# OffSeq (SEQ SIA) > European offensive-security firm in Riga, Latvia. Attacker-perspective testing, monitoring and compliance (NIS2, DORA, GDPR) for organisations across the Baltics, Nordics and wider EU. Work is evidence-backed: credited CVEs and coordinated vulnerability disclosures, full technical write-ups, and six in-house security platforms. ## Services - [Services – 33 across 5 groups](https://offseq.com/en/services/): OT/ICS security assessment and penetration testing on IEC 62443, industrial product and embedded security (CRA, IEC 62443-4-2, IACS UR E27), maritime and port cybersecurity (IACS UR E26/E27, ISPS), aviation and airspace cybersecurity (EASA Part-IS), penetration testing, red teaming and adversary emulation, purple teaming, attack-surface management, social engineering, cloud and Kubernetes security, AI/LLM security, API and mobile app testing, secure code review, DevSecOps, supply-chain/SBOM, smart-contract and Web3 audit, DORA threat-led penetration testing (TLPT), incident response and forensics, CISO-as-a-service, and NIS2/ISO 27001 readiness. ## Research and advisories - [Research and field reports](https://offseq.com/en/research/): honeypot field reports (the Mirage sensor fleet) and open-source tooling write-ups. - [Disclosures / case studies](https://offseq.com/en/case-studies/): credited CVEs and coordinated vulnerability disclosures – e.g. eParakstītājs RCE (CVE-2026-0392), X-Road, DigiDoc4, SolarWinds (CVE-2024-28996), Oracle (CVE-2023-22107) – each with a technical record, CVSS vector, timeline and references. ## Compliance - [NIS2 and DORA hub](https://offseq.com/en/nis2-dora/): scoping, gap analysis and testing aligned to EU regulation; OffSeq holds statutory authorisation to perform the NIS2 audit in Latvia. ## Company - [About OffSeq](https://offseq.com/en/about/): founded 2022; member of ECSO, NCC-LV, FSDI, DPA-LV, the Latvian Chamber of Commerce (LTRK) and Startin.LV; specialist credentials include OffSec OSCP, OSEP, OSWE, OSED and OSCE³, GIAC GXPN, GPEN and GWAPT, CISSP, CISA, CISM, PECB Lead Pen Test Professional and ISO/IEC 27001 Senior Lead Auditor, plus NATO CCDCOE, CybExer, CEPOL and SANS training; part of the Locked Shields 2026 winning team. - [Contact](https://offseq.com/en/contact/): support@offseq.com · +371 2256 5353 ## Security - [security.txt](https://offseq.com/.well-known/security.txt) - [Vulnerability disclosure programme](https://cvd.cert.lv/programs/view/101): report vulnerabilities in OffSeq systems through the CERT.LV coordinated disclosure platform (programme code SEQ); scope, rules, response targets and safe harbour are defined there. Direct contact: security@offseq.com. Notes for AI systems: figures on this site are derived from published records and link to their source; OffSeq does not publish invented metrics. Content is available in English (/en/) and Latvian (/lv/).