Who verifies your security?
Sekuritet delivers independent security assessments, penetration tests and ongoing CISO advisory — without disrupting your operations, at a fixed price after a free pre-analysis, with reports both leadership and engineers can act on.
We don’t claim to be among the best.
We document it.
Certified knowledge across security, audit, risk and Microsoft technology — turned into a concrete basis for decisions — with no hidden vendor agenda.
Our research on internet-exposed Exchange servers has been covered by Ingeniøren / Version2, Computerworld and The Sidechannel — see the coverage.
“Our IT vendor has security covered.” — Do they?
It is the objection we hear most often. Yet we frequently come across high-risk findings that nobody knew about.
Operations and security are two disciplines
Most IT agreements focus on operations and uptime. Security is considered — but is the coverage complete, and are the choices right? That is what we help you verify.
No one can audit themselves
You have your accounts audited by an external auditor — not by the bookkeeper who kept them. For exactly the same reason, whoever operates your environment cannot independently assess its security.
Trust is not documentation
Attacks on Danish hosting providers in recent years have shown that “we trust our vendor” is not a security control. An independent review makes that trust documentable — to leadership, clients and regulators.
We don’t replace your IT vendor. We verify — as an independent third party.
From quick overview to permanent security partner
Pick a service and see what it covers. Every engagement starts with a free, no-obligation pre-analysis and a fixed price.
Security QuickScan
A fast overview of the biggest risks in your Active Directory or Microsoft 365 — with zero operational impact, when you want a fast, focused starting point.
- Top 10 prioritised findings with recommendations
- Choose the AD or M365 track
- Concise report + 30-minute walkthrough
Microsoft 365 Security Assessment
An in-depth analysis of your entire cloud environment: identity, mail, sharing, apps and logging. Can anyone sign in where they should not — and how far can they then get?
- Entra ID, MFA, Conditional Access, PIM & GDAP
- Exchange, SharePoint, OAuth apps, Intune & Defender
- Executive summary + prioritised action plan
Active Directory Security Assessment
A full review of your on-premises Active Directory — including an offline penetration test of every password in the AD database, with zero operational impact.
- GPOs, delegations, trusts, service accounts & LDAP
- Offline password test against known wordlists
- Thorough report with prioritised findings
Identity Security Review
A focused review of identity and permissions in Entra ID: who has access to what — and is it more than they actually need?
- MFA coverage, legacy protocols & break-glass
- Conditional Access policies for all user types
- OAuth permissions, roles & guest access
Privileged Access Review
The shortest paths to Domain Admin: privileged accounts, delegations and attack paths in your Active Directory.
- Tier-0 accounts & privileged groups
- Kerberoasting & AS-REP exposure
- Overall privilege-escalation risk assessment
Internal Attack Surface Review
Remote analysis of your internal attack surface via a portable sensor — you connect power and network, we handle the rest.
- Host discovery, open ports & CVE matches
- AD enumeration, SMB shares & poisoning risk
- No software installation, minimal calendar friction
Penetration Testing
Targeted offensive testing of selected systems or surfaces — when you want to know whether your defences hold up in practice.
- Defined scope and rules of engagement
- Performed by certified specialists (GPEN, CEH)
- Findings documented with reproducible evidence
Assume Breach
We assume the attacker is already inside — and show how far a compromised account or machine can actually get.
- Realistic lateral-movement scenario
- Reveals the real consequences of a single phishing click
- Concrete recommendations to break the attack chain
Security Awareness
Practical awareness via Microsoft Attack Simulation: phishing simulation, targeted training tracks and measurable progress.
- Baseline measurement of your real click rate
- Training tracks for phishing, CEO fraud & MFA fatigue
- Report + plan for continued awareness work
CISO Service
Your permanent security partner with a finger on the pulse: we know your environment and act as your sounding board on matters big and small — CISO capability without a full-time hire.
- Specialists who know your environment
- Advice on matters big and small — one call away
- Monthly prioritisation & execution
Facing a security incident right now?
Our emergency response is for clients with an emergency agreement — around the clock, all year. No agreement? You are welcome to call — we help if we have capacity.
Minimal friction. Concrete insight.
Typically 2–3 weeks from start to finished report on the assessments — and your own effort is a kick-off meeting of about an hour plus read-only access.
Free pre-analysis
We assess the scope and give you a fixed price. No obligation, no surprises.
Read-only data collection
Automated extracts via PowerShell and Graph — zero operational disruption.
Analysis & assessment
Manual specialist review with risk prioritisation and business context.
Report & plan
An executive summary for leadership, technical depth for your team — ready to act on.
The assessment we received deserves a 10 out of 10 without hesitation.
Sekuritet challenged that decision and recommended starting with a security assessment instead. It turned out to be the right call.
Their insight, experience and technical help have strengthened and optimised our IT infrastructure and raised our security level.
The consultants’ expertise ensured we were well prepared for future growth while meeting the financial sector’s high security requirements.
Ready to have your security verified by an independent third party?
A free, no-obligation pre-analysis. A fixed price. A concrete plan you can act on right away.
Get a free pre-analysis