SECURITY ASSESSMENTS WITH CLEAR PRIORITIES

Find weak points before they become critical risks.

We assess your product, infrastructure and processes within agreed boundaries. You receive validated risks, clear priorities and an action plan your team can use immediately.

Discuss an assessment What you receive in the report
Penetration testing · Cloud & pipeline · Adversary simulation · Social engineering training
Ukraine · Europe · UK & Ireland
01

Controls are in place. Their effectiveness is not yet proven.

A green dashboard does not show whether a control will detect and contain an agreed, controlled scenario.

02

Findings exist. Priorities do not.

A long list does not show which weaknesses can be combined, how they lead to impact or where to act first.

03

A report exists. The next decision is unclear.

Decision-makers need the material risk; engineers need the evidence and next step. One document should serve both.

PRACTICAL QUESTIONS

Three questions about security readiness

Readiness is established through agreed, controlled scenarios—not assumptions or dashboard status.

01

Would your team see and handle a high-impact alert outside business hours?

We agree the test window with you in advance and record what is detected, escalated and contained.

02

Which access rules or exceptions no longer match how your systems are used?

We assess the paths that matter to the engagement, then show how they could be combined.

03

Could a realistic request bypass the process designed to protect your team?

With written authorization, we test the process—not individuals—and turn the result into practical improvements.

THE ATTACK PATH

A path to impact, not a list of isolated issues

We follow a controlled route from an agreed entry point toward an agreed objective, showing where one weakness makes the next step possible.

EXAMPLE ENTRY POINTS — SELECTED FOR YOUR ENGAGEMENT
ENTRY · PEOPLE
Your employee
the email they click
ENTRY · CODE
Public repo
exposed token
ENTRY · PERIMETER
Edge service
unpatched VPN
1
Initial access
first foothold
2
CI / CD
build injection
3
Cloud IAM
role escalation
4
Production
lateral move
5
Your data
objective
WHAT CAN REMAIN UNCLEAR

A severity-sorted list can still leave the relationship between individual findings and potential impact unclear.

WHAT OUR REPORT SHOWS

An agreed route from entry point to potential impact, with the control improvements that interrupt it.

SERVICES

Six assessment formats with clear boundaries, price and delivery date.

RECON4 days

Basalt Recon

One agreed route to potential impact, assessed from the outside in.

from €2 500
PROBE8 days

Basalt Probe

Manual assessment of web applications and APIs within agreed engagement boundaries.

from €6 000
PIPELINE10 days

Basalt Pipeline

Cloud, CI/CD and supply-chain assessment of infrastructure as code, secrets, artefacts and identity paths.

from €9 000
PROOF10 days

Basalt Proof

Controlled validation of SOC or MDR detection and response against agreed ATT&CK scenarios.

from €10 000
RECORDretainer

Basalt Record

Quarterly retesting and continuous monitoring of agreed external exposure.

from €1 000/mo
RANGE2–3 days

Basalt Range

Hands-on training where engineers identify and remediate issues in a deliberately vulnerable application.

from €3 000

Everything we do, in the words you would search for

OFFENSIVE TESTING
External perimeter · internal network and Active Directory · web · API · mobile · adversary simulation · purple team · social engineering and phishing · OSINT and organisational footprint · attack surface monitoring
CLOUD, PIPELINE, SUPPLY CHAIN
AWS · Azure · GCP · Kubernetes and containers · CI/CD · infrastructure as code · secrets and key management · privilege chains and identity federation
AI, TRAINING, ASSURANCE
LLM application testing · ML supply chain · secure development workshops · social-engineering resilience · blue-team attack-chain review · quarterly retest and auditor evidence
METHOD

Clear boundaries and disciplined delivery.

Each engagement combines recognized testing standards with explicit authorization, documented handling of data and an agreed delivery process.

PTES OWASP WSTG OWASP MASTG NIST SP 800-115 MITRE ATT&CK

Clear authorization before technical work

We begin only after an authorized representative signs the letter of authorization and rules of engagement.

Agreed data-retention terms

Engagement data is destroyed thirty days after closure, including any retest period. The obligation is written into the contract.

Independent report review

A second member of the core team reviews every report before it is delivered.

A committed delivery date

The contract records the delivery date and the late-delivery terms.

THE DELIVERABLE

A report designed for decisions.

You receive a clear account of the assessment: what mattered, how impact could occur, what is working and what to do next.

Executive summary

A concise view of material risk and the decisions it requires, written for non-technical stakeholders.

The attack path

A visual route from the agreed entry point to potential impact, so teams can align on priority.

Findings

Evidence, reproduction steps and practical remediation guidance for the owners who will act on it.

What held

Controls that stopped the tested route, so you can see what is worth retaining and strengthening.

Retest included

A 30-day remediation window. We retest agreed findings and issue confirmation for your records.

Annexes

Scope, methodology, timeline, limitations and tools used.

Begin with one critical scenario.

Four days, fixed price. We test one agreed route to impact and deliver a clear view for both decision-makers and engineers.

Discuss an assessment
hello@basaltsec.com · PGP key at /.well-known/security.txt