One system, scored end to end.

A focused threat risk assessment of a single application, environment or vendor deployment already in use. The tightest scope we run, and the fastest route to an answer you can act on.

What triggers this engagement.

A single system carries a decision you need to make, or a single system carries risk you cannot currently describe.

R-01Credential compromiseSample

Likelihood

5

Impact

4

Inherent

20

Residual

8

Each risk in the register carries this readout, and each number carries the reasoning that produced it.

Where the boundary sits.

A scope that is not written down is a scope that grows. Ours is agreed before work starts and it is printed in the report.

In scope
  • The application or environment itself, and the data it holds
  • The identities and access paths into it
  • Its integrations and the third parties it depends on
  • The controls already protecting it, credited where they earn it
Out of scope
  • Systems adjacent to it that share no data or trust
  • Exploitation in practice, which is what a penetration test is for
  • Remediation delivery, which we can quote separately
What we need
  • Access to the people who run and use the system
  • Any architecture or data flow documentation you hold
  • A clear statement of the decision the assessment supports
Timeline

Usually a few weeks from kickoff to final report. Scope sets the exact timeline and we agree it before any work starts.

What you receive.

One document, layered so that a board and an engineering team can both work from it.

01Executive summary written for a decision maker
02Ranked register of every risk found in the system
03Threat model mapped to STRIDE and MITRE ATT&CK
04Control recommendations matched to tools you already run
05Remediation roadmap sequenced by risk reduction

Is this the right scope for you?

Tell us the decision you are facing. If a different engagement fits better, we will say so before you commit to this one.

Request an assessment