Reg. No. 40203410806 VAT LV40203410806

Theme

Book a consultation Book

Evidence-Led Cybersecurity

Think like an attacker.
Defend like one too.

Penetration testing, red teaming and NIS2 / DORA readiness for organisations across the EU.

We verify security through attacker-led testing, clear evidence and practical remediation guidance.

Reply within 24 hours · Re-testing available for every engagement

  • OffSeq found issues our previous audits never surfaced — and explained exactly how to fix them.
    Oskars Podziņš Printful
  • A genuine attacker’s perspective. The red team report changed how we prioritize security investment.
    Oskars Zīle Eleving Group
  • Clear, pragmatic and fast. They treat our risk like it’s their own.
    Viktors Trifanovs Test Dev Lab

01

Security claims should be supported by evidence.

03 / 07

The specialists who conduct our client engagements also perform independent vulnerability research and build the tools used in our work. The results below are publicly verifiable.

  1. 01

    Cross-instance configuration poisoning in X-Road

    X-Road Security Server (< 7.8.2)

    X-Road Security Servers wrote federated global-configuration parts to disk based on the ecosystem identifier carried inside each part, without verifying it matched the actual source. A malicious federation partner could serve a SHARED-PARAMETERS part naming a victim ecosystem — signed with the victim’s own key — and overwrite its authoritative trust configuration, gaining persistent control and the ability to impersonate any of the victim’s members and Security Servers.

    Insufficient verification of data authenticity (CWE-345, CWE-346)

    CVSS 8.0 High GHSA-c5gr-pcm6-828r 2026
  2. 02

    Command injection fixed in Estonia’s national eID software

    DigiDoc4 — Estonia’s official eID signing application

    DigiDoc4’s file-manager integration constructed shell commands using unsanitised filenames. A specially crafted filename could execute arbitrary code when a user selected the file for signing or encryption. The issue affected software used for legally binding electronic signatures.

    OS command injection (CWE-78)

    Critical 2026
  3. 03

    SWQL injection in SolarWinds Platform

    SolarWinds Platform (≤ 2024.1 SR 1)

    A query-language injection vulnerability allowed an attacker to manipulate back-end database queries in the SolarWinds Platform. It was identified during penetration testing for the NATO Communications and Information Agency.

    SQL / SWQL injection (CWE-89)

    CVSS 7.5 High CVE-2024-28996 2024
See all results

A European cybersecurity company, verified in public

OffSeq is an EU-based cybersecurity company working with organizations across Europe, backed by public evidence, international certifications and EU-wide regulatory expertise.

  1. 01

    Evidence in the public record

    Credited CVEs and coordinated disclosures in software used across Europe and beyond — from national eID systems to enterprise and data-exchange platforms.

    See results
  2. 02

    European competence network

    Connected to the European Cybersecurity Competence Centre (ECCC) network through its national coordination centres across the EU.

    EU network
  3. 03

    NIS2, DORA & GDPR expertise

    Compliance audits, gap assessments and threat-led testing aligned with the EU requirements relevant to your organization.

    EU regulation

How our approach differs

We combine manual attacker-led testing with reproducible evidence and practical remediation guidance.

  1. 01

    Compared with generic audits

    Elsewhere

    A compliance checklist with limited technical validation.

    With OffSeq

    Testing based on relevant attack paths, supported by evidence of potential business impact.

  2. 02

    Compared with automated scanners

    Elsewhere

    Large volumes of unverified results that your team must triage.

    With OffSeq

    Manual validation by qualified specialists, focused on findings that materially affect risk.

  3. 03

    Compared with unproven providers

    Elsewhere

    A report from a provider whose qualifications may be difficult to verify.

    With OffSeq

    An EU-based team whose work is verifiable in the public record, operating under NDA and offering re-testing to verify remediation.

03

What we test

We assess the technical, human and physical attack surfaces available to an adversary. Each row links to the relevant service; testing depth ranges from a focused assessment to a full-scope red-team engagement.

