Technical Security Services

A penetration test reveals vulnerabilities at a specific point in time. Technical Security Services address the situation both before and after: they continuously reduce the attack surface, harden specific systems, prepare you for a real-world incident and verify whether your incident detection and response processes actually work. Six services that, together, transform one-off assessments into a continuous level of security.

Get in touchAll Services
Technical
Security
Continuous Protection

Sections

6 Services

Getting Started

Attack Surface Analysis

Ongoing

Vulnerability scanning

In an emergency

Incident Response

How the services relate to one another

The six services cover different phases; they do not serve the same purpose under different names.

See what is visible from the outside

Attack Surface Analysis provides an overview: what is actually accessible from the outside. This is often the most sensible first step before anything is hardened or tested.

Continuous monitoring rather than a one-off check

Vulnerability scanning and management does not replace a penetration test, but complements it by providing continuous visibility between two test dates.

Hardening specific systems

Microsoft M365 hardening is the practical implementation for one of the most widely used and, at the same time, most frequently inadequately configured environments.

Test your response

Ransomware emulation does not test your systems, but rather your SOC and your processes: it detects and stops an attack that appears to be genuine ransomware.

Raising awareness

Live-Hacking makes attacks visible and tangible to management and staff, serving as an awareness-raising exercise rather than a technical assessment.

When an incident has occurred

Incident Response takes over once an incident has actually occurred, regardless of which of the other services were previously in use.

Where to start

Your situation Suitable service
Unclear what is actually accessible from the outside Attack Surface Analysis
Frequent releases; an annual test is not enough to keep up Vulnerability scanning and management
Microsoft 365 in use, standard configuration never checked Microsoft M365 hardening
SOC or SIEM in place, but untested to see if it really works Ransomware emulation
Awareness day, staff meeting or management briefing planned Live-Hacking
An incident is currently underway or has just been detected Incident Response, emergency contact – see there

If in doubt, the rule is: if there is no ongoing incident, you usually start with an attack surface analysis; this provides the basis on which all other services can be sensibly implemented.

How the services interrelate

A typical structure looks like this: Attack Surface Analysis first identifies what is actually exposed. This is followed by the hardening of specific systems, such as M365. Vulnerability scanning continuously monitors the current status. At regular intervals, a penetration test assesses which of these vulnerabilities are actually exploitable. Ransomware emulation tests whether detection systems would even respond in a real-world incident. Live-Hacking ensures that staff and management understand the risks these measures are designed to address. And should something still happen, Incident Response is on hand.

No company necessarily needs all six services at the same time. Where you start depends on the maturity of your current security measures; we’ll clarify this during our initial consultation.

When it’s worth a look

  • The last security measure was implemented longer ago than the last major overhaul of the IT environment.
  • A SOC or SIEM has been implemented, but has never been tested under realistic conditions.
  • Microsoft 365 has essentially been running with its default configuration since its introduction.
  • Between the annual penetration tests, there is no visibility of new vulnerabilities.
  • Awareness training has so far consisted of compulsory e-learning modules that nobody actually completes.
  • An incident in the industry has raised the question of how effective the organisation’s own response would actually be.

Why Mint Secure?

All under one roof
Attack surface, hardening, detection testing and awareness come from the same team that carries out your penetration tests. The recommendations build on one another rather than contradicting each other.

Honest prioritisation
We do not automatically make a recommendation for the most comprehensive service package. If a single service is sufficient for your situation, we’ll tell you so.

Technical Security Services

Tell us where you’re at. During the initial consultation, we’ll determine which service is best suited to your level of maturity.

  • Six services covering all phases
  • From the same team that carries out your Pentests
  • Honest prioritisation rather than the broadest scope
  • Usually starting with an attack surface analysis