Cybersecurity  /  CASP

Sehen, was Angreifer already know.

CASP shows what attackers can already combine publicly — and where you break the chain. Manual, passive, signed report in ≤14 days.

FullEUR 19,9005 domains · hybrid
Litefrom EUR 7,500primary domain · fixed price
MethodePassivemanual · DNS TXT · NDA
Report≤14dafter scope approval
Services / 02

CASP first — then a targeted pentest or audit.

Do not scan first and sort later. CASP manually clarifies which public signals form a chain and which link is cheapest to break. Then you know whether an authorized penetration test, an IT security audit, or ongoing re-investigation is next.

FLAGSHIP · MANUAL · PASSIVE · DNS TXT · NDA
/ 01

Cyber Attack Surface Profiling (CASP)

Hybrid, passive OSINT investigation of your public attack surface by a named analyst with targeted automation. You see which public signals form attack chains — and get prioritized countermeasures in a signed management and technical report. Entry CASP Lite from EUR 7,500 or CASP Full EUR 19,900 (5 domains included).

  • Manually validated — no scanner dump
  • DETECT · COLLECT · PROTECT
  • Only owned or written-authorized domains
  • DNS TXT verification before start · NDA
  • Attack chains + prevention roadmap + score
  • Lite EUR 7,500 · Full EUR 19,900 · +Domain EUR 1,490
/ 02

Penetration Tests

Authorized active testing when a system, web app, or cloud scope needs targeted verification. Penetration tests start only after written approval, clear rules of engagement, and reproducible evidence.

  • Web app, API, infrastructure, cloud, or mobile
  • Black, grey, or white box depending on scope
  • OWASP WSTG / ASVS and reproducible PoCs
  • Retest after remediation
View details
/ 03

IT security audits

Structured assessment for security organization, controls, and evidence. Audits translate technical findings into verifiable actions for management, IT, customer questionnaires, and external review paths.

  • Policies, processes, and responsibilities
  • Identity, patch, backup, logging
  • NIS2, DORA, ISO 27001, and SOC 2 readiness
  • Prioritized action plan
View details
/ 04

Executive Exposure Review

Executive Exposure for executives, founders, and key people: manual, passive OSINT on personal attack surface — from EUR 5,900 per person. Scope is named people, not domain packages. Optionally bundle with domain CASP.

  • from EUR 5,900 · 1 person · +EUR 2,900 each additional
  • Scope unit: person/role (not domain count)
  • Kickoff checklist: mandate, NDA, recipients, scope list
  • 4 artifacts + 60–90 min briefing · no company BPS
View details
Methodik / 03

DETECT. COLLECT. PROTECT.

Drei Phasen, eine Untersuchung. Jeder Befund wird manuell ermittelt, quellenbasiert validiert, in Angriffsketten eingeordnet und mit Gegenmaßnahmen versehen — strikt passiv, ohne Scan und ohne Zugriff auf Ihre Infrastruktur.

/ 01 — DETECT

Discover

Manual identification of publicly available information across the approved scope: domains, subdomains, technology footprints, employee exposure, document leaks, credential breaches, and publicly visible organizational traces.

Surface web discoveryTechnology fingerprintingBreach database correlation
/ 02 — COLLECT

Triage

Konsolidierung und Korrelation verwertbarer Datenpunkte. Falsch-positive Befunde werden entfernt, Quellen nachvollziehbar dokumentiert, Risiken als realistische Angriffsketten formuliert — nicht als lose Liste.

Source corroborationAttack path modelingFalse positive elimination
/ 03 — PROTECT

Reduce

For each attack path: a concrete prevention guide with priority, ownership, and effort — readable for management and engineering.

Prevention-RoadmapImpact × effort prioritizationBriefing-Call
Attack chain — where CASP starts
Reconnaissance+Exploit+Breach=COMPROMISE
Block one step=ATTACK FAILS

Attackers often need only one entry. Defenders must secure everything. CASP models the chain and shows which link is fastest and cheapest to break — that is where prioritized measures start.

