Offensive

Assume Breach

Sooner or later the perimeter gets breached — the question is what happens next. In an Assume Breach engagement we start from a compromised standard account or machine and map how far an attacker can actually move through your environment before anyone notices. The engagement is controlled, agreed in writing and performed by independent specialists.

What the test covers

  • Starting point: an agreed standard user or machine
  • Lateral movement, privilege escalation and access to critical data
  • Detection-gap mapping — what did your defences catch along the way?
  • Controlled execution with clear rules of engagement

What you get

  • Report describing the attack chain step by step
  • Assessment of detection and response capability
  • Prioritised recommendations to break the chain

Out of scope

  • Performed only under written agreement and a defined scope
  • Destructive actions are never part of the engagement

How it works

01

Scope & starting point

We agree the starting point — a standard user or machine — plus the frame and a written agreement.

02

Controlled attack path

We move as an attacker would: lateral movement, privilege escalation and access to critical data.

03

Detection analysis

What did your defences catch along the way — and when? The gaps are mapped.

04

Report & recommendations

The attack chain step by step and prioritised recommendations to break it.

Frequently asked questions

How does Assume Breach differ from a penetration test?

A penetration test starts from the outside and tests whether someone can get in. Assume Breach starts inside — from a compromised standard account — and shows how far an attacker can get, and what your defences catch along the way.

Why assume the attacker is already inside?

Because sooner or later that is reality: phishing, reused passwords or a vulnerability grants access. Assume Breach shows the consequence of that first click — and where the chain can be broken.

Is the engagement risky for operations?

The engagement is agreed and controlled: a clear frame, time windows and escalation paths — and destructive actions are never part of it.

First step

Ready to have your security verified?

A free, no-obligation pre-analysis. A fixed price. A concrete plan you can act on right away.

Book a free pre-analysis