Fewer usable pretexts.
Public role and contact traces are prioritized so attackers find fewer credible entry points.
A confidential, manual outside-in review of public traces around visible decision makers. You learn which signals enable social engineering and account takeover — and receive a prioritized protection plan for the person, assistant, and IT.
The engagement ends with actions person, assistant, and IT can execute together — not a sensational list.
Public role and contact traces are prioritized so attackers find fewer credible entry points.
Leaks, old identities, and login surfaces become a concrete hardening sequence.
Person, assistant, and IT share the same warning signs and escalation rules.
Many executive risks are not in a server log. They come from combinable public details: roles, appearances, old accounts, data leaks, assistants, travel and communication patterns. Billing and scope run on named people — domains appear only as context.
We apply the same care as in company CASP analysis (manual, passive, validated, with countermeasures), but strictly person-centered. This is not private curiosity — it is about which public signals open realistic attack paths and which measures close them.
You get risks and protections — not a reusable collection of private details.
Business clients only, named people with authorization. No consumer orders, no third-party VIPs without a mandate.
Personal and company attack surface are complementary. Bundle available in a scope meeting.
There is no 1–10 firm score. Success = fewer attack signals + a prioritized protection plan.
Privacy and compliance references are operational, not legal opinions.
Focus on information attackers combine to fake trust, target accounts, or abuse communication paths — around the person.
Public profiles, responsibilities, contact paths, and details that enable credible pretexts.
Breach signals, email patterns, old accounts, and account-takeover indicators.
Relationship patterns, public schedules, assistants, vendor and partner context.
Channels and workflows through which sensitive requests reach the person and assistant.
Signal, risk, recipients, and next step stay separated. The goal is actionable reduction of personal attack surface — not another report in the archive.
Prioritized personal exposures, attack paths, recipient group, and protection priorities.
Role, relationship, and account signals by abuse path; domain only as context.
60–90 minutes: scenarios, warning signs, and approval rules for person, assistant, and escalation.
Sequence for trace reduction, account hardening, communication rules, and follow-up.
Fixed net prices. Start with one person; add more transparently. Optional: domain CASP (Lite from EUR 7,500 · Full EUR 19,900) in the same program — complementary, not a substitute.
| People | Scope | Price (net) | Duration |
|---|---|---|---|
| 1 person | Standard review · 4 artifacts · briefing 60–90 min | EUR 5,900 | 5–8 working days |
| 2 people | Two person scopes, joint prioritization | EUR 8,800 | 7–10 working days |
| 3 people | Leadership set (e.g. CEO + 2 key roles) | EUR 11,700 | 8–12 working days |
| Additional person | Extra named scope in the same engagement | + EUR 2,900 | +2–3 working days |
Tight and confidential. Work starts only after mandate, scope list, NDA, and recipients are set.
B2B mandate, named scope list, NDA, recipient group, and boundaries — in writing before start.
Manually correlate public signals, leak context, and social-engineering vectors — passive, no system access.
Separate irrelevant traces from realistically usable attack paths around the person.
Confidential handoff (60–90 min) and concrete measures for person, assistant, and IT.
Entry from EUR 5,900 for one named person. In the scope meeting we fix people, mandate, and recipients — domain CASP on request.