducted continuously since 2011.

ReferenceCD-2026-001
TargetCraig Donkin, Cyber Security Consultant & Penetration Tester
Current engagementSenior Manager, KPMG Canada
Assessment window2011 – present (ongoing)
Prepared forProspective clients, employers, and the professionally curious
ClassificationPublic

0.0 Contents

1.0 Document Control

Version Date Change description
v0.12008Initial build: BSc (Hons) Computing and Geography, University of Manchester
v1.02011Offensive security module enabled: joined Context Information Security as a penetration tester
v2.02020Migrated to Canadian infrastructure: joined KPMG Canada as Manager
v3.02025Privilege escalation successful: promoted to Senior Manager

2.0 Executive Summary

Craig is a cyber security consultant specialising in penetration testing, with over fourteen years of hands-on offensive security experience. Today he co-leads KPMG Canada's offensive security practice as a Senior Manager.

He is a subject matter expert in application penetration testing (web, API and mobile), but also has extensive infrastructure testing experience, honed on the floors of many a UK data centre. Since 2021 he has been deploying that experience: creating scoping guides, testing methodologies and report templates, and maintaining high standards for the offensive security practice.

3.0 Key Findings

CD-001 Extensive offensive security track record Critical
Description
The target has performed penetration testing continuously since 2011, across two countries and organisations ranging from boutique consultancy to Big Four.
Impact
Over fourteen years of offensive security experience, developed against client environments across a wide range of sectors, from small boutique firms to UK government departments and some of the financial world's biggest organisations.
CD-002 Confirmed privilege escalation path High
Description
Escalation from Security Consultant (2011) through Lead and Senior Consultant, then Manager to Senior Manager (2025) was achieved without any exploitation of trust, only the repeated demonstration of it.
Impact
Over a decade of sustained delivery quality, client confidence, and increasing leadership responsibility.
CD-003 Force multiplier: builds the tooling others test with Medium
Description
Beyond hands-on testing, the target has repeatedly built the systems a practice runs on: a library of 140+ templated findings, bilingual (English/French) report templates, an automated reporting solution, and web and mobile testing methodologies grounded in OWASP, MASVS and ASVS.
Impact
Lifts the quality and consistency of every tester around him, not just his own output.
CD-004 Application security specialism & team leadership Info
Description
Deep specialism in application security (web, mobile and API penetration testing), paired with line management and technical leadership of testing teams, including QA, peer review and mentoring.
Impact
Provides senior-level application security assurance while developing the people who deliver it.

4.0 Engagement History

KPMG Canada 2020 – present · Quebec, Canada
Context Information Security 2011 – 2019 · 8 yrs · United Kingdom

5.0 Scope of Expertise

In scope — technical

  • Web application testing
  • Mobile application testing
  • API testing
  • Infrastructure / network
  • Simulated attacks (Purple & Red team)
  • Technical QA & peer review

In scope — leadership

  • Engagement scoping & delivery
  • Practice & methodology development
  • Team leadership & mentoring
  • Red team management
  • Training & upskilling
  • Client advisory & pre-sales

Out of scope

  • Unauthorised targets
  • Fixing your printer

6.0 Credentials

Offensive Security Certified Professional (OSCP)
OffSec · 2021–present · OS101-49708
CREST Certified Tester, Application (CCT App)
CREST · 2015–2018
CHECK Team Leader (CTL)
NCSC CHECK scheme · 2015–2018
CREST Registered Tester (CRT)
CREST · 2012–2015
BSc (Hons) Computing and Geography
University of Manchester · 2008

7.0 Disclosure & Contact

This report is published under a full-disclosure policy. Engagement enquiries, job opportunities, and differences of professional opinion may be responsibly disclosed via LinkedIn or GitHub.