What we test
Surface ╲ Test REC Reconnaissance & ASM VA Vulnerability assessment PT Penetration test RT Red team HR Hardening review MON Continuous monitoring
Reconnaissance & ASM: Core capability Vulnerability assessment: Core capability Penetration test: Core capability Red team: Core capability Hardening review: Core capability Continuous monitoring: Available when included in scope
Reconnaissance & ASM: Core capability Vulnerability assessment: Core capability Penetration test: Available when included in scope Red team: Available when included in scope Hardening review: Available when included in scope Continuous monitoring: Core capability
Reconnaissance & ASM: Core capability Vulnerability assessment: Core capability Penetration test: Core capability Red team: Available when included in scope Hardening review: Core capability Continuous monitoring: Available when included in scope
Reconnaissance & ASM: Core capability Vulnerability assessment: Core capability Penetration test: Core capability Red team: Core capability Hardening review: Available when included in scope Continuous monitoring: Available when included in scope
Reconnaissance & ASM: Available when included in scope Vulnerability assessment: Core capability Penetration test: Available when included in scope Red team: Out of scope Hardening review: Core capability Continuous monitoring: Core capability
Reconnaissance & ASM: Available when included in scope Vulnerability assessment: Core capability Penetration test: Core capability Red team: Core capability Hardening review: Core capability Continuous monitoring: Available when included in scope
Reconnaissance & ASM: Available when included in scope Vulnerability assessment: Core capability Penetration test: Core capability Red team: Available when included in scope Hardening review: Core capability Continuous monitoring: Out of scope
Reconnaissance & ASM: Core capability Vulnerability assessment: Out of scope Penetration test: Core capability Red team: Core capability Hardening review: Available when included in scope Continuous monitoring: Available when included in scope
Reconnaissance & ASM: Core capability Vulnerability assessment: Available when included in scope Penetration test: Core capability Red team: Core capability Hardening review: Available when included in scope Continuous monitoring: Out of scope
Reconnaissance & ASM: Core capability Vulnerability assessment: Available when included in scope Penetration test: Available when included in scope Red team: Available when included in scope Hardening review: Available when included in scope Continuous monitoring: Out of scope
  • Core capability
  • Available when included in scope
  • Out of scope
See the full coverage matrix

04

A structured process, not just a scan

A transparent, repeatable process that turns an attacker’s view of your organization into measurable security improvements.

01

Reconnaissance

Map the attack surface relevant to your organization, including assets, exposure, people and third parties.

02

Assessment

Assess and test through vulnerability analysis, penetration testing, social engineering and red team simulation.

03

Reporting and remediation

Severity-rated findings with business impact, proof, and a prioritised remediation roadmap.

04

Resilience

Continuous monitoring, incident-response readiness and compliance — so gains hold over time.

In the field

Security testing in practice

Engagements, venues and equipment — from classified cyber ranges to security-community events.

CR14 Classified Cyber Range
01 / CR14 — classified cyber range
Field hardware testing kit
02 / Field kit — hands-on hardware testing
Security community hacker camp
03 / Hacker camps & the security community

Helpful tools

  1. 01 Scope a test Create a scoped brief in one minute
  2. 02 NIS2 / DORA scope check Check whether the regulations apply to your organization
  3. 03 Security maturity assessment Assess your organization across six domains

Trusted by organizations in the Baltics and beyond

  • LG logo
  • Eleving Group logo
  • TestDevLab logo
  • Livonia Print logo
  • Datakom logo
  • Codex logo
  • Kinetics logo
  • NMPD logo
  • Standards Digital logo
  • Jāņa Sēta logo
  • Trace Space logo

07

Certified to international standards

  • OSCP OffSec
  • Lead Pen Test Professional PECB
  • ISO/IEC 27001 Senior Lead Auditor PECB
  • Certified Information Systems Auditor ISACA
  • Red Team Operations Clarified Security
  • Critical Information Infrastructure Protection NATO CCDCOE
  • Web Applications Attack & Defence NATO CCDCOE
  • IT Systems Attack & Defense CybExer
  • Cybercrime CEPOL
  • Cyber Bite: Darkweb CEPOL
  • OSINT – Cryptocurrencies CEPOL
  • Security Awareness: Privileged Accounts SANS

