Security Audits
Authorised security testing of infrastructure, applications and processes, with controlled validation of vulnerabilities and practical remediation guidance.
A security assessment identifies exploitable vulnerabilities, weaknesses in controls and gaps between documented requirements and actual implementation. Findings are prioritised by likelihood, technical impact and business impact.
Our methodology combines OWASP, NIST, PTES and MITRE ATT&CK guidance with manual testing. Every engagement is formally authorised and includes agreed rules of engagement, controlled exploitation, secure evidence handling, immediate escalation of critical findings and detailed activity records.
The approach can be black-box, grey-box or white-box, depending on the objectives, available access and required coverage.
How it works
01
Planning & scoping
Objectives, scope, rules of engagement, approach, timeline and authorisation.
02
Intelligence gathering
Reconnaissance, OSINT, enumeration, technology identification and attack-surface mapping.
03
Vulnerability analysis
Scanning, manual testing, configuration, auth and encryption review.
04
Exploitation & post-exploitation
Controlled exploitation, privilege escalation, lateral movement and impact assessment.
05
Analysis & reporting
Validation, risk prioritisation, root-cause analysis, technical detail and executive summary.
06
Remediation support
Findings review, fix guidance and verification re-testing (optional).
Packages
- Essential
- Focused testing for SMBs with a clear, prioritised report.
- Enterprise
- Broad assessment with architecture review and compliance gap analysis.
- Red TeamPopular
- Full-scope, multi-week adversary simulation against your defences.
Supported by our own threat-intelligence platform
Our testers don’t start from a blank page — the same intelligence platform we sell is included, so every audit is informed by live exploit and exposure data.
- OffSeq Threat Radar, opens in a new tabExplore
Current CVE and threat intelligence helps prioritise vulnerabilities relevant to your technology stack and observed exploitation activity.
- threat-finder, opens in a new tabExplore
Our open-source runtime scanner finds CVEs in the services genuinely running on your hosts, ranked by network exposure.
Frequently asked questions
How do your assessments differ from automated scanning tools?
Automated tools help identify known patterns and broad exposure, but they cannot reliably assess business logic, chained attack paths or contextual impact. Our specialists combine tooling with manual analysis, controlled validation and false-positive review, then provide remediation guidance that reflects the affected system and business context.
What qualifications do your testers hold?
We assign specialists according to the technologies and attack surface in scope. Relevant professional experience and certifications are documented in the proposal or statement of work, so you can verify the qualifications of the team assigned to your engagement.
How disruptive is security testing to normal operations?
We minimise operational impact through agreed testing windows, rate limits, exclusions, escalation contacts and stop conditions. Passive and configuration checks are generally low impact; active exploitation is performed only within the agreed rules of engagement. Red-team activity is similarly controlled, but realistic testing can never be described as entirely risk-free.
Can you test our production environment safely?
Yes, where the risk is acceptable and suitable safeguards are in place. We agree production-safe techniques, testing windows, exclusions, monitoring and rollback or stop procedures in advance. For particularly fragile or safety-critical systems, a representative non-production environment may be more appropriate.
How do you ensure the security of vulnerability information?
Assessment data is handled under agreed security and retention controls. Reports and evidence are encrypted in transit and at rest, access is restricted to authorised personnel, and project data is deleted or returned after the contractual retention period.
How often should we conduct security assessments?
Frequency should reflect risk, system change and regulatory obligations. An annual penetration test is a common baseline, with additional testing after major releases, architectural changes or incidents. Higher-risk or rapidly changing environments may require quarterly or continuous assessment; red-team exercises are most useful once foundational controls and detection capabilities are mature enough to evaluate.
Helpful tools
- Scope a test
Create a scoped brief in one minute
- Security maturity assessment
Assess your organization across six domains
Credited findings
Public disclosures and field research where this work produced citable, verifiable results.
- Pre-authentication denial of service in X-Road signature verificationGHSA-rc33-88jw-c5jp
The hash-chain verifier in X-Road’s batch-signature handling had no cycle detection, depth limit or cap on resolved steps, and the attacker-controlled chain was resolved before signature and certificate checks. A registered ecosystem member could send a small crafted request (a few KB) to trigger exponential CPU use or unbounded recursion, exhausting processing threads and disrupting the data-exchange service before authentication.
- Command injection fixed in Estonia’s national eID softwareCritical
DigiDoc4’s file-manager integration constructed shell commands using unsanitised filenames. A specially crafted filename could execute arbitrary code when a user selected the file for signing or encryption. The issue affected software used for legally binding electronic signatures.
- SWQL injection in SolarWinds PlatformCVE-2024-28996
A query-language injection vulnerability allowed an attacker to manipulate back-end database queries in the SolarWinds Platform. It was identified during penetration testing for the NATO Communications and Information Agency.
- SQL injection affecting customer data, responsibly disclosedHigh
An SQL injection vulnerability could have exposed customer data. It was reported through a responsible-disclosure process and fixed promptly. CERT.LV has publicly acknowledged our founder’s contributions to the security of Latvia’s internet space.
All services
- Red Team & Adversary Emulation
Test whether the organisation can prevent, detect and respond to a goal-driven attack.
- Social Engineering Assessment
Measure resilience to phishing, voice fraud and other social-engineering techniques.
- Purple Teaming
Validate and improve detection and response collaboratively.
Scope a test
[email protected]+371 2256 5353
Direct access to a senior specialist · Reply within 24 hours · NDA available on request