Skip to content

SVC-02 · Practice

Information security assurance

Security programmes, control reviews and CEH-led penetration testing.

Likelihood almost certain · Impact severe

What this is

We help you keep the confidentiality, integrity and availability of your information systems and data intact. That runs from writing the security programme to breaking into it on purpose.

When you need it

  • You have a security policy nobody has opened since it was approved.
  • A regulator, a partner or a customer has asked for evidence of a penetration test.
  • You are moving a core workload to cloud and the security model changed underneath you.
  • Something happened, it was contained, and you still do not know how far it reached.

What we do

  • 01 Develop and implement security programmes and policies that fit how the organisation actually works.
  • 02 Review and evaluate existing controls against the threats the organisation genuinely faces.
  • 03 Perform penetration testing of IT infrastructure using our CEH-qualified team.
  • 04 Reveal existing vulnerabilities on your systems and rank them by what an attacker would reach first.
  • 05 Assist with remediation, then retest to confirm the finding is closed.

What it looks like

Findings by exploitabilityCritical 03 Reachable from outside. Reported the day it is confirmed.High 07 Reachable once inside. Fixed inside the engagement.Medium 14 Needs a chain of conditions. Scheduled, not rushed.Low 21 Recorded so the next tester is not rediscovering it.Each finding ships with reproduction steps
An extract from the working paper this practice produces. Yours carries your controls, your systems and your figures.

What you get

Penetration test report
Findings ranked by exploitability, each with reproduction steps.
Security programme
Policies, standards and the operating model that keeps them alive.
Control gap assessment
Where you stand against ISO/IEC 27001 today, stated plainly.
Retest certificate
Written confirmation that a finding is closed, for your evidence file.

SVC-02 · next step

Talk to us about information security assurance.

Send a short brief. We will come back within two working days with proposed scope, cost and duration.

Send an enquiry

+254 721 687846 taarifa@techrisk.co.ke