Skip to main content
REF-INF-001

Compromise Assessments

Identifies potential security breaches and determines the extent of the compromise, analyzing network logs, system configurations, and other data sources for signs of malicious activity.

A forensic bench with drives connected to a write blocker
Objectives

What this achieves.

01

Detecting compromise

Identifies signs of unauthorized access, data exfiltration, or malicious activity across systems and networks.

02

Determining impact

Assesses the extent of a breach and its consequences to critical assets, data, and infrastructure.

03

Providing recommendations

Delivers actionable guidance on risk mitigation and restoring security measures.

04

Improving security posture

Helps identify and address the weaknesses and vulnerabilities that allowed the compromise.

Approach

Six phases.

1

Preparation

Define assessment scope, establish objectives, identify assets, and gather preliminary data.

2

Data Collection

Gather network logs, system configurations, and security tool output to detect compromise indicators.

3

Analysis

Confirm signs of compromise, determine the breach's extent, identify attack sources, and document attacker methods.

4

Assessment

Evaluate impacted systems in detail to determine organizational impact and risk level.

5

Recommendations

Provide guidance on risk mitigation, posture improvement, and system restoration.

6

Reporting

Document findings, recommendations, and mitigation actions taken.

Executive Summary Detailed Report Remediation Plan Follow-Up Review
Deliverables

What you receive.

01

Executive Summary

A high-level summary of the findings and recommendations, written for senior management and stakeholders.

02

Detailed Report

The extent of the compromise, the methods the attacker used, and the impact of what they reached.

03

Technical Documentation

The analysis itself: the tools and techniques used during the assessment, and the findings each produced.

04

Risk Mitigation Recommendations

Technical and procedural changes, security controls, and the practice needed to close the exposure.

05

Remediation Plan

Steps for restoring systems and networks to a secure state, including fixing the vulnerabilities found.

06

Follow-Up

A review to confirm the recommendations were effective and the remediation plan was actually carried out.

FAQ

Common questions.

Do we need to suspect a breach before running this?

No. The assessment looks for signs of unauthorized access, data exfiltration, or malicious activity that may already be present but has not been detected.

What data does the assessment work from?

Network logs, system configurations, and security tool output, gathered during the data collection phase and analyzed for indicators of compromise.

If something is found, do you establish how it happened?

Yes. The analysis phase confirms the compromise, determines its extent, identifies attack sources, and documents the methods used, so the weaknesses that allowed it can be addressed.

What do we receive?

An executive summary, a detailed report, a remediation plan, and a follow-up review.

Ready to scope Compromise Assessments?

Request an Assessment
Request an Assessment Email Us