Penetration Testing
Authorised attacks on your systems — black, white or grey box, external and internal. With findings ranked by severity …
ViewOffensive Services
Technology can be hardened. People can only be prepared. A social engineering assessment tests how your organisation reacts when somebody asks politely instead of breaking in — and provides the basis for learning from it.
We reproduce how attackers actually operate: not with a generic bulk email, but with whatever is publicly discoverable about your company. Job adverts reveal the software in use, LinkedIn the reporting lines, a press release the moment at which an invented urgency sounds plausible.

That last point matters to us. A test that leaves nothing behind but a click rate improves nothing — it creates mistrust. Every assessment therefore ends with a debrief for the workforce showing how the attack could have been recognised. Making that permanent is what the Security Awareness Training is for.
objectives, limits and escalation routes are settled in writing beforehand
analysis of publicly accessible sources on the company and its staff
the agreed scenarios, within agreed time windows
rates per scenario and department, without naming individuals
training on exactly the patterns that worked
A report with rates by scenario, department and over time — anonymised
Example attack chains including the pretexts actually used
mail filtering, reporting route, response time
Concrete recommendations, separated into technology, process and training
On request, a repeat measurement after six to twelve months
A social engineering assessment touches on personal rights and on employee representation. We work exclusively on the basis of a written engagement, settle the scope with your data protection officer and works council, and as a matter of principle do not analyse results per person. No result of our test is suitable as grounds for disciplinary measures — and that is deliberate.
Ahead of an ISO 27001 certification, as recurring evidence under NIS2, after an actual incident, or when a merger brings two security cultures together. Alongside it, Penetration Testing examines the technical side, and Red Teaming both in combination.
Offensive Services
Authorised attacks on your systems — black, white or grey box, external and internal. With findings ranked by severity …
ViewOuter skin, internal network, web applications and cloud checked continuously against CVE — rated against your situatio…
ViewSix to eight weeks against one agreed objective — technology, people, buildings. What is measured is your detection, no…
ViewContact
Talk to us before somebody else does. The first conversation is free and we reply the same business day.