Initial discussion & scope
Clarify environment, goals, scope and organizational boundaries.
A structured technical baseline assessment for businesses that want to know which risks should be addressed first. Offensive testing is not part of the standard scope.
Not every company needs the same checks. Before work begins, we define which systems and roles are relevant. Missing evidence is not reported as a confirmed weakness.
Windows and Linux baselines, services, local security settings and relevant operational information.
Users, privileged roles and selected GPO, trust and delegation contexts depending on the agreed scope.
Locally bound services, firewall context, allowed source networks and evidenced external reachability are clearly distinguished.
Evidence about coverage, recency, monitoring and documented recovery tests.
Depending on the environment, IIS, RDS, SQL Server and Exchange can be added selectively.
Technical evidence is translated into understandable findings, priorities and an actionable plan.
We distinguish technical observation, reachability, exploitability and business relevance as far as possible. Unknown or uncollected information remains explicitly visible as such.
Technical collection is defensive and strictly read-only. There is no active exploitation, password spraying, credential theft or destructive change. Extended or offensive testing requires a separate written agreement.
The deliverables are designed to support decisions and implementation – not merely count findings.
Key risks, priorities and limitations in an understandable form.
Traceable findings with context, evidence and recommendations.
Prioritized sequence for immediate and planned actions.
Transparency about the evidence behind the assessment and its limitations.
Structured working list for status, ownership and follow-up.
Joint review and selection of the most sensible next steps.
Systems, responsibilities and data use are clarified before work begins. Technical collection starts only after the scope is agreed.
Clarify environment, goals, scope and organizational boundaries.
Collect agreed technical evidence read-only.
Assess results in technical context and prepare the report.
Review the report and prioritize next actions.
For the first inquiry, an approximate number of systems and a brief description of your situation are enough.