Services
Technical security from operators with 16+ years of Norwegian CERT/SOC experience. We build, detect, respond, and harden.
Blue Team & Detection Engineering
We build detection capabilities that catch real threats. From Sigma and YARA rules to full detection-as-code pipelines — we design, deploy, and tune detection logic tailored to your environment.
For SOC teams and organizations building or improving their detection capabilities
- Sigma/YARA/KQL detection rules
- SIEM tuning and optimization
- detection-as-code pipeline
- threat hunting reports
- SOC maturity assessment
Digital Forensics & Incident Response
When an incident hits, minutes count. We perform disk, memory, and network forensics, secure evidence with proper chain of custody, and deliver reports that hold up in court. We also offer retainer agreements for guaranteed response times.
For organizations experiencing or preparing for security incidents
- Forensic analysis (disk/memory/network)
- evidence collection and chain of custody
- malware analysis
- incident report for management/insurance/law enforcement
- retainer agreement with SLA
Security Testing & Vulnerability Assessment
Thorough technical testing of infrastructure, applications, and cloud platforms. We find the vulnerabilities before attackers do — with concrete findings and prioritized recommendations.
For organizations that want to know their technical weaknesses and close them
- Vulnerability scanning (internal/external)
- web application and API penetration testing
- Active Directory security assessment
- cloud security review (Azure/AWS/GCP)
Purple Teaming
Collaborative offense and defense in controlled exercises. We emulate real threat actors based on MITRE ATT&CK, test your detection coverage, and improve defenses together with your team.
For mature security teams looking to systematically test and improve their defenses
- MITRE ATT&CK-based adversary emulation
- detection gap analysis
- attack simulation with real-time blue team feedback
- metrics-driven improvement plan
Hardening — On-Prem & Cloud
Systematic hardening of servers, networks, Active Directory, and cloud platforms. We follow CIS benchmarks and best practices to reduce the attack surface — whether you run on-prem, hybrid, or full cloud.
For organizations looking to reduce the attack surface of their infrastructure
- Windows/Linux hardening (CIS benchmarks)
- Active Directory hardening and tiering
- Azure/M365 security configuration
- network segmentation and zero trust
- container and Kubernetes security
Tabletop Exercises & Training
Realistic exercise scenarios that test your organization's ability to handle security incidents. From ransomware scenarios for executives to technical incident response drills for the SOC team.
For management, boards, and security teams that want to practice realistic incidents
- Ransomware scenario for management
- technical IR drill for security teams
- crisis management exercise
- board cybersecurity briefing
- evaluation report with improvement actions
Risk Assessment & Security Evaluation
Structured risk assessments following ISO 27005 and NS-ISO 31000. We evaluate security posture against NSM Basic Principles and ISO 27001, providing a clear picture of where you stand and what to prioritize.
For organizations needing documented risk understanding for board or regulators
- Risk assessment (ISO 27005/31000)
- security evaluation against NSM Basic Principles
- ISO 27001 controls assessment
- third-party and supply chain risk assessment
- business impact analysis (BIA)
From assessment to security
A structured process that delivers results — without disrupting your daily operations.
Discovery
We start by understanding your business, systems, and risk exposure through conversations and technical review.
Assessment
Thorough analysis of security posture with testing, vulnerability scanning, and review of architecture and procedures.
Report & Plan
Detailed report with findings, risk ranking, and a prioritized action plan with concrete measures.
Implementation
We help implement the measures — from configuration changes to building detection capabilities.
Ready for a security assessment?
Book a no-obligation conversation and find out how we can help your organization.