01 · Entry
Every attack starts with a single packet.
From the outside it looks like ordinary network traffic. The purpose of a test is to detect the threat before a real attacker exploits it.
02 · Network card
Reconnaissance and attack surface mapping.
I identify the services, ports and devices reachable from the network. I apply an attacker's methods within an agreed scope and under a formal engagement.
03 · Processor
Exploitation: from individual vulnerabilities to an attack chain.
I combine weaknesses in applications, networks and Active Directory into a path to the objective. Every step is authorised and documented.
04 · Data
Impact assessment: data and critical systems.
I demonstrate which data, accounts and OT control functions can be accessed before a real attacker takes advantage of them.
05 · Fix
Report, recommendations and retest.
I deliver a report with prioritised remediation actions, referencing IEC 62443 and NIS2. Once fixes are in place, I verify their effectiveness with a retest.