SVC-02 · Practice
Information security assurance
Security programmes, control reviews and CEH-led penetration testing.
Likelihood almost certain · Impact severe
What this is
We help you keep the confidentiality, integrity and availability of your information systems and data intact. That runs from writing the security programme to breaking into it on purpose.
When you need it
- You have a security policy nobody has opened since it was approved.
- A regulator, a partner or a customer has asked for evidence of a penetration test.
- You are moving a core workload to cloud and the security model changed underneath you.
- Something happened, it was contained, and you still do not know how far it reached.
What we do
- 01 Develop and implement security programmes and policies that fit how the organisation actually works.
- 02 Review and evaluate existing controls against the threats the organisation genuinely faces.
- 03 Perform penetration testing of IT infrastructure using our CEH-qualified team.
- 04 Reveal existing vulnerabilities on your systems and rank them by what an attacker would reach first.
- 05 Assist with remediation, then retest to confirm the finding is closed.
What it looks like
What you get
- Penetration test report
- Findings ranked by exploitability, each with reproduction steps.
- Security programme
- Policies, standards and the operating model that keeps them alive.
- Control gap assessment
- Where you stand against ISO/IEC 27001 today, stated plainly.
- Retest certificate
- Written confirmation that a finding is closed, for your evidence file.
SVC-02 · next step
Talk to us about information security assurance.
Send a short brief. We will come back within two working days with proposed scope, cost and duration.
+254 721 687846 taarifa@techrisk.co.ke