
The report is not the result.
The remediation is.
Configuration review, secure SDLC review, hardening and compliance readiness — and the implementation too, if you want it. We are a software company: we can not only name findings but close them with your team. From €2,500.
Why the same findings come back every year
Put two pentest reports two years apart side by side and you often find the same items: missing access control in a new place, outdated dependencies, overly broad cloud permissions, secrets in the repository. That is rarely the developers' fault and almost always the surrounding system's — configuration standards that do not exist, reviews that never ask about security, a pipeline that lets everything through. An audit that only inspects does not fix this. So our work does not stop at the report: we examine the cause, propose concrete changes — and implement them with you on request.
Our audit and consulting services
Short, clearly bounded packages instead of open-ended consulting mandates
Audit and consulting by the numbers
Fixed packages, predictable effort
How an audit runs
Two days of review, one result you can act on
Kickoff and scoping
What is in scope, which access do we need, who is the contact? Usually a 30-minute call.
Inventory
Read access to configurations, repositories or cloud accounts. We look at what exists before we assess it.
Review
Comparison against hardening baselines, vendor guidance, OWASP and BSI IT-Grundschutz — combined with manual review of the critical areas.
Assessment and prioritisation
Every item with risk, effort and impact — so you can decide what happens this week and what waits for next quarter.
Action plan
Concrete changes instead of general recommendations: which setting, which value, which file, which owner.
Handover workshop
A walk-through with your team rather than a PDF by email. Questions get answered where they arise.
Implementation — optionally with us
You implement, we support selectively, or we take remediation on completely. Afterwards we verify.
Why our audit ends differently
Not with a recommendation but with a change
We can implement
The decisive difference to a pure security boutique: if you lack capacity, our developers take on remediation — within the same engagement, without onboarding another vendor.
Concrete, not generic
No recommendations in the conditional. We name the setting, the value, the file and the order — verifiable and traceable, including for auditors.
Small packages, fast results
Two days of review, the result a few days later. No consulting mandate that drags on for months until nobody can name its value.
Connects to the pentest
Audit and penetration test interlock: the test finds what is exploitable, the audit explains why it could arise. Together that is root-cause remediation.
Usable as evidence
Results are documented so they can be used in NIS2, ISO 27001 or TISAX contexts — including tracking of the agreed measures.
Knowledge transfer included
The closing workshop is not an extra but part of the engagement. Your team should avoid the next mistake themselves rather than wait for us.
Audit and consulting pricing
Fixed packages — no day-rate surprises
Security audit
Configuration and hardening
- Cloud, infrastructure or M365 review
- Permissions and network rules
- Logging and backup security
- Prioritised action plan
- Handover workshop included
Secure SDLC review
The cause, not the symptoms
- Pipeline and build process
- Dependencies and SBOM maturity
- Secrets and access management
- Review and testing practice
- Sample code review
- Developer workshop included
Compliance readiness
NIS2 or CRA
- Assessment against the testable requirements
- Prioritised gap list
- Action plan with effort estimates
- Management summary
- Recommendation for the testing scope
Frequently asked questions on audits and consulting
Clarified before you engage
The penetration test attacks: it checks from outside or inside what is actually exploitable. The audit looks inward: configuration, architecture, processes, permissions. A test finds the open door; the audit explains why the door was built and how many more exist. Combining both fixes causes instead of symptoms — which is why both are part of our Security Cycle.
Let's look behind the symptoms
In the intro call we define the review scope and tell you whether an audit, a secure SDLC review or a penetration test first delivers the greater value.