Focused engagement / NIS2

NIS2 Attack-Path Review

A fixed-scope offensive review to see whether external exposure, identity paths, and initial access can still lead to business impact.

01 / Fixed scope, clearer budget

Why this offer exists now

Most teams already have controls, policies, and older assessment reports. What they often still lack is a short offensive review that shows whether a small opening can still turn into business impact.

?

The team that scopes the review is the team that runs it and explains it back.

02

Capabilities

What we test

We do not try to cover everything. We test a plausible route from likely entry to impact and show where it breaks, or where it still holds.

Trace / 01

External exposure

What is visible, reachable, and genuinely interesting from the outside.

    Trace / 02

    Identity / AD / Entra / M365 paths

    Where permissions, trust relationships, and admin paths create real leverage after the first foothold.

      Trace / 03

      Phishing or initial-access scenario

      Short and targeted if it helps validate a plausible entry path in your environment.

        Trace / 04

        Escalation, lateral movement, and impact

        Not a list of isolated vulnerabilities: the review follows what can actually reach critical systems, roles, or data.

          03 / Operating sequence

          How the review runs

          01

          Short scoping

          01 We lock the scope, the business question, and the constraints in one focused conversation.

          02

          Attack-path validation

          02 We test the external path, the identity path, and the initial scenario where it helps.

          03

          Decision-ready debrief

          03 You get the attack narrative, the findings, and the priorities back in language people can use.

          04

          Clear next step

          04 You know what to fix first, what to retest, and when broader work makes sense.

          04

          Evidence delivered

          What you leave with

          01

          NIS2 Attack-Path Readiness Review

          Good fit if...

          • A management summary decision-makers can use
          • An attack-path walkthrough from entry point to impact
          • Technical findings prioritized in a useful order
          • A debrief that aligns security, infrastructure, and management
          • A quick retest option if you move fast on fixes
          • You need a short technical validation before an NIS2, audit, client, or board conversation.
          • You suspect identity or external exposure is the real weak point.
          • You want a clearer next step than a broad “maybe we need a red team.”
          05

          Questions before scope

          Questions before scope

          Is this a pentest or a red team?

          It sits between the two: more targeted and easier to buy than a full red team, but more attack-path driven than a narrow technical check.

          Who is this best for?

          Teams that need a credible technical answer before an NIS2 discussion, a client assurance request, or a broader resilience programme.

          How long does it take?

          Usually 1 to 2 weeks, depending on scope, contact availability, and whether phishing or initial-access validation is included.

          What do we need to prepare?

          The business-critical system or function that matters, the key constraints, and the right contacts. Where it helps, we will agree the minimum access needed to validate the path.