From quick overview to permanent security partner
Ten services in four groups: assessment, offensive testing, people and ongoing work. Some are settled in under a week, others are a standing agreement. All start with a free, no-obligation pre-analysis and a fixed price — talk to us first if you are unsure of the order.
Security assessments, offensive testing and ongoing advisory
A security assessment documents where you stand and what to prioritise. Offensive testing shows what an attacker can reach. And ongoing advisory keeps the level up once everyday operations take over.
Security QuickScan
A fast overview of the biggest risks in your Active Directory or Microsoft 365 — with zero operational impact, when you want a fast, focused starting point.
- Top 10 prioritised findings with recommendations
- Choose the AD or M365 track
- Concise report + 30-minute walkthrough
Microsoft 365 Security Assessment
An in-depth analysis of your entire cloud environment: identity, mail, sharing, apps and logging. Can anyone sign in where they should not — and how far can they then get?
- Entra ID, MFA, Conditional Access, PIM & GDAP
- Exchange, SharePoint, OAuth apps, Intune & Defender
- Executive summary + prioritised action plan
Active Directory Security Assessment
A full review of your on-premises Active Directory — including an offline penetration test of every password in the AD database, with zero operational impact.
- GPOs, delegations, trusts, service accounts & LDAP
- Offline password test against known wordlists
- Thorough report with prioritised findings
Identity Security Review
A focused review of identity and permissions in Entra ID: who has access to what — and is it more than they actually need?
- MFA coverage, legacy protocols & break-glass
- Conditional Access policies for all user types
- OAuth permissions, roles & guest access
Privileged Access Review
The shortest paths to Domain Admin: privileged accounts, delegations and attack paths in your Active Directory.
- Tier-0 accounts & privileged groups
- Kerberoasting & AS-REP exposure
- Overall privilege-escalation risk assessment
Internal Attack Surface Review
Remote analysis of your internal attack surface via a portable sensor — you connect power and network, we handle the rest.
- Host discovery, open ports & CVE matches
- AD enumeration, SMB shares & poisoning risk
- No software installation, minimal calendar friction
Penetration Testing
Targeted offensive testing of selected systems or surfaces — when you want to know whether your defences hold up in practice.
- Defined scope and rules of engagement
- Performed by certified specialists (GPEN, CEH)
- Findings documented with reproducible evidence
Assume Breach
We assume the attacker is already inside — and show how far a compromised account or machine can actually get.
- Realistic lateral-movement scenario
- Reveals the real consequences of a single phishing click
- Concrete recommendations to break the attack chain
Security Awareness
Practical awareness via Microsoft Attack Simulation: phishing simulation, targeted training tracks and measurable progress.
- Baseline measurement of your real click rate
- Training tracks for phishing, CEO fraud & MFA fatigue
- Report + plan for continued awareness work
CISO Service
Your permanent security partner with a finger on the pulse: we know your environment and act as your sounding board on matters big and small — CISO capability without a full-time hire.
- Specialists who know your environment
- Advice on matters big and small — one call away
- Monthly prioritisation & execution
Microsoft 365 or Active Directory?
The two main assessment tracks each cover their own security surface. If you have both, both assessments make sense — we recommend starting where the risk is greatest.
Choose the Microsoft 365 track
- You use Microsoft 365 for mail and files
- Your users sign in to the cloud
- You want accounts protected against phishing
- You share data with external parties
- You have apps connected to Microsoft 365
Choose the Active Directory track
- You run your own Windows servers
- You operate an Active Directory domain
- You want the paths to Domain Admin mapped
- You want your passwords tested
- You worry about on-prem ransomware
Frequently asked questions about our services
Which IT security advisory services do you offer?
Ten services in four groups: security assessments of Microsoft 365, Active Directory, identities and privileged access; offensive testing such as penetration testing, Assume Breach and internal attack surface; security awareness with phishing simulation; and ongoing advisory such as the CISO Service. All start with a free pre-analysis and a fixed price.
Where do we start if we do not know what we need?
With the free pre-analysis. In a start-up meeting of about an hour we clarify what you have, what you are worried about, and which service answers it. If you are unsure about the whole picture, a Security QuickScan of Active Directory or Microsoft 365 is the fastest first overview.
What is the difference between a Security QuickScan and a full security assessment?
A QuickScan is a short engagement with the ten most important findings in one track, Active Directory or Microsoft 365, and a 30-minute walkthrough. The full security assessment covers the entire security surface of the track, in the AD track including an offline test of all passwords, and delivers a report with an executive summary and a prioritised action plan.
Why are there no prices listed for the services?
Because no two companies — or system landscapes — are alike, and a fixed price list would be either too high for some or too vague for all. Instead, we always start with a free, no-obligation pre-analysis. After that you usually get a fixed price with no surprises — and where a fixed price isn’t possible, an estimate we stand behind and keep.
- Unilite
- Cadpeople
- Kunde & Co
- Bitcoin Suisse
- Mercantec
- Dagrofa
- Laursens Realskole
- Zug Kommune
- Altid Vikar
- Adeo Datacenter
- A&O Kreston
- Numarics
- Geelmuyden Kiese
80+ certifications — CISSP, CISM, CISA, ISO 27001 · More about Martin →
Facing a security incident right now?
Our emergency response is for clients with an emergency agreement — around the clock, all year. No agreement? You are welcome to call — we help if we have capacity.
Ready to have your security verified by an independent third party?
A free, no-obligation pre-analysis. A fixed price. A concrete plan you can act on right away.
Get a free pre-analysis