Strategic impact

DISCOVER

See what attackers see.

Validated visibility into your exposed attack surface based on publicly available information.

DISRUPT

Remove usable signals.

Prioritize exposed data and weak posture so teams can reduce the attack foundation deliberately.

DENY

Control recurrence.

Recurring cycles show whether risks return, disappear, or shift.

Review scope / 04

What the analyst reviews manually.

Sieben Kategorien, per Hand. No customer infrastructure is touched, scanned, or proxied. Only domains owned by the customer or with written authorization — verified by DNS TXT before start.

Assets & infrastructure

Owned domains, subdomains, IP ranges, ASNs, CIDR blocks, exposed services, and SSL/TLS posture.

Technologie-Footprint

Stack and version fingerprinting, end-of-life software, and exposed admin interfaces.

Domain & DNS-Posture

Registration data, DNS records, mail authentication, and clearly authorized domain relationships.

Credential & Email-Exposure

Leaked credentials in known breaches, exposed email patterns, and account takeover risk.

Document & data leaks

Public exposure of internal documents, source code, configuration, API keys, and secrets.

Human Footprint

Executives and key personnel, social-engineering vectors, and insider indicators.

Threat context

Industry-specific threat actors, recent incidents in adjacent organizations, and active campaigns.

Process & reports / 05

From approved scope to signed report and score.

Every engagement follows the same logic: clarify scope and authorization, investigate hybrid and passively, prioritize findings, hand over measures and score. Re-investigation cycles update score, findings, and trends as needed.

/ 01 — Tag 0–3

Onboarding

Scope for owned or authorized domains, brands, and relevant executives. Threat-model intake. Mutual NDA. DNS TXT verification of domain authorization before start.

Scope-DocDNS-TXTNDA
/ 02 — Tag 3–10

Investigation

Manual OSINT across all categories. Source corroboration, false-positive elimination, customer-specific attack chains, industry and role context.

Manual OSINTChain modelingContext mapping
/ 03 — Tag 10–14

Delivery

Intelligence report (exec + tech), briefing call, Breach Probability Score with baseline, prioritized prevention roadmap.

Report (PDF)Briefing 60–90 minScore + Roadmap
/ 04 — Recurring

Re-investigation

After Lite or Full: one run per chosen interval (30 / 90 / 180 days or ad-hoc). Net-new, re-verification, score and trend — EUR 4,500 per run.

30 / 90 / 180 daysNet-new + Re-CheckEUR 4,500 / run
Lieferumfang

Seven artifacts — per cycle.

  • Executive Intelligence ReportPDF · 5-10 pages · C-suite & board
  • Technical findings reportPDF · complete · security team
  • Attack scenariosNarrative + diagrams · both audiences
  • Prevention-RoadmapPrioritized actions · security team
  • Breach Probability Score1.0–10.0 · getrendet · C-Suite
  • Compliance evidenceNIS2 · DORA · ISO 27001 · SOC 2
  • Briefing-Call60–90 Minuten · zielgruppenoffen
BREACH PROBABILITY SCORE
1.010.0

Scale · SECURED to CRITICAL

SECUREDCRITICAL

A board-grade single metric for public breach exposure — signed by the analyst and updated each cycle. Management and security share the same status over time.

  • 8.0–10.0CRITICAL — immediate action
  • 6.0–7.9HIGH RISK — multiple exposures
  • 4.0–5.9MODERATE — manageable risk
  • 2.0–3.9LOW — proactive posture
  • 1.0–1.9SECURED — minimal visibility
Warum CASP / 06

Why manual reconnaissance belongs before scanners and one-off tests.

Scanners produce volume. Pentests actively test an approved scope. Audits review governance. CASP sits before that: it places public information into realistic attack chains and shows which next test or evidence path is worth it.

