Boutique cyber defense / Cham, Zug, Switzerland / Founded 2019
Bespoke security for organizations
that don't fit the off-the-shelf.
A small firm of senior consultants. Most forensics specialists do not know the platform deeply, and most platform specialists do not do forensics. The work here has always needed both. The firm delivers digital forensics, incident response, advanced threat detection and transformation programs at the depth your risk requires.
What the firm does
Four postures. One standard.
Proactive
Find and close the weaknesses before an adversary does. SOC effectiveness reviews, compromise assessment and incident readiness.
Managed
Continuous defense, calibrated to a moving threat. Assurance programs and threat hunting on a set cadence.
Reactive
Answers when the case is hard, including reviewing the work of other senior teams and finishing investigations that had been written off.
Offensive
Proof of what an attacker could reach, found before anyone uses it. Penetration testing, red teaming and a review of the identity paths to Active Directory and Entra ID.
Who this is for
- Assessments that go past a check list, informed by decades of tracking advanced threat actor groups.
- Organizations that are risk averse and prefer to build resilience against the threats that actually apply to them.
- Teams that need high assurance that enterprise threat detection works as intended.
- High stakes DFIR investigations involving advanced threats, or evidence that standard tooling cannot read.
Where the firm is a poor fit
- Quality and attention to detail are not the priority.
- You want a product rollout or a managed software solution. The firm resells, hosts and maintains nothing.
- You need an audit shaped certificate more than you need deep insight.
- Off-the-shelf solutions already cover what you need.
Flagship program
CDAP
Cyber Defense Assurance Program
The Cyber Defense Assurance Program is a multi-year engagement rather than a series of unrelated projects. One named senior lead stays with the account, so the estate is learned once and then kept current.
01 / OBJECTIVE
The program works to reduce the attack surface of the organization and to raise the maturity of its security function, cycle after cycle.
02 / APPROACH
A dynamic mix of technical assessments that find the missing best practices attackers exploit, continuous threat detection, and remediation carried through to a verified close. Hardening feeds detection, and both shape response.
03 / GROWTH
The mix follows the organization. Early cycles concentrate on prevention and detection; later ones on incident response planning, tabletop and functional exercises. Findings are tracked cycle over cycle, so improvement is shown rather than claimed.