Let's talk about your project
Cybersecurity

See the risks. Move with confidence.

Manage testing, remediation and monitoring in one place.

Risk visibilityPrioritized fixesContinuous follow-up

How it works

02 / Scope

6 layers, 89 test categories

6 layers, 89 test categories, more than 100,000 automated security checks and 24/7 monitoring: from your website to your network, from your staff to your cloud infrastructure, under one roof.

  • 6security layersWeb · Network · People · Cloud · Code · Mobile
  • 89test categories
  • 100,000+automated security checks
  • 1,700+attack techniques and scenarioscontrolled simulation
  • 600+cloud configuration checks
  • Thousandsup-to-date vulnerability templates
  • 24/7continuous monitoring option

Ongoing enterprise service lines

Beyond testing: continuous monitoring, response, simulation and consulting.

The figures are the number of checks in our automated security engines. Not every category runs in every test; the ones that fit your target and scope are selected.

Every test runs with your written permission and within the scope we agree together. Tests that could disrupt a service, and social engineering, are planned only with separate written approval. No test proves that a system is completely secure; we report clearly what was and was not found.

03 / For your needs

Solutions for your needs.

Only explicitly authorized assets and agreed scope are assessed.

Cybersecurity · Testing

  • Authorized scope
  • Risk table
  • Finding evidence
  • Remediation plan
View details

Cybersecurity · Remediation

  • Quote per finding
  • Fix work plan
  • Change notes
  • Retest report
View details

Cybersecurity · Monitoring

  • Asset inventory
  • Alert rules
  • Incident timeline
  • Monthly report
View details

Cybersecurity · Incident response

  • Incident triage
  • Containment plan
  • Recovery plan
  • Incident report
View details

Cybersecurity · Simulation

  • Authorized scope
  • Authorized attack scenario
  • Defense review
  • Remediation plan
View details

Cybersecurity · Compliance

  • Gap analysis
  • Policy drafts
  • Evidence list
  • Readiness review
View details

Cybersecurity · Mobile apps

  • App permissions
  • Data flow
  • Storage review
  • Risk table
View details

Cybersecurity · Cloud security

  • Identity and access review
  • Network review
  • Configuration review
  • Risk table
View details

Cybersecurity · Code security

  • Code review
  • Dependency review
  • Secret review
  • Fix work plan
View details

Cybersecurity · Deception and decoys

  • Isolated decoys
  • Alert rules
  • Response playbook
  • Scope boundaries
View details

Cybersecurity · Badge verification

  • Assessment summary
  • Validity period
  • Badge verification
  • Renewal retest
View details

Cybersecurity · Testing · Security testing packages

  • Authorized scope
  • Risk table
  • Finding evidence
  • Remediation plan
View details

Cybersecurity · Monitoring · External attack surface

  • Asset inventory
  • Exposure changes
  • Alert rules
  • Monthly report
View details

Cybersecurity · Monitoring · Basic monitoring

  • Alert rules
  • Availability signals
  • Incident timeline
  • Monthly report
View details

Cybersecurity · Monitoring · SOC-Lite

  • Alert rules
  • Triage plan
  • Response playbook
  • Scope boundaries
View details

Cybersecurity · Monitoring · Enterprise SOC

  • Log scope
  • Incident triage
  • Response playbook
  • Responsibility and governance
View details

Deliverables and acceptance criteria are agreed during scoping.

04 / What the price depends on

What sets the price of security work

In security work, the price depends on what is examined, how deeply and how often. The scope is agreed in writing, and no system outside it is touched.

  1. Number of assets in scope

    The basic unit is the number of web assets, network blocks, cloud accounts or monitored devices. One web asset covers a domain, its subdomains and one connected application.

  2. Method and package level

    Black-box or grey-box testing, whether areas behind a login are tested with test accounts, and the chosen package (Starter, Standard, Comprehensive) change the effort involved.

  3. Tests that need separate approval

    Phishing, phone-based social engineering and tests that could disrupt your service are not in the default scope. If you want them, each is planned as a separate line with separate written approval.

  4. Retest and fixing

    One retest within 30 days of the report is included in the price. Fixing the vulnerabilities is a separate service, priced per issue and by risk level, with a bulk discount when there are many.

  5. Monitoring level

    For ongoing monitoring, the chosen level (external attack surface, basic monitoring, SOC-Lite or Enterprise SOC) and the number of monitored assets or devices set the monthly fee.

  6. Incident response model

    For incident response you can choose an annual standby agreement or a one-off engagement; the length of the response and the number of affected systems set the price.

The price becomes clear in a written quote listing the assets, the method and the date range, prepared after a short first conversation; nothing is charged up to that point. No test starts without a signed written authorisation.

Request a quote
05 / Let's begin

Let's talk about your project.

Tell us what you need; we will define the scope together.