Defensive Assessment

Infrastructure Security Assessment

A defensive review of your IT environment with clear findings, priorities and a 30/60/90-day action plan.

SecureInfra dashboard visualizing findings and evidence
Structured assessmentFindings, evidence and priorities in one clear view.
Active Directory and GPO review visualization
AD & GPO reviewAccounts, permissions and policy exposure.

Understand your security baseline

We review technical evidence, configurations and operational basics without offensive testing as part of the standard scope.

  • Active Directory and account structure
  • privileged accounts and permissions
  • Windows/Linux server basics and workstation configuration
  • network access, firewall exposure and VPN
  • backup readiness
  • prioritized findings and action plan
Options

Typical entry packages for SMBs

The exact scope is defined during the initial consultation. These options make the starting point easier to understand.

Quick Security Baseline

A compact start for small environments: basic review of servers, accounts, external access and backup readiness with a short results summary.

Infrastructure Security Assessment

Full defensive assessment with AD und GPO, privileged accounts, Windows/Linux baseline, network exposure, backup readiness, executive summary and technical report.

Assessment + Managed Monitoring

Assessment as the foundation, followed by Wazuh-based monitoring, monthly KPI/trend reporting and remediation tracking.

BSI / DIN SPEC 27076

Aligned with recognized SMB security fundamentals

The assessment is written for German SMBs: clear baseline review, prioritized recommendations and understandable documentation. The BSI CyberRisikoCheck based on DIN SPEC 27076 is used as professional orientation, but the service is not presented as an official BSI service until a corresponding qualification exists.

Transparent wording: “BSI-oriented” means that we use the idea of a structured, SMB-friendly security review and extend it with technical SecureInfra checks. It is not a certificate, seal or official BSI confirmation.

Boundaries

What we deliberately do not do in the standard scope

The service is defensive, transparent and focused on improvement.

No exploits

No exploitation of vulnerabilities and no attack simulation without a separate written agreement.

No credential theft

No password theft techniques, no password spraying and no collection of credentials.

No destructive remediation

Changes are recommended and planned; production changes only happen after approval.