Security Assessments

See the exposure. Know what to fix first.

An assessment should do more than produce a vulnerability list. We combine technical validation with business context so material exposure can be separated from routine improvement work.

Assessment portfolio

Choose the method that answers the right question.

Automated coverage can support discovery, but significant findings are manually reviewed and placed in context before reporting.

01 / BASELINE

Vulnerability Assessment

Identify and validate weaknesses across an agreed environment, then review exposure, exploitability and operational significance.

02 / ATTACK PATH

Penetration Testing

Test whether agreed attack paths can achieve defined objectives within controlled rules of engagement and safety constraints.

03 / EXTERNAL

External Attack-Surface Review

Examine publicly reachable services, exposed management interfaces, domains, certificates and observable entry points.

04 / INTERNAL

Internal Network Assessment

Review segmentation, trust relationships, administrative access, common service exposure and movement between zones.

05 / CLOUD IDENTITY

Microsoft 365 Security Review

Assess identity protection, roles, conditional access, legacy authentication, app consent, audit coverage and sharing.

06 / DIRECTORY

Active Directory Assessment

Review privilege, tiering, service accounts, delegation, domain controllers, legacy protocols, trusts and recoverability.

07 / NETWORK

Firewall & Architecture Review

Evaluate trust boundaries, rule intent, management access, remote connectivity, inter-site exposure and logging.

08 / READINESS

Ransomware-Readiness Assessment

Review identity, endpoint coverage, segmentation, privileged access, response preparation, backups and recovery dependencies.

09 / RECOVERY

Backup & Recovery Validation

Examine backup architecture, administrative separation, monitoring, restoration procedures and selected recovery tests.

10 / ACTION

Remediation Roadmap

Organize findings by practical risk, dependency, effort, ownership and the evidence required to verify correction.

Assessment method

Controlled testing, manual validation and usable reporting.

  1. Scope and authorization

    Define assets, windows, contacts, exclusions and rules of engagement.

  2. Discovery and testing

    Map relevant systems and combine automated coverage with manual analysis.

  3. Risk evaluation

    Consider exploitability, exposure, business role, controls and operational impact.

  4. Reporting and workshop

    Document reproducible findings and review priorities with technical owners.

  5. Retest where agreed

    Confirm whether selected corrective actions resolved the original condition.

What clients receive

Decision material and implementation detail.

Findings are structured for both leadership and the teams responsible for remediation.

  • Executive assessment of material exposure
  • Defined scope, assumptions and exclusions
  • Validated technical findings
  • Affected assets and supporting evidence
  • Clear severity rationale
  • Reproduction and verification guidance
  • Prioritized remediation roadmap
  • Technical readout and retest statement when included

Assessment FAQ

What to expect before testing.

What is the difference between a vulnerability assessment and a penetration test?

A vulnerability assessment emphasizes coverage and validated weaknesses. A penetration test pursues agreed objectives to determine whether selected weaknesses can be combined or exploited in practice.

Can testing be performed safely in production?

Many tests can be conducted with controlled methods, defined windows and active coordination. No production test is entirely without risk, so sensitive techniques and stop conditions are agreed first.

Are automated scanner results included as findings?

Scanner output is treated as input, not a final conclusion. Significant findings are manually reviewed and contextualized before reporting.

Is remediation support included?

The report includes remediation guidance and a technical readout. Implementation support and formal retesting can be included in the agreed scope.

Are credentials required?

Some assessments are external and unauthenticated; others require controlled test accounts. Access requirements are agreed during scoping and exchanged through an approved secure method.

Testing boundaries

Authorization is part of the method.

Testing is limited to systems and techniques expressly authorized in writing. Denial-of-service testing, destructive techniques, social engineering, physical testing and third-party systems are excluded unless separately scoped.

Next step

Start with the question the assessment must answer.

We will help define the appropriate scope, testing method and deliverables before work begins.

Plan an Assessment