Skip to content
Someone working on a laptop late at night, the screen the only bright thing in a dark room.

Services

Offensive Security

Find the way in before someone else does.

Find the way in before someone else does.

Every control you own has a way around it that nobody has looked for. Offensive security is the discipline of looking: applications, APIs and mobile apps, the infrastructure they sit on, the cloud accounts they run in, and the code that ties them together.

We test the way an attacker works — from the outside with nothing, from the inside with a stolen laptop, or as a full red team with a goal and a time limit — and we report the way an engineer needs: what was found, how it was exploited, what to fix first, and a retest to confirm it is closed.

Testing runs with PASSI-qualified partner teams where the qualification is required, under our scoping and our accountability. What you get is a ranked list you can act on, not a PDF of scanner output.

Offensive Security

Penetration testing and red team

Applications, infrastructure, cloud and code, attacked under contract and reported with fixes.

  • Application pentest (web, API, mobile)Typical duration: 5–12 daysRetest includedDelivered with a qualified partner

    Manual testing of your applications and APIs against the OWASP methodology, delivered with a PASSI-qualified partner. The retest after remediation is included in the price.

    You receive

    • Technical report with reproducible proofs
    • Severity and exploitability rating
    • Developer-facing remediation guidance
    • Retest report and attestation
  • Infrastructure pentestTypical duration: 5–10 daysRetest included

    External and internal testing of your network, exposed services and Active Directory, aimed at the paths an attacker would actually take to reach your data.

    You receive

    • External and internal attack paths
    • Active Directory findings and privilege escalation
    • Prioritised remediation plan
    • Retest report
  • Red TeamTypical duration: 15–40 daysDelivered with a qualified partner

    A goal-oriented, intelligence-led exercise run with a specialist partner: realistic tradecraft against your detection capability, with a purple-team debrief so the blue team gains from it.

    You receive

    • Scenario and rules of engagement
    • Attack narrative with timeline
    • Detection and response gap analysis
    • Purple-team debrief workshop
  • Secure code reviewTypical duration: 5–12 daysRetest included

    Manual review of the parts of your codebase where a flaw is expensive: authentication, authorisation, data access, cryptography and the handling of untrusted input.

    You receive

    • Findings with code references
    • Secure coding recommendations
    • Rule tuning for your SAST tooling
    • Developer debrief session
  • Cloud configuration audit (AWS, Azure, GCP, M365)Typical duration: 3–8 daysRetest included

    A configuration review against CIS benchmarks and the provider's own guidance, covering identity, network, logging, storage exposure and the tenant settings people forget.

    You receive

    • Findings mapped to CIS benchmarks
    • Identity and network exposure review
    • Infrastructure-as-code remediation snippets
    • Retest and drift check

Cyber 360 Flash

Three weeks to a clear picture: maturity, exposure and the ten things to fix first.

Duration
3 weeks
Price
€6,000 to €9,000
excl. VAT, indicative

Discuss this pack — Cyber 360 Flash

Vulnerability and attack-surface management

Continuous scanning of what you own and what is exposed in your name, with findings filtered, prioritised and tracked to closure rather than published as a raw list.

What is included

  • Internal and external scanning
  • External attack surface discovery
  • Risk-based prioritisation
  • Remediation tracking against SLAs
  • Monthly reporting
SOCOffensive

Discuss this service — Vulnerability and attack-surface management

Start with a flash audit

Cyber 360 Flash takes three weeks and gives you the ten findings that matter, ranked by what an attacker would do with them.