
Security is not a project. Security
is a cycle.
Attack surface monitoring, penetration testing, red teaming and security consulting โ four phases that feed each other instead of sitting side by side. German security lead, efficient delivery team, pricing that works for mid-sized companies.
One pentest a year is not a security programme
Most companies buy a penetration test once a year, receive a PDF, file it โ and change nothing until the next audit. Meanwhile the attack surface keeps growing: new subdomains, a forgotten staging server, a credential leaked in somebody else's breach, a deployment that skipped review. Attackers work continuously. A defence that happens once a year loses by design. That is why we do not sell isolated engagements but a cycle โ and half of it is what happens after the report.
The DeViLink Security Cycle
See. Test. Attack. Harden.
Four phases that trigger each other. You can enter at any point โ and stay in the loop instead of starting from zero every year.
Monitoring
See
What does an attacker see before they start?
Continuous monitoring of your externally reachable attack surface: domains, subdomains, exposed services, certificates, cloud storage โ plus leak monitoring for employee credentials surfacing in third-party breaches.
- External asset and service discovery
- Alerts on new exposure, not on inventory
- Credential and leak monitoring
- Monthly report for management
Finds an exposed application โ triggers phase 2.
See attack surface monitoringPenetration testing
Test
Is what is reachable also exploitable?
Manual penetration testing to OWASP, PTES and BSI standards โ web applications, APIs, cloud and infrastructure. With management summary, CVSS-prioritised findings, concrete fixes and a re-test after remediation.
- Web, API, cloud, infrastructure
- Blackbox, greybox or whitebox
- CVSS-prioritised findings with fix guidance
- Re-test after remediation included
Finds a class of bug โ triggers phase 4.
See penetration testingRed teaming
Attack
And if somebody really wants in?
Scenario-based attack simulation instead of a vulnerability list: we start from an assumed foothold and work towards a defined objective โ lateral movement, privilege escalation, data access. And we measure whether you notice.
- Assumed-breach assessment from 5 days
- Lateral movement and privilege escalation
- Detection check: what gets noticed, what doesn't
- Social engineering on request
Reveals detection gaps โ triggers phases 1 and 4.
See red teamingConsulting & audit
Harden
Why does this keep happening?
The part where most reports die: remediation. We review configuration and architecture, clear findings with your developers, anchor security in your delivery pipeline โ and produce the evidence for NIS2, CRA, ISO 27001 or TISAX along the way.
- Security audit and configuration review
- Secure SDLC review and developer workshop
- NIS2 and CRA readiness incl. action plan
- We can fix it with you, not just flag it
Raises the baseline โ back to phase 1.
See security auditThe difference to a pure security boutique: we are a software company. Remediation is our home turf โ we can not only name the findings but close them with your team.
IT security by the numbers
Professional security expertise at mid-market conditions
Regulation
The deadline is no longer an argument. It has passed.
NIS2 has applied in Germany since 6 December 2025 with no transition period. The first CRA reporting obligations became binding on 11 September 2026. If you have no evidence now, you have a problem โ not a project.
NIS2 / BSIG
Around 29,500 German companies must demonstrate risk management โ including testing the effectiveness of their measures. That is exactly what a penetration test delivers.
NIS2 & penetration testingReporting since 11 Sep 2026Cyber Resilience Act
Manufacturers of connected products and software must report actively exploited vulnerabilities within 24 hours โ including for products shipped long ago. No detection, no report.
CRA & vulnerability handlingAudit evidenceISO 27001 & TISAX
Certification and re-audits require solid technical testing. We deliver the report in the form your auditor expects โ including remediation tracking.
See security auditIndustry standardPCI-DSS & customer audits
Payment data, enterprise customers, tenders: a current pentest report is increasingly the ticket to the table, not a nice-to-have. We deliver it predictably and repeatably.
See penetration testingOur security services
Available individually โ considerably more effective as a cycle
Why DeViLink for IT security?
German leadership, efficient delivery, honest limits
German security lead
Your contact is based in Germany, runs the engagement, signs every report and can be on site when it matters. The delivery team supports preparation, scanning and re-tests.
We can also fix it
Most security providers deliver findings and disappear. We are a software company: if you lack the capacity to remediate, we take it on โ within the same engagement.
Mid-market pricing
Penetration tests from โฌ3,500 instead of the โฌ7,500โ15,000 typical in Germany for comparable scopes. Transparently calculated, verifiable upfront in the calculator.
Reports that survive audits
Management summary for leadership, technical section for your developers, evidence format for auditors. CVSS scoring, reproduction steps, remediation guidance.
A cycle, not a one-off
Monitor, test, remediate, re-test โ planned across the year as a retainer from โฌ990 per month instead of an annual fire drill.
Honest limits
We say openly what we do not do: no 24/7 SOC, no TLPT under TIBER-DE, no certification body. What we commit to, we deliver even at full capacity.
Transparent security pricing
Entry from โฌ249 per month โ or the full cycle as a retainer
Attack surface monitoring
The entry point to the cycle
- External attack surface monitoring
- Leak and credential monitoring
- Alerts on new exposure
- Monthly report
- No minimum term on the Basic plan
Security Cycle retainer
The complete cycle
- Monitoring included
- One penetration test per year
- Two audit/consulting days per year
- Re-tests after remediation
- Priority scheduling
- Compliance documentation for NIS2, ISO 27001, CRA
Single engagements
Specific, one-off need
- Security audit from โฌ2,500 (2 days)
- NIS2/CRA readiness check โฌ2,900
- Penetration test from โฌ3,500
- Assumed-breach assessment โฌ9,900
- Consulting day โฌ1,250
Frequently asked security questions
What customers ask us before the first engagement
A penetration test starts at โฌ3,500 for a small web application. The price depends on scope: number of endpoints, user roles, methodology (blackbox, greybox, whitebox), cloud infrastructure, data sensitivity and compliance requirements. Our pentest calculator lets you model your scope in two minutes and returns a solid price indication.
Start with what an attacker can see
In a 30-minute intro call we clarify your need, place it in the cycle and tell you honestly what you need now โ and what can wait.