Physical security · OSINT · Black teaming

Services

We work in the physical and human domain — not on the network. Here is the full range: what each service covers, what it starts from, how long it takes, and the situation it was built for.

Overview

Four families of services

The services build on each other. An assessment gives you the picture. An intrusion tests whether the picture holds when someone actively tries to bypass your security. Intelligence shows what an attacker can find out before they turn up. And training turns all of it into something that works day to day — including when nobody is watching.

Assessment

A systematic review of the security level with a score, photographic evidence and a prioritised action plan.

Intrusion

A controlled, authorised attempt to get in — from a single unannounced test to an engagement running for months.

Intelligence

A map of what lies open about you, your key people and your counterparties.

Training

Behaviour, conversation and security culture for the people who have to spot the attempt while it is happening.

Services

Five entry points

The scope is always agreed in advance. Prices are indicative, exclude VAT, and cover preparation, execution and the report.

Every engagement can be extended with network and specialist testing: passive or active network scanning, assume-breach, Wi-Fi audits, phishing and vishing campaigns, purple team and tabletop workshops. Add-ons run in parallel with the main engagement, are delivered as separate chapters in the report and are agreed in advance. All prices are indicative, exclude VAT, and are adjusted to the scope and complexity of the task.

What fits you?

Start with the question,
not with the product

Most enquiries begin in one of these four places. Find the situation that looks like yours — and the choice usually makes itself. If you are still in doubt, we can take it over the phone.

“You want the complete picture”

Security Assessment

You don't know exactly where you stand, and you need a starting point you can show the board and measure yourself against a year from now. We review the whole facility systematically, score eight categories and hand over an action plan in three phases.

Security Assessment

“You want to know whether someone can get in”

Physical Penetration Testing

You have locks, access cards, cameras and procedures — and you assume they hold. So let us try. We attempt to gain access as a real attacker would and document the path we found, and whether anyone noticed at all.

Physical Penetration Testing

“You need intelligence on a person or a company”

OSINT

Before a deal, a hire or an investment — or when you need to assess a threat against a key person. We collect what lies open, weigh the sources against each other and write down how confident we are in each conclusion.

OSINT

“You want to measure yourself against a strong adversary”

Controlled, authorised intrusion

One test is not enough if the adversary has time, money and patience. The levels turn up preparation and persistence — all the way to a months-long APT simulation and attacks routed through suppliers and partners.

If instead you want your own people to get better at spotting the attempt while it is happening, that is training. And if you need sparring on security levels, design or operational security rather than a test, we also advise by agreement — write or call.

Ground rules

Controlled. Authorised. Agreed.

Whichever service you choose, the frame is the same: a written agreement that you approve before we begin.

Scope, techniques, sensitive areas, escalation procedures and safety limitations are defined in advance. We never remove or alter anything without agreement, and there is always a point of contact on your side who can stop a test in an instant.

The purpose is never to disrupt operations or embarrass employees. The report also describes what worked — and the employees who did the right thing are named as strengths, not as failures.

Our assessments are anchored in recognised frameworks, so you can tie the findings to the requirements you already have to meet. We are not certified against them — we use them as a yardstick.

Read about the approach

Frame of reference
  • ISO 27001 (Annex A)
  • CPTED
  • F&P Sikringsguiden
  • NIS2 / CER
  • NIST SP 800-115

Next step

Test the assumptions.
Find the attack paths.

A short conversation is enough to work out whether a Security Assessment or a full penetration test is the better fit. It costs nothing and commits you to nothing.