Skip to content

Exposure Management

If an attacker decided to compromise your company today, would they succeed?

Passing compliance does not mean real resistance. SEK replicates the tactics of threat groups active in Latin America. Penetration testing, red teaming and adversary simulation with over 25 years of offensive operation and in-house tooling, to answer that question with evidence.

Request a test scopeBook an FRA session

Already know you are looking for an annual programme? Go straight to Business Takeover Simulation ↓

+800Organisations assessed in the region
+50Offensive specialists
+450Researchers in the CyScope community
+25Years of offensive operation

The surface

See everything that is exposed. Prove what is exploitable.

Four layers of the attack surface, swept continuously, from what sits outside the inventory to the internal environment. You can only validate what you can see.

OUTSIDE THE INVENTORYEXTERNAL PERIMETERCLOUDINTERNAL ENVIRONMENTCRITICAL ASSET
Continuous visibility5 verticals
EASM
External attack surface · outside the inventory

What is on the internet in the company's name, seen through the attacker's eyes.

External vuln
External vulnerability management · external perimeter

The blind spot the attacker sees first.

CSPM
Cloud posture · cloud

Configuration, legacy and excessive permissions in the cloud.

Internal vuln
Internal vulnerability management · internal environment

Internal perimeter prioritised by business context.

CTEM
Continuous technical compliance · see Governance ↓

Configuration measured against the CIS Benchmark permanently. It answers "am I compliant?", not "what do I have exposed?".

The first four verticals are contracted as a continuous programme in the Continuous exposure family. The fifth lives in Governance.

The programme

One year. Four cycles. An adversary that does not go away.

Business Takeover Simulation
Red Team · one-offTAE · quarterlyBTS · annual

Governance

From technical finding to governance decision

A technical report answers what happened. It almost never answers why it existed, who owns the fix or how you verify that it does not come back. That translation is a distinct piece of work, and it is where a finding stops being a ticket and becomes a decision.

01The technical data

Finding, evidence and real exploitability. The starting point, not the conclusion.

02The cause in the process

Why it was possible: which control was missing, which decision enabled it, what repeats elsewhere for the same reason.

03Owner, control and metric

Who owns it, which control closes it and how it is verified. With no owner, the fix depends on somebody remembering.

04Board and regulator language

The same finding expressed as business risk and as evidence of compliance.

When the goal is that the finding does not come back the following year, our governance team takes the technical data through to root cause, owner and control, using regulation as the common language. Compliance is not the destination: it is how improvement becomes verifiable by a third party.

The instruments

International standards

  • ISO 27001 ISMS implementationFrom diagnosis to certification.
  • NIST CSF 2.0 assessmentMaturity by function and an action plan.
  • CIS Controls v8 assessmentCoverage by implementation group.
  • SWIFT CSPThe customer's annual attestation.
  • Continuous technical complianceConfiguration measured against the CIS Benchmark permanently.

Local regulation by country

  • LGPD and ANPDBrazil.
  • BCB resolution and central-bank requirementsBrazil · financial institutions.
  • Personal Data Act 21.719Chile.
  • RAN 20-10 CMFChile · banking and financial institutions.
  • Financial and data regulationPeru, Colombia and Argentina.

Governance and leadership

  • Strategic advisory and cybersecurity governanceStructure, committees, policies and board metrics.
  • CISO as a ServiceDedicated security leadership, on a fractional basis.
  • Maturity assessment and multi-year planA baseline, prioritised gaps and the associated budget.
Resilience programmeResilience Acceleration Program

Where BTS answers "would we resist an attack?", RAP answers "how long would it take us to get back to operating?". A bounded intervention with a baseline, quarterly targets and executive follow-up, to move resilience from one point to another within a defined period. It lives inside the SEK method.

See the RAP method

Why SEK

Offensive operation, not catalogue penetration testing

Catalogue pentest
SEK operation
Who executes
A consultant running somebody else's tool
A team that researches and speaks at Ekoparty, 8.8 and DEF CON
Tooling
A public framework, the same for every client
In-house methodology and tooling, with offensive AI
Scope
Whatever the tool can scan
The business process that cannot fail
Execution
Automated, finds the obvious
Over 80% manual, chaining smaller flaws
Coverage
Digital perimeter
IT, OT, AI, human and physical
Deliverable
A list of CVEs
A narrative and evidence the CISO takes to the board

Next step

Two ways in

If you already know what you want to test, ask for the scope directly. If you do not know where to start, run the diagnostic first and prioritise by risk.

Request a test scope