IT infrastructure and information systems security assessment
An independent technical security assessment that shows the real security posture of your networks, systems and source code: exploitable vulnerabilities and clear remediation priorities.
- Vulnerability assessment
- Penetration testing
- Web security scan
- Code review
Four independent modules
Each module can be ordered separately or in any combination — none is a prerequisite for another. You choose the order of execution to match your priorities and budget periods.
Vulnerability assessment
Automated scanning of the external perimeter and internal networks, including authenticated scanning that reveals the real patch and configuration state.
Penetration test
A controlled attack simulation from outside and inside the network, Active Directory assessment and practical verification of attack chains.
Web security scan
Testing of public systems, APIs and data services using the OWASP methodology: authentication, access control, data exposure.
Code security review
Static analysis, dependency and supply-chain checks (SBOM), secret scanning and manual review of critical code paths.
NIS2 and national cybersecurity law compliance
The law requires ICT asset inventory, risk assessment and protective measures. An independent technical assessment proves the measures work in practice — and supports your ISO/IEC 27001 journey.
Methodology and tools
Work follows internationally recognised methodologies. Every finding is rated with CVSS, and remediation priority additionally uses EPSS — the probability of real-world exploitation.
Standards
PTES, NIST SP 800-115, OSSTMM, OWASP WSTG and ASVS (level 2), OWASP Code Review Guide.
Professional tools
Greenbone Enterprise, Nmap, Burp Suite Professional, BloodHound, PingCastle, Semgrep, SonarQube, Trivy and more.
Authenticated scanning
Unlike an outside-only view, authenticated scanning also reveals patch levels and local configuration — the full picture, not just the facade.
What you receive
Concrete, actionable deliverables for every module.
Technical report
Detailed findings with impact assessment, reproduction steps and remediation recommendations.
Executive summary
The risk picture in non-technical language with the key decisions management needs to make.
Findings register
In Excel with CVSS and EPSS scores, priorities, owners and deadlines — a ready-to-use work list.
Action plan
Measures grouped into three execution windows: immediately, within 1–3 months and within 3–6 months.
Presentation
Results walkthrough for management and the IT team, on-site or remote.
Re-test
After fixes are deployed we verify their effectiveness and issue a confirmation.
How the assessment works
A full four-module assessment takes about 12 weeks; individual modules are correspondingly shorter. Any work that could affect system availability is scheduled in pre-agreed windows.
Kick-off
NDA, written testing authorisation, scope and rules of engagement, access preparation.
Testing
Scanning, testing and review on the agreed schedule; critical findings are reported immediately.
Reporting
Technical reports, executive summary, action plan and presentation.
Re-test
After remediation we verify that the findings are resolved.
Confidentiality and data protection
NDA before work starts, encrypted storage of all results in the EU, minimal personal-data processing and same-day notification if signs of a prior intrusion are found.
Additional services
ICT security risk assessment
ICT asset inventory, risk identification and assessment in line with national cybersecurity law requirements.
NIS2 compliance audit
Assessment of security controls, documentation and processes with a remediation plan.
Continuous vulnerability management
Monthly scanning, change comparison and a concise report.
Phishing simulation
Social-engineering test for employees with results analysis.
Annual re-assessment
A condensed assessment after 12 months to maintain your security level.
How secure is your IT environment, really?
Tell us about your infrastructure and we will prepare an assessment offer with the right combination of modules for your needs.