Automated ASM tools

Broad hit lists, often noise — without business priority or a resilient chain.

CASP → CASP validates manually and translates findings into risk and action logic. Nothing raw from the tool.

Penetration Tests

Valuable with a clear scope — but active and costly when the test space is unclear.

CASP → CASP sharpens the test space first and avoids unnecessary active tests.

Classic audits

They review processes and evidence — not what attackers can combine publicly.

CASP → CASP adds outside-in evidence and prioritized technical findings.

TXTScope verificationbefore every analysis starts
1named analystvon Scope bis signiertem Report
3target audiencesmanagement, IT, and compliance
Which test when? / 07

Which engagement answers which risk.

Threat class
CASP
Pentest
Audit
Leaked credentials & data breaches
·
·
Exposure of domains, DNS, and subdomains
·
·
Webapp-Schwachstellen (SQLi, IDOR, SSRF)
·
·
Cloud-Misconfigurations (S3, IAM, Lambda)
·
Executive & employee exposure
·
·
Document & source leaks
·
·
Compliance & NIS2 / DORA / ISO 27001 / SOC 2
·
·
Typical use cases
Control ongoing exposurePrioritize credential leaksExecutive & key-person exposureM&A: public risks before purchase or investmentCover holdings, brands, and PE portfoliosEvidence NIS2 · DORA · ISO 27001 · SOC 2Post-incident: outside-in posture after an incident

Industries: Finanz · Healthcare · Tech · Industrie · Öffentliche Hand · Bildung · Telekom. Buyers: CISOs, CTOs, SOC-Leads, Compliance, PE-/Holding-Operating-Partner.

Compliance / 08

Evidence for NIS2, DORA, ISO 27001, and SOC 2 — outside-in and traceable.

CASP does not replace legal advice, a certification audit, or a pentest. It delivers repeatable, signed evidence: which external attack surface is visible, which risks follow, and which measures were pursued.

NIS2

Make risk management and technical measures provable.

CASP supports NIS2 preparation by documenting external exposure, usable attack paths, priorities, and countermeasures. This does not replace legal advice, but it creates resilient evidence for risk and action communication.

  • public attack surface
  • prioritized countermeasures
  • management and technical report
DORA

Make ICT risks and third-party exposures tangible for financial actors.

For DORA-relevant organizations, CASP documents the publicly visible digital attack surface, usable attack chains, and prioritized remediation — as outside-in evidence for ICT risk management and supervisory communication. Not a legal opinion and not an audit substitute.

  • ICT-relevant exposure overview
  • Attack chains with priority
  • signed report per cycle
ISO 27001

Provide input for risk analysis, asset visibility, and treatment.

An ISMS needs traceable risks and documented treatment. CASP complements that work with an outside-in view of external assets, DNS/domain posture, credential exposure, and remediation history.

  • Exposure-Register
  • Finding history
  • Remediation recheck
SOC 2

Answer trust questions about security controls more concretely.

For SOC 2 and customer questionnaires, CASP provides traceable evidence that external attack surface is reviewed, assessed, and improved regularly. It is not a replacement for attestation, but an operational evidence component.

  • repeatable re-investigation
  • score and trend
  • signed report
Frame: Strikt passiv. Nur eigene oder schriftlich autorisierte Domains. DNS-TXT-Verifikation vor Start.
Next step

Ready for a scope meeting?

Entry CASP Lite from € 7.500 oder CASP Full € 19.900 (5 Domains inkl., +€ 1.490 je weitere). Re-Investigation € 4.500 pro Durchlauf — Abstand 30 / 90 / 180 Tage oder ad-hoc. Report in ≤14–21 Tagen nach Onboarding und Freigabe. Wir starten mit Domains, NDA und DNS-TXT — nicht mit einem Blind-Scan.

Lite from € 7.500 · Full € 19.900Next step
Request scope meeting