The surface
See everything that is exposed. Prove what is exploitable.
Four layers of the attack surface, swept continuously, from what sits outside the inventory to the internal environment. You can only validate what you can see.
What is on the internet in the company's name, seen through the attacker's eyes.
The blind spot the attacker sees first.
Configuration, legacy and excessive permissions in the cloud.
Internal perimeter prioritised by business context.
Configuration measured against the CIS Benchmark permanently. It answers "am I compliant?", not "what do I have exposed?".
The first four verticals are contracted as a continuous programme in the Continuous exposure family. The fifth lives in Governance.
Catalogue · 5 families
Five families, from continuous exposure to the persistent adversary
Organised by what is tested, not by the tool that tests. Each service states its depth: one-off, recurring or programme.
01Adversary simulationWould they detect us, and would we respond?4 services · a ladder up to the annual programme
The ladder: Table Top rehearses the decision. Red Team validates it once. TAE sustains the quarterly rhythm. Business Takeover Simulation ↓ turns that capability into an annual programme of four cycles.
02Human riskDo my people resist, and do they know how to react?13 services · we test, we strengthen, we test again
Each campaign measures individual behaviour, not the effectiveness of the email filter.
The on-site perimeter is as critical as the digital one, and it is almost never tested.
People remember what they live through. Formats that install the habit, rather than tick a training box.
03Technical assessmentIs it exploitable?8 services · scope defined by the business process
04Critical surfacesAnd what cannot stop?3 services · specialised buyer, current alliances and certifications
Three surfaces where the mistake is not measured in leaked data, but in stopped production, money moved or an automated decision nobody reviewed.
05Continuous exposureWhat do I have exposed, all the time?8 services · a subscription, not a project
An accessible entry point: Digital Risk Surface and web penetration testing validate the initial posture without the scope of a full programme. A smaller ticket, high discovery value, and usually the first step towards something broader.
The programme
One year. Four cycles. An adversary that does not go away.
Governance
From technical finding to governance decision
A technical report answers what happened. It almost never answers why it existed, who owns the fix or how you verify that it does not come back. That translation is a distinct piece of work, and it is where a finding stops being a ticket and becomes a decision.
Finding, evidence and real exploitability. The starting point, not the conclusion.
Why it was possible: which control was missing, which decision enabled it, what repeats elsewhere for the same reason.
Who owns it, which control closes it and how it is verified. With no owner, the fix depends on somebody remembering.
The same finding expressed as business risk and as evidence of compliance.
When the goal is that the finding does not come back the following year, our governance team takes the technical data through to root cause, owner and control, using regulation as the common language. Compliance is not the destination: it is how improvement becomes verifiable by a third party.
The instruments
International standards
- ISO 27001 ISMS implementationFrom diagnosis to certification.
- NIST CSF 2.0 assessmentMaturity by function and an action plan.
- CIS Controls v8 assessmentCoverage by implementation group.
- SWIFT CSPThe customer's annual attestation.
- Continuous technical complianceConfiguration measured against the CIS Benchmark permanently.
Local regulation by country
- LGPD and ANPDBrazil.
- BCB resolution and central-bank requirementsBrazil · financial institutions.
- Personal Data Act 21.719Chile.
- RAN 20-10 CMFChile · banking and financial institutions.
- Financial and data regulationPeru, Colombia and Argentina.
Governance and leadership
- Strategic advisory and cybersecurity governanceStructure, committees, policies and board metrics.
- CISO as a ServiceDedicated security leadership, on a fractional basis.
- Maturity assessment and multi-year planA baseline, prioritised gaps and the associated budget.
Where BTS answers "would we resist an attack?", RAP answers "how long would it take us to get back to operating?". A bounded intervention with a baseline, quarterly targets and executive follow-up, to move resilience from one point to another within a defined period. It lives inside the SEK method.
Why SEK
Offensive operation, not catalogue penetration testing
Next step
Two ways in
If you already know what you want to test, ask for the scope directly. If you do not know where to start, run the diagnostic first and prioritise by risk.
