Our own SaaS platform for Continuous Threat Exposure Management assesses your external attack surface non-invasively. We also give you a vendor-neutral view of the current state and effectiveness of your security tools — SIEM, XDR and vulnerability scanners — and show you the target state. Architecture consulting completes the portfolio.
A non-invasive assessment of your externally reachable assets, prioritised by real exploitability. Usable for ISO 27001 and NIS2.
To the attack surface assessment →What is changing?Continuous view of your externally exposed assets, vulnerabilities and leaked credentials — operated by us. No security department of your own needed.
To attack surface monitoring →Does your defence see what happens?A vendor-neutral assessment of your SIEM and the systems around it — with a maturity rating, your largest gaps and a clear target state.
To GrayCheck →Does the foundation hold?Zero Trust, threat modelling, risk assessment, compliance support — with your own SOC, a small team or none at all.
To consulting →No SIEM yet, or unsure which tools you actually need? We often join companies one step earlier — at the question of which solutions make sense and are cost-effective in the first place.
Results that are structured and traceable — usable for audits and evidence obligations.
| Standard | What our assessments deliver |
|---|---|
| ISO/IEC 27001A 5.9 · A 8.8 · A 8.15/8.16 | An inventory of externally reachable assets, technical vulnerabilities, logging and monitoring. |
| NIST CSF 2.0ID.AM · ID.RA-01 · DE.CM | Discovered assets, prioritised findings per asset, detection coverage. |
| NIS2 Directive (EU)Art. 21(2) a · d · e | A dated snapshot for risk analysis, supply chain and vulnerability handling. |
We assess and improve company security from three perspectives: from outside (your attack surface — as a one-off report or continuously as a managed service), in the defence (the effectiveness of your SIEM and security tools with GrayCheck) and in the foundation (architecture & consulting).
With the one-off assessment of your external attack surface: a defined scope, predictable cost and a result report — with no ongoing contract. You then decide whether we take over monitoring.
The one-off assessment is a snapshot with a full result report — usable as evidence in an audit. Monitoring runs continuously and reports changes and new risks as they appear.
No. You can use every service yourself, with partial support, or fully operated by us — whether you have your own SOC, a small team, or none at all.
Yes. The attack surface assessment is performed from outside and is not tied to a location; subsidiaries in other countries can be included.
What is reachable from outside? Whether your tools work? Or what the target architecture should look like?
Tell us where you stand — we will suggest the right starting point.
Updates on our cybersecurity products and selected security insights — by email, with double opt-in, and you can unsubscribe at any time.
Subscribe to the newsletter →Tell us briefly what it’s about – we’ll get back to you within 1–2 business days.