SSQ.AISSQ.AI

Specialized Security Assessments

Now reorganized into our service lines

You can still start from the threat that worries you. Each topic is now handled by the service that fits it best.

Below is where each of the six former topics lives now. If you are not sure where to start, tell us what worries you and we will decide together.

Where is this threat handled now? Reviewed

Each topic points to the service that fits it.

Logic protection Separation, exfiltration Personal data Malware spread Phishing, impersonation External exposure BESPOKE Bespoke validation RED TEAM Red teaming INTEL Intelligence VAPT Vulnerability testing CHECK Health Check If you're not sure
Where each of the six former topics goes now.

Where each topic is now

For each topic: which services handle it now, and which part each covers. Most topics span two services.

  • External Exposure & Attack Surface

    Assets and information visible from the internet, and signs of leaks or impersonation, are investigated in Threat & Exposure Intelligence. Whether exposed servers and admin screens can actually be exploited is tested in VAPT.

    Threat & Exposure Intelligence

    Vulnerability Assessment & Penetration Testing (VAPT)

  • Client & Service Logic Protection

    In Bespoke Security Validation, ‘App and client logic protection’ checks how much an analyzed app gives away of its core logic and security features, and whether they can be modified or bypassed. Business rules such as prices and discounts fall under ‘Business logic abuse’.

    Bespoke Security Validation

  • Phishing & Service Impersonation

    Look-alike sites and messages impersonating your company are investigated in Threat & Exposure Intelligence. Whether your organization notices and stops an attack that comes in through phishing or social engineering can be tested, if agreed, within a Red Team Assessment.

    Threat & Exposure Intelligence

    Red Team Assessment

  • Sensitive Data Exposure

    Where personal and sensitive data is kept and where it could leak is validated in the Bespoke Security Validation area of the same name. Signs that data has already leaked or is being traded outside are investigated in Threat & Exposure Intelligence.

    Bespoke Security Validation

    Threat & Exposure Intelligence

  • Malware Ingress & Internal Spread

    Whether an attack really gets from first entry to spreading inside, and whether your organization notices and stops it at each stage, is assessed in a Red Team Assessment. To check technique by technique whether spreading is detected, and fix gaps on the spot with your defenders, choose Purple Teaming & Detection Validation.

    Red Team Assessment

    Purple Teaming & Detection Validation

  • Network Separation & Data Exfiltration

    Whether network separation and exfiltration controls work as designed is validated in the Bespoke Security Validation area of the same name. Whether a realistic attack can reach the separated network, and how your organization responds, is covered by Red Teaming & Resilience Testing.

    Bespoke Security Validation

    Red Teaming & Resilience Testing

  • Not sure which threat to start with

    We look across your organization from several angles and set out where you stand and what to improve first. If your worry is hard to put into words, help! lists similar ones.

    Security Health Check

    Find similar worries on help!

Scope

The procedures and typical durations on the former page no longer apply. We agree the scope and schedule of each engagement with you.