What we solve
For owners of public systems, personal data, and critical integrations. The assessment method is chosen after reviewing the attack surface and the level of impact permitted on live infrastructure.
What you get
The client receives a report with validated vulnerabilities, risk ratings, evidence, and a prioritized remediation plan. A separate retest can follow after fixes are made.
What is included
- Definition of goals, systems in scope, and exclusions
- Written authorization and rules of engagement
- Selection of specialist testers
- Testing and validation of findings
- A report, results review, and remediation plan
How we work
- Document scope and permitted methods.
- Agree the testing window and incident contacts.
- Test without exceeding the authorized scope.
- Deliver the report and discuss remediation priorities.
Optional additions
- Retesting of fixes
- Configuration review
- Review of development practices
- Help prioritizing technical controls
Important considerations
Work begins only with written authorization from the system owner. The team and methods depend on the target; any production impact and use of sensitive data are agreed in advance.