Skip to main content
Security Assessment

Understand the attack surface Before you choose the remedy.

We evaluate the publicly exposed website, domain, email and services, validate findings and turn them into a technical plan prioritized by risk and impact.

Scope map

Four areas, the same context of risk.

Scope is tailored to the environment and objective of engagement. We do not add assets or testing techniques beyond authorization only to produce a longer report.

SCOPE / 01

External attack surface

Domains, subdomains, applications, public services, DNS and exposed configurations that can be observed or attacked from outside.

SCOPE / 02

Web & infrastructure posture

TLS, security headers, exposed technologies, access paths, defensive configurations and known vulnerabilities relevant to the services in scope.

SCOPE / 03

Identity & email posture

MFA and access controls where they can be evaluated, plus SPF, DKIM, DMARC and domain configurations that influence impersonation and account risk.

SCOPE / 04

Risk & remediation

Findings are explained through impact and context, then transformed into a prioritized and verifiable remedy plan.

Methodology

From scope to verification, without mysterious steps.

Value comes from validation, context, and prioritizing findings around the actual service.

01

Define scope

We set assets, averages, authorization limits and what is not valued before any technical activity.

02

Discover

We build the exposure inventory and identify technologies, services and configurations that are worth looking into in depth.

03

Validate

We check the findings enough to avoid false positives and keep the testing within the limits set for engagement.

04

Prioritize

We correlate technical severity with exploitability, exposure and impact on the service or data.

05

Report

We document the finding, relevant evidence, impact and recommended actions in a format that can be used by the technical team.

06

Remediate & verify

If it goes into scope, we help remedy and check if the change has closed the cause, not just the symptom.

Finding anatomy

A find must be able to be used.

Finding must provide enough context for the technical owner to understand the problem, decide the order, and be able to verify the remedy.

FINDING-07 / DEMO PRIORITIZED
01Finding

What we have identified and where the problem arises.

02Evidence

The minimum technical information necessary to understand or reproduce the finding safely.

03Risk

What can the problem enable and what is the actual context of exploitation or impact.

04Priority

The recommended order of remedy in relation to the other findings and addictions.

05Remediation

What needs to be changed and what compromises or checks may be needed before implementation.

06Verification

How we confirm that the remedy solved the cause without breaking the legitimate functionality.

Deliverables

The report should reduce uncertainty.

We separate the immediate risk from the recommended hardening and indicate what needs to be checked after the change so that the report can be turned into execution.

  1. 01 scope and inventory of the analyzed surface
  2. 02 Technical findings prioritized by risk and context
  3. 03 sufficient evidence for understanding and remediation
  4. 04 Technical recommendations and next steps
  5. 05 separarea problemelor urgente de hardening-ul recomandat
  6. 06 mapping to controls or compliance requirements where relevant
  7. 07 Review of results with technical owners

Rules of engagement

Assessment limits are part of security.

A good assessment is explicit about what it can test, how far it validates and what assets remain outside of authorization.

RULE-01

Authorization first

We do not extend testing to other systems, tenants or suppliers just because they appear as dependencies.

RULE-02

Assessment ≠ pentest implicit

A security assessment does not automatically become a penetration test. Active testing, exploitation and other intrusive techniques require an appropriate scope and rules for engagement.

RULE-03

Minimizing the impact

Validation must provide sufficient confidence without causing unavailability, data loss or unnecessary changes in production.

RULE-04

Secrets do not enter the public form

Passwords, private keys, recovery codes and tokens should not be sent through the public form. Required access is established through the appropriate channel after the engagement is defined.

Customer reviews

What customers say

Real feedback about security, managed hosting, support and projects delivered by ZebraByte.

I had the site full of viruses and it gave me mistakes all the time. It didn’t work properly anymore and nobody knew what it had. Those at ZebraByte helped me immediately cleaned everything, secured the site and moved it to their servers. Since then it’s gone perfectly and I haven’t had any problems anymore. It’s seen that I know what I’m doing and even getting involved. I recommend 100%!
Cosmin Szavui
Recenzie Google
I started working withZebrabytefor a few months and they delivered more than I expected. I decided to move my site to them because I had problems with the old provider and it was also viral. Those at ZebraByte have very high standards in terms of security and enterprise hosting. Their team is very professional, responds quickly to any questions, offers clear solutions and explains the meaning of everyone even if you don’t have technical knowledge. Hosting platforms are stable, fast and well protected.
Alexandra Aless
Recenzie Google
I had a bad problem with the site, I still got security alerts and weird links appeared everywhere. Those at ZebraByte immediately entered, cleaned everything and moved it to them. Since then it goes smoothly, even faster. Very serious!
Stefania Iancu
Recenzie Google
Super professional! We worked very well with this team. All requirements were solved in a very short time.
by Cristina
Recenzie Google
I have worked great with this team.
Jadu Ro
Recenzie Google
Very good team! Best cooperation i have ever seen. 10 stars!!!
Morosanu Gabriel
Recenzie Trustpilot
Excellent service, very understanding and patient with all our requests. I fully recommend ZebraByte for website designs to suit your needs!
Gabriela Ferguson
Recenzie Trustpilot

Frequently asked questions

Security Assessment este un penetration test? +

Not by default. The Assessment analyzes the exposed surface, configurations and controls within the scope. A penetration test has separate testing and authorization rules and should be agreed separately when necessary.

Do you need administrative access? +

We can start from an external perspective and extend the review to internal configurations only if the scope requires it and access is provided through an appropriate channel.

Do you also review third-party suppliers? +

We can document dependence and associated risk, but we do not test third-party infrastructure without proper authorization.

What happens after the report? +

You can fix with the existing team or provider, or ZebraByte can take certain hardening, website/email security, migration or managed security actions if they fall within scope.

Can the assessment also help with ISO27001, NIS2 or GDPR? +

Yes, technical findings and evidence can support relevant risk treatment or controls, but the Assessment does not certify the organization and does not replace the applicable compliance program or legal analysis.

Let’s start with the correct scope, not a list of tools.

Tell us what you want us to evaluate and what the business context is.We set engagement limits before any testing.

Talk about assessment
ZebraByte

Managed frameworks Managed frameworks

Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Not seeing the framework you are looking for?
Reach out — we may already support it in the programme.

SOC 2 Type 1
ISO 27001
ISO 42001
CCPA
GDPR
ISO 27701
HIPAA
FERPA
CASA
SOC 2
Talk to an expert Talk to an expert