An independent assessment of one cyber security consultant. Testing conducted continuously since 2011.
| Reference | CD-2026-001 |
| Target | Craig Donkin, Cyber Security Consultant & Penetration Tester |
| Current engagement | Senior Manager, KPMG Canada |
| Assessment window | 2011 – present (ongoing) |
| Prepared for | Prospective clients, employers, and the professionally curious |
| Classification | Public |
| Version | Date | Change description |
|---|---|---|
| v0.1 | 2008 | Initial build: BSc (Hons) Computing and Geography, University of Manchester |
| v1.0 | 2011 | Offensive security module enabled: joined Context Information Security as a penetration tester |
| v2.0 | 2020 | Migrated to Canadian infrastructure: joined KPMG Canada as Manager |
| v3.0 | 2025 | Privilege escalation successful: promoted to Senior Manager |
Craig is a cyber security consultant specialising in penetration testing, with over fourteen years of hands-on offensive security experience. Today he co-leads KPMG Canada's offensive security practice as a Senior Manager.
He is a subject matter expert in application penetration testing (web, API and mobile), but also has extensive infrastructure testing experience, honed on the floors of many a UK data centre. Since 2021 he has been deploying that experience: creating scoping guides, testing methodologies and report templates, and maintaining high standards for the offensive security practice.
Co-leads KPMG Canada's offensive security practice nationally, with accountability for both technical delivery and team performance. Manages a portfolio of penetration testing engagements as engagement manager, scoping, delivering and quality-assuring projects directly with clients, while helping shape the future direction of the practice, supporting hiring, and acting as a performance manager.
Managed KPMG Canada's web and mobile application testing lines, with delivery responsibility across the full penetration testing service range. Built and rolled out an automated reporting solution and designed the practice's bilingual (English/French) report template. Authored a library of 140+ templated findings to standardise reporting quality, and wrote the practice's web and mobile testing methodologies grounded in OWASP, MASVS and ASVS. Mentored junior consultants, ran peer reviews, and helped implement a formal technical QA process.
Led and delivered complex, high-profile penetration testing engagements, including red team exercises to the CBEST standard for the financial services sector. Acted as line manager for several team members, contributed to engagement scoping and technical QA across the team, and served as service lead for Context's mobile penetration testing offering, owning its technical direction and quality.
Held CREST Certified Tester (Application) status and served as a CHECK Team Leader, running multiple web application assessments end-to-end (scope, team and delivery phases). Performed technical QA across the practice, spent six months as Context's technical pre-sales consultant supporting scoping calls and client visits, and completed a 6+ month embedded placement at a global payments company. Delivered testing across Context's full service range, remotely and onsite across the UK, Canada, Switzerland and Poland.
Began his cyber security career as a penetration tester within Context's testing teams, working across the firm's full service range. Achieved CREST Registered Tester (CRT) certification and qualified as a CHECK Team Member.
This report is published under a full-disclosure policy. Engagement enquiries, job opportunities, and differences of professional opinion may be responsibly disclosed via LinkedIn or GitHub.
not a real AI