We simulate attacks on your systems under controlled conditions, using the same methods as real attackers. The result is not a scan report, but a plan prioritized by urgency.
Manual testing instead of just scans
Until then, an attacker often has access for weeks. A test conducted under controlled conditions reveals in advance where you are vulnerable.
Automated tools can identify gaps for which an entry already exists. Only a human can identify attack vectors that arise only through the combination of several small errors.
A list of sixty findings doesn't help anyone. What matters is determining what needs to be addressed first and what can wait.
A firewall doesn't prevent someone from walking into the office and plugging in a USB drive. Physical security is the most commonly overlooked area.
We use the same methods that attackers employ. No automated runs—instead, our testers combine techniques and follow up wherever a vulnerability is found.
From the outside and the inside, including the firewall, VPN, and accessible services.
Applications and programming interfaces, including errors in business logic.
Microsoft 365, Azure, AWS, and Google Cloud, including permissions and access rights.
Expansion of Permissions, Registration Process, and Paths from User to Administrator.
It's easy to know the gap.
But it's not easy to know which one comes first.
Each finding is accompanied by information on the level of risk and the extent of the work required to resolve it. This determines which issues are addressed first.
From the initial assignment to the follow-up test. You'll know exactly what we're working on and what's coming next at every step of the way.
Together, we determine what will be tested, which methods will be used, and over what time frame. Written approval is required before testing begins.
We gather information, assess the attack surface, and identify initial points of entry.
Any vulnerabilities we find are manually exploited and investigated further. We report critical findings immediately, without waiting for the report.
You will receive the report, which includes detailed findings for each item and an action plan, along with a personal discussion of the results.
Once the issue has been resolved, we'll check to see if the measures are actually effective. This is part of the service, not an additional assignment.
Red teaming goes beyond a penetration test. It focuses on a specific target rather than a list of systems, and it also tests whether anyone would notice the attack.
Specified systems are systematically checked for technical vulnerabilities. Your IT department is aware of this.
We are working toward a goal and combining technical, human, and physical approaches. Only management and one contact person are aware of this.
We test how far an unauthorized person can get: into the building, into the server room, to an available network port. This service can also be booked individually.
Entrance, reception area, side entrances, underground parking garage, and secure areas.
Whether you're a technician, a vendor, or a new colleague: How far can a plausible story take you?
Media that have been laid out, along with an analysis of how often they were infected.
Reactions to strangers, open screens, documents on desks.
A test that only generates a report is not complete. We follow up until the issue has been verified as resolved.
Once the issue has been resolved, we'll check again—without any additional budget and without a new order.
A risk assessment, clear documentation, and a specific recommendation. Not just a list of identifiers.
Medical findings, login credentials, and system information are transmitted in encrypted form and stored exclusively in Austria.
The reports are structured in such a way that they can be used to provide evidence to auditors and insurance companies.
A scan automatically lists known vulnerabilities. During a penetration test, our testers attempt to actually exploit these vulnerabilities, chain them together, and go further. This reveals attack paths that no tool can detect.
That depends on the scope. A web application test typically takes three to five days, while an internal infrastructure test takes five to ten days. Red Teaming takes four to eight weeks. We’ll determine the exact timeframe together in advance.
Yes. After the issue is resolved, we'll check to see if the measures are effective. That's an integral part of the service.
We agree in advance exactly which actions are permitted. Destructive tests, such as deleting data, are never part of the scope. If anything is unclear, we pause and ask for clarification.
That's up to you. Typically, only management and a single contact are aware of this, so that the detection can be tested under realistic conditions.
Yes, it can be booked separately. Many customers even start with this option because this area is checked the least often, and the results are often surprising.
Once a year as a general rule, and additionally following major changes such as the implementation of new systems, a move to the cloud, or an acquisition, as well as before upcoming audits.
Exclusively in Austria, encrypted, and without any U.S. providers. Upon request, we will delete all data completely upon project completion.
A test is a snapshot. Detection requires someone who pays close attention over the long term.
In thirty minutes, we'll determine which test is appropriate for your situation and what it entails.
We use cookies to operate this website and analyze its usage. You decide which categories to allow. You can adjust your settings at any time.