Offensive

Assume Breach

Sooner or later the perimeter gets breached — the question is what happens next. In an Assume Breach engagement we start from a compromised standard account or machine and map how far an attacker can actually move through your environment before anyone notices. The engagement is controlled, agreed in writing and performed by independent specialists.

In short

Assume Breach starts where the perimeter has already failed: from a single compromised standard account, we map how far an attacker can actually get in your environment — and what your defences catch along the way. It is for organisations that want to know the consequence of the first phishing click. You get the attack chain step by step, an assessment of detection capability and prioritised recommendations. Controlled, agreed in writing, at a fixed price after a free pre-analysis.

What the test covers

  • Starting point: an agreed standard user or machine
  • Lateral movement, privilege escalation and access to critical data
  • Detection-gap mapping — what did your defences catch along the way?
  • Controlled execution with clear rules of engagement

What you get

  • Report describing the attack chain step by step
  • Assessment of detection and response capability
  • Prioritised recommendations to break the chain

Out of scope

  • Performed only under written agreement and a defined scope
  • Destructive actions are never part of the engagement
Clients who trust Sekuritet
  • Unilite
  • Cadpeople
  • Kunde & Co
  • Bitcoin Suisse
  • Mercantec
  • Dagrofa
  • Laursens Realskole
  • Zug Kommune
  • Altid Vikar
  • Adeo Datacenter
  • A&O Kreston
  • Numarics
  • Geelmuyden Kiese
The consultants’ expertise ensured we were well prepared for future growth while meeting the financial sector’s high security requirements.
Christian Holm · CTO · Bitcoin Suisse · More client testimonials →

80+ certifications — CISSP, CISM, CISA, ISO 27001 · More about Martin →

How it works

01

Scope & starting point

We agree the starting point — a standard user or machine — plus the frame and a written agreement.

02

Controlled attack path

We move as an attacker would: lateral movement, privilege escalation and access to critical data.

03

Detection analysis

What did your defences catch along the way — and when? The gaps are mapped.

04

Report & recommendations

The attack chain step by step and prioritised recommendations to break it.

Frequently asked questions

Assume Breach, Assumed Breach or Assumed Compromise — is it the same thing?

The terms describe the same premise: that the attacker is already inside. Assume Breach is the most common name; Assumed Breach and Assumed Compromise are used interchangeably. With us it is the same engagement either way — we start from one compromised standard account and measure how far an attacker gets, and what your defences catch along the way.

How does Assume Breach differ from a penetration test?

A penetration test starts from the outside and tests whether someone can get in. Assume Breach starts inside — from a compromised standard account — and shows how far an attacker can get, and what your defences catch along the way.

Why assume the attacker is already inside?

Because sooner or later that is reality: phishing, reused passwords or a vulnerability grants access. Assume Breach shows the consequence of that first click — and where the chain can be broken.

Is the engagement risky for operations?

The engagement is agreed and controlled: a clear frame, time windows and escalation paths — and destructive actions are never part of it.

What does an Assume Breach engagement cost — and why isn't the price listed here?

Because no two companies — or system landscapes — are alike, and a fixed price list would be either too high for some or too vague for all. Instead, we always start with a free, no-obligation pre-analysis. After that you usually get a fixed price with no surprises — and where a fixed price isn’t possible, an estimate we stand behind and keep.

First step

Ready to have your security verified by an independent third party?

A free, no-obligation pre-analysis. A fixed price. A concrete plan you can act on right away.

Get a free pre-analysis