Industries served
The threat is common. The critical asset is not.
Organizations across industries face the same set of attacks, but the order of protection depends on what sustains the operation. The initial monitoring scope is defined from that analysis during implementation.
Profile
Organizational profile served
The platform was sized for a specific profile. Recording that limit in advance avoids an evaluation process that produces no result for either party.
Suitable profile
- Organizations with between 10 and 500 employees.
- No dedicated information security professional, or a single professional holding the function alongside others.
- Infrastructure managed by a small IT team or by an external vendor.
- Requirements from clients, insurers, or auditors for evidence of security controls.
- Processing of client data, internet-facing systems, or operations with a material cost of downtime.
Outside the profile
- Organizations with an established security team and their own operations center.
- A requirement for response to an incident in progress, which constitutes a distinct service.
- A need limited to obtaining certification, with no intention of executing the corrections identified.
Industry 01
Healthcare — clinics, laboratories, and small hospitals
The electronic records system admits no downtime, a material share of equipment runs on systems without manufacturer support, and patient data constitutes the most sensitive category under privacy law. An attack interrupts continuity of care directly.
Critical assets
- Electronic records and patient clinical history
- Diagnostic equipment and reporting stations on legacy systems
- Scheduling and billing systems that sustain daily operations
- Legal responsibility for sensitive personal data
Initial scope applied
- Full inventory of assets connected to the network, including undocumented equipment
- Identification of legacy systems that cannot be updated, with compensating controls defined
- Mapping of the internet-facing surface from the facility network
- Reporting to evidence diligence in audits and payer contracts
Industry 02
Professional services — accounting, law, and consulting
The central asset is client information held under professional confidentiality, and trust constitutes the product itself. Contracts with larger organizations incorporate security questionnaires at each renewal, and answering them requires documentary evidence most firms do not hold.
Critical assets
- Client documents, filings, and cases under professional confidentiality
- Credentials for third-party systems held on the client’s behalf
- Contracts conditioning renewal on evidence of controls
- Institutional reputation, where damage from a breach is difficult to reverse
Initial scope applied
- Verification of corporate credentials exposed in public and restricted databases
- Mapping of published services: client portal, corporate mail, and remote access
- Prioritization oriented to the controls requested in client security questionnaires
- Executive reporting intended to support responses to those questionnaires
Industry 03
Retail and e-commerce
Availability of the sales platform corresponds directly to revenue, and each hour of downtime represents measurable loss. The customer database associated with payment methods constitutes the target of greatest interest in attacks against the sector.
Critical assets
- Sales platform and checkout process
- Customer database and transaction history
- Integrations with payment providers, marketplaces, and logistics operators
- Administrative panels published without adequate access restriction
Initial scope applied
- Assessment of the web application against the flaw categories most frequently exploited
- Identification of administrative panels and services exposed without operational need
- Audit of the cloud configuration hosting the platform
- Continuous monitoring, given the frequency of change in the environment
Industry 04
Manufacturing, logistics, and distribution
Coexistence between the administrative network and the operations network frequently occurs through undocumented interconnection points. Production control systems remain unpatched for extended periods, since halting the line presents a cost above the perceived risk.
Critical assets
- Production control systems and equipment on discontinued software
- ERP and integrations with suppliers and clients
- Operational continuity, with downtime cost measurable by the hour
- Remote maintenance access kept active by vendors
Initial scope applied
- Identification of interconnection points between the administrative and operations networks
- Inventory of equipment running systems outside the manufacturer support period
- Survey of remote maintenance access that is active and no longer in use
- Prioritization incorporating downtime cost alongside technical severity
Establish your current exposure.
The evaluation runs against the organization’s real environment and delivers the initial security index and the prioritized risk queue within the first week.