What people say about working with us

At Trace.Space, security has always been a core priority — not an afterthought. As an AI platform trusted by engineering teams building regulated products in automotive, aerospace, medical and defense industries, we hold ourselves to the highest standards. Because we are shipping features at an incredible pace, we recognized that we needed a security partner capable of scaling at our velocity. That is exactly why we partner with OffSeq. We don’t want a standard checkbox compliance vendor; we want an elite partner to help us continuously take our security posture to the next level. Instead of slowing us down, they seamlessly integrate with our fast-moving engineering team, providing proactive, high-level insights that let us fortify our systems in real time as we grow. Working with OffSeq consistently proves that when you are building fast, having a world-class security partner in your corner is the best way to stay ahead of the curve.
Karlis Broders CTO · Trace.Space
We’ve had the pleasure of working with SEQ SIA (led by Nils Putniņš) on multiple information security engagements at Printful, ranging from targeted penetration testing to in-depth evaluations of our platform’s security maturity. In every project, SEQ SIA has demonstrated a rare combination of technical precision, strategic thinking, and professionalism. Most recently, during a performance and security audit of one of our core systems — used daily by thousands of employees and clients — SEQ SIA delivered beyond expectations. Their structured methodology, clear communication, and actionable insights directly contributed to increased system reliability, scalability, and resilience. SEQ SIA has become a trusted security partner, and we highly value the clarity and confidence they bring to complex security challenges.
Oskars Podziņš Head of Information Security · Printful
I had some expectations when we signed up with OffSeq. I was expecting some social engineering, routine web works to see our loopholes. Instead, they dug with passion, and they dug deep. They found holes me and my IT team were astonished to hear about. They worked from the heart and in high quality.
Andzejs Stenclavs Kinetics
We confirm that SIA “SEQ” conducted three information system security audits in 2025. The audits were carried out professionally and in full compliance with the contractual requirements. We are satisfied with the service provided. — State Emergency Medical Service of the Republic of Latvia (NMPD).
Liene Cipule Director · NMPD
Ar šo apliecinām, ka SIA “Codex” ir veiksmīgi sadarbojies ar SIA “SEQ” un tā speciālistu Nilu Putniņu vairāku nozīmīgu projektu ietvaros. Sadarbības laikā esam augsti novērtējuši SIA “SEQ” sniegto pakalpojumu kvalitāti, profesionalitāti un atbildīgo pieeju. Visas saistības veiktas norunātajos termiņos un augstā kvalitātē. Nils Putniņš ir apliecinājis sevi kā augstas klases ekspertu informācijas sistēmu drošības un kiberdrošības jomā.
Vladimirs Dagenvalds Board Member · Codex
The OffSeq team collaborated with the LG team to identify and resolve several high-severity vulnerabilities within LG’s products and services promptly. We appreciate their dedication to helping us improve the security of LG Electronics.
LG PSRT Product Security Response Team · LG Electronics
In Eleving Group security resilience is at the core of what we do across 17 markets and more than 1.8M customers. Partnering with OffSeq on a red team engagement gave us a genuine adversarial perspective that went well beyond a traditional penetration test. Their team demonstrated deep technical expertise, operated with realism and precision, and communicated findings in a way that was both clear and actionable. We came away more resilient and better informed.
Oskars Zīle CISO · Eleving Group
Working with OffSeq has been a solid experience from day one. They’ve helped us with red teaming, penetration testing, and assessments — not just for our own systems but also for some of our clients. What stands out is their practical approach — no fluff, just clear findings and actionable recommendations. They know how to dig deep, but they also understand how to communicate technical risks in a way that makes sense to different stakeholders. We’ve come to trust them as a reliable extension of our security team, and we’re looking forward to continuing the collaboration.
Viktors Trifanovs CISO · TestDevLab
We export to over 20 countries, so the security of our systems and client data isn’t something we take lightly. OffSeq ran a black-box audit that showed us exactly where we stood — no sugarcoating, just an honest picture from a real attacker’s perspective. The report worked for both our IT team and our board, which is rare. Really solid work all around.
Ivo Petrovskis Network & Security Administrator · Livonia Print
We were working with SEQ and their expert Nils Putniņš for security testing of our systems and we are happy with the results and their fast response time. We recommend SEQ and are looking forward to a long-term collaboration.
Mareks Zirdziņš Director of IT Operations · Standards Digital
SEQ and specialist Nils Putniņš performed a security audit for a project in development at Jāņa Sēta in June 2023. We are very satisfied with the test results, which helped improve the system’s security. The work was done quickly and to a high standard. We plan to keep working with SEQ.
Mareks Kilups Board Member · Jāņa Sēta

Frequently asked questions

What are your credentials as a cybersecurity provider?

OffSeq is an EU-based cybersecurity company working with organizations across Europe. Our credentials are public: credited CVEs and coordinated vulnerability disclosures; OSCP, CISA and PECB ISO/IEC 27001 Lead Auditor certifications held by the specialists who perform the work; and testing aligned with EU regulation such as NIS2, DORA and GDPR.

Will I get proof, or just a scanner dump?

Every finding is manually reproduced and assessed by severity and business impact. The report includes supporting requests, responses, payloads and specific remediation guidance. A complete sample report covering findings from Critical to Low is available on our sample-report page.

How quickly do you report critical findings?

Immediately after confirmation. Critical findings are reported as soon as they are verified, allowing remediation to begin before the final report is delivered.

Do you verify that our fixes actually worked?

Yes. A re-test is available on every engagement: we re-check each remediated finding and update its status, so you get closure, not just a list of problems.

Which regions and organization sizes do you serve?

We work with organizations across the Baltics, Scandinavia and the wider EU, from scale-ups to public institutions and large enterprises. Each engagement is scoped to the organization’s risks and timeline rather than a fixed package.

Do we need a designated cybersecurity manager under NIS2?

Organizations within the scope of NIS2 or applicable national cybersecurity law may be required to designate a person responsible for cybersecurity. Our CISO-as-a-Service can provide qualified leadership and support required reporting without the need to hire a full-time CISO.

How do you help with NIS2, DORA and ISO 27001 compliance?

We determine which obligations apply, assess gaps against the relevant controls and provide a prioritized remediation plan and evidence package. The assessment is grounded in realistic attack paths rather than a generic checklist. For DORA, we can also provide TIBER-EU-aligned threat-led penetration testing.

Define the scope of an engagement

Tell us what you need to protect. We will explain how we would test it and how to strengthen its defenses. We reply within 24 hours.