Skip to content
TheoSec

00By invitation · 90 minutes · No cost

How they'd
come for you.

Most firms open the relationship by offering you a free scan. We would rather spend the time telling your leadership something they do not already know — who would target an organisation like yours, what you are already disclosing, and where a capable attacker would start.

  • Threat actors currently working financial services
  • What your public footprint already discloses
  • The three routes in we would try first
  • Straight answers, in the room, no report to chase

//Why not a free scan

Anyone can run a tool at your perimeter.

The free assessment is the oldest move in this industry, and it is usually a scan someone automated once and now runs for every prospect. It is cheap to give away because it costs almost nothing to produce, and that is exactly what it is worth.

What is genuinely scarce is judgement — someone who has broken into organisations like yours telling you, plainly, how they would do it to you. That does not compress into a PDF, which is why this is a conversation and not a deliverable.

You should leave knowing something you did not know when you walked in. If you do not, we have wasted your time and we will say so.

01What we cover

Three things.

Built specifically for your organisation before we meet. Nothing here is a template deck with your logo dropped into the corner.

Who actually targets you

Not the generic threat landscape. The groups and motivations that credibly apply to your sector, your size and your geography.

  • Relevant actors and their usual first move
  • What they are after in an organisation like yours
  • Which of your peers have already been hit

What you already give away

A read of your public footprint as an adversary would assemble it — before any testing, using only what anyone can see.

  • What your perimeter discloses about its insides
  • People, roles and relationships worth targeting
  • Credentials and documents already in the open

Where we would start

The three routes we would try first against you, why those three, and what each would cost us in effort and noise.

  • Three concrete initial-access hypotheses
  • What would have to be true for each to work
  • Which of your controls would notice

02How it works

Four steps.

  1. 01

    Introduction

    A short call to confirm the briefing is a fit and to agree who should be in the room. We do not need access to anything.

  2. 02

    Preparation

    We spend our own time building the picture — sector threat intelligence, your public footprint, and the routes those two suggest.

  3. 03

    The briefing

    Ninety minutes with your leadership and whoever owns security. We present, then answer whatever you ask, including the awkward questions.

  4. 04

    Your move

    No proposal in the room, no follow-up sequence. If you want to talk about an engagement afterwards, you know where we are.

03Boundaries

What this is not.

This is an intelligence and perspective exercise, not testing. No packets are sent at your infrastructure and no authorisation is required, because nothing is touched.

You do get

  • A view of your organisation from the outside in
  • Named, plausible routes rather than generic advice
  • Direct answers from the person who would run the work
  • An honest read on whether you need us at all

You do not get

  • Any testing against your systems
  • A written report or scan output
  • Evidence for an auditor or a questionnaire
  • A proposal pushed at you in the room

By invitation. We run a small number of these, because each one takes real preparation time and that time has to come from somewhere. Tell us who you are and what you are responsible for, and we will tell you honestly whether it is worth both our while.