SERVICE / BEFORE · AFTER
Compromise assessment.
A focused hunt for signs an attacker is already inside — or still inside after an incident.

AT A GLANCE
What this covers
Who it serves
Organizations that suspect but can’t confirm compromise, are closing an acquisition, or need post-incident assurance.
Typical trigger
Odd behaviour, a peer breach, M&A due diligence, or insurer/board request.
The work
- Agree scope: endpoints, identity, email, cloud tenants
- Deploy or use existing telemetry for a time-boxed hunt
- Review identity, persistence and exfiltration indicators
- Escalate immediately to Incident Response if active compromise is found
Deliverables
- Findings with evidence and confidence level
- Indicators of compromise list
- Remediation priorities
- Executive summary
Not included
- A guarantee of no compromise — assessments reduce uncertainty within scope
- Remediation work (optional add-on)
Talk it through
Tell us where you are. We’ll recommend a sensible first step.