Cybersecurity Assessment

Service Overview

We assess applications, infrastructure, and internal processes to find security weaknesses before attackers do. Every engagement ends with a clear report - not just a list of problems, but fixes already applied to the issues that matter most, and a prioritized plan for the rest.

What's Included

  • Boundary Definition:
    A signed scope and rules-of-engagement document covering the applications, APIs, network segments, and (where relevant) OT/ICS zones under test.

  • SAST & DAST:
    Static analysis of source code, dependencies, and CI/CD configuration, plus dynamic testing of running applications and APIs against the OWASP Top 10 and OWASP API Top 10.

  • Secure Architecture Analysis:
    Review of trust boundaries, network segmentation, identity and access management, encryption, and third-party/vendor connectivity.

  • Compliance Verification:
    A control-by-control gap assessment against NIS2 (Article 21), IEC 62443 for OT/ICS, NIST CSF 2.0 / 800-171, or ISO/IEC 27001, depending on your sector and market.

  • Risk Management:
    Findings consolidated into a single risk register, scored by likelihood x impact and mapped to the business processes they actually affect, with a remediation roadmap your management team can sign off on.

  • Cybersecurity Fixes:
    Implementation of fixes for Critical and High findings within our control, with verification retesting. Scoped into every engagement up front, not offered as optional follow-on work.

  • Vulnerability Reporting Compatible with NIS2:
    Severity ranked for the 24-hour/72-hour/one-month notification clock, a pre-filled CSIRT notification template, an executive summary for the management body, and a technical appendix for engineering.

The Challenge

Security issues are far cheaper to fix before they're exploited than after. Our assessments give you a concrete, prioritized picture of where your systems are exposed, close the gaps ourselves for the issues that matter most, and hand you a report built to slot straight into NIS2 reporting obligations.

Transparent, Per-Application
Pricing

Pick the tier that matches your application's complexity

Small

Single-purpose internal tool or small API, limited attack surface

  • Boundary definition & rules of engagement
  • SAST & DAST
  • Secure architecture analysis
  • Compliance verification (NIS2, ISO 27001)
  • Risk register & remediation roadmap
  • Fix implementation for Critical/High + retest
  • OT/ICS-adjacent system coverage
  • NIS2-ready reporting & CSIRT template
Price: 6,000 €Get a Quote

Standard

Customer-facing or production-support app with several integrations

  • Boundary definition & rules of engagement
  • SAST & DAST
  • Secure architecture analysis
  • Compliance verification (NIS2, IEC 62443, ISO 27001)
  • Risk register & remediation roadmap
  • Fix implementation for Critical/High + retest
  • OT/ICS-adjacent system coverage
  • NIS2-ready reporting & CSIRT template
Price: 10,000 €Get a Quote

Complex

Multi-service architecture, OT-adjacent or safety-relevant system

  • Boundary definition & rules of engagement
  • SAST & DAST
  • Secure architecture analysis
  • Compliance verification (NIS2, IEC 62443, NIST CSF, ISO 27001)
  • Risk register & remediation roadmap
  • Fix implementation for Critical/High + retest
  • OT/ICS-adjacent system coverage
  • NIS2-ready reporting & CSIRT template
Price: 15,000+ €Get a Quote

Support

Frequently Asked Questions

Straight answers to what teams ask before we start working together.

A single application typically runs four to eight weeks end to end, from boundary definition through fix verification. Multi-application or OT-inclusive engagements are scoped individually.

We scope access to the minimum required, use time-boxed credentials, and sign NDAs before any assessment work starts.

We agree the scope upfront - most engagements test staging and non-critical production paths first, then expand only with your sign-off.

Fix implementation for Critical and High findings is included in the base price of every engagement, with retesting to confirm each fix actually closes the finding. Where a fix depends on a third party (a vendor patch, a budget-gated change), we hand over a ready-to-execute remediation ticket instead of a generic recommendation.

Yes. Findings are ranked to match the 24-hour early-warning / 72-hour notification / one-month final-report cadence, and we include a pre-drafted CSIRT notification template plus a board-level summary for Article 20 accountability.

Pricing is per application, in three tiers based on complexity - see the Pricing section below for exact EUR rates.