Pre-Acquisition Security Assessment
Conduct a thorough assessment of a target company’s security risks so you can go into negotiations with confidence.
When the problem isn’t a pentest.
Incident response, purple team, tabletops and security assessments, delivered by the engineers behind our pentests and published CVEs.
Pre-Acquisition Security Assessment
Conduct a thorough assessment of a target company’s security risks so you can go into negotiations with confidence.
Figure out how they got in, what was damaged or stolen, and help you get everything back online.
Simulated ‘tabletop’ security incidents utilize a narrated discussion to engage key players in the organization.
Red meets blue in this hybrid assessment where our offensive and defensive expertise sharpen your team’s skills.
Using frameworks like CIS 18, NIST, or ISO 27001, we deliver a clear gap analysis and roadmap that pinpoints risks and guides improvements.
The SFA delivers a scaled-down maturity analysis tailored for small and mid-size businesses.
Nothing replaces skill.
We map the target’s entire internet-facing footprint: domains, subdomains, cloud assets, exposed services, and forgotten infrastructure. Asset inventories rarely match reality, and the difference is usually the risk.
We look for evidence that someone has already been inside. Undisclosed or undetected breaches are among the most costly surprises a buyer can inherit, and they are far cheaper to find before close than after.
Interviews and documentation review against recognized frameworks reveal whether the target has a functioning security program or a folder of unenforced policies. We assess what is actually practiced, not what is written down.
If the target handles cardholder data, PHI, or customer data under SOC 2 or ISO 27001 commitments, we identify where obligations are unmet and what remediation will cost you post-close.
Findings are translated into a prioritized roadmap with effort estimates, so you can quantify integration risk, adjust valuation, or negotiate specific reps and warranties.
Diligence windows are short. We scope assessments to fit your timeline and deliver a clear executive summary alongside the technical detail your engineers will want.
First priority is stopping the bleeding. We work with your team to isolate affected systems, cut off attacker access, and preserve evidence before it is overwritten, without taking down more of your business than necessary.
We reconstruct the attack timeline: initial access vector, privilege escalation path, lateral movement, and dwell time. You get a defensible account of what happened, not a guess.
What data was accessed, exfiltrated, or altered? We establish the blast radius, which drives everything downstream: legal exposure, notification obligations, and customer communications.
Attackers leave backdoors. We hunt for persistence mechanisms, implants, and rogue accounts across the environment so you do not rebuild only to be re-compromised through the same door.
We help you restore operations safely and close the gaps that allowed the intrusion, including compensating controls where a full fix is not immediately practical.
A written report suitable for executives, insurers, regulators, and counsel, plus a debrief with your technical team on the lessons that matter most.
We develop the scenario around your actual infrastructure, industry, and threat profile. Ransomware in a manufacturing OT network looks nothing like a SaaS credential compromise, and the exercise should not pretend otherwise.
A Raxis facilitator narrates the incident as it unfolds and injects complications along the way. Executives, IT, security, legal, HR, and communications all work the problem together, as they would in the real thing.
Who declares an incident? Who can authorize taking systems offline? When does the board get told? Ambiguity in the chain of command is one of the most common findings, and one of the easiest to correct.
We exercise the parts teams practice least: customer messaging, regulatory notification timelines, insurer contact, and what does and does not get said publicly while facts are still developing.
You receive a written summary of what worked, where the plan broke down, and prioritized recommendations mapped to specific owners.
Exercises map directly to requirements including CIS 18 Control 17.7, NIST 800-53 IR-3, and PCI DSS Requirement 12.10.2, and support incident response and continuity testing expectations under SOC 2, HIPAA, and ISO 27001. We document the exercise so it stands up to an auditor’s review.
Our operators run adversary techniques with your defenders informed and observing. Every action is announced, timestamped, and correlated against what your tooling actually reported.
Techniques are selected and tracked against the ATT&CK framework, producing a clear picture of which tactics you detect, which you miss, and where coverage is thinner than the dashboard suggests.
We find the alerts that never fired, the logs that were never forwarded, and the rules that were tuned into silence: the gaps that only show up when someone is deliberately exercising them.
Detections are adjusted during the engagement, then re-tested immediately. Your team ends the week with rules they have personally validated against real attacker behavior.
Your analysts work alongside experienced offensive operators and learn what the telemetry of an actual intrusion looks like. The training value outlasts the engagement.
We baseline detection and response performance at the start and re-measure at the end, giving you defensible metrics to show leadership what improved.
We evaluate your program against CIS 18, NIST CSF, NIST 800-53, or ISO 27001, whichever aligns with your obligations, using consistent criteria across every control area.
Assessment is grounded in interviews across IT, security, and business units plus review of actual documentation, configurations, and artifacts. We verify rather than take a checklist at face value.
Each control domain receives a maturity rating, so you can see at a glance whether the weakness is in identity, asset management, monitoring, vendor risk, or incident readiness.
Findings are ranked by risk reduction per unit of effort. Quick wins are separated from multi-quarter initiatives so nothing stalls waiting on a large project.
A sequenced plan with recommended owners, dependencies, and effort estimates, built so you can defend the security budget with something more substantial than a vendor pitch.
Deliverables include a technical report for your team and a concise summary written for leadership, useful for board reporting, cyber insurance applications, and customer security reviews.
We use the identical control library as our Enterprise Analysis, organized by process domain and focused on the areas that carry the most risk for organizations your size.
Structured conversations with the people who actually run your systems, often a handful of generalists rather than specialized teams. There is no prerequisite of a mature documentation set.
We review the policies, procedures, and configurations you do have, and identify the small number of documents genuinely worth creating versus the ones that only generate maintenance work.
A clear rating across each process domain shows where you are solid and where you are exposed, in plain language you can share with a non-technical owner or board.
Recommendations are sequenced and realistic for a small team’s capacity, with an emphasis on the changes that reduce the most risk for the least cost.
The output helps you answer vendor security reviews, cyber insurance applications, and early-stage SOC 2 or HIPAA readiness questions with evidence instead of guesswork.