Penetration testing
Web applications, mobile apps, perimeter, internal infrastructure, Active Directory and SAP. Hand-driven rather than a scanner dump, every finding reproducible and CVSS-rated.
See penetration testingCYBER SECURITY DÜSSELDORF
SEKurity is an offensive security firm based in Düsseldorf. From here we run penetration tests, red team operations and security awareness programmes across Germany and the rest of Europe — remote where that makes sense, on site where the test demands it.
01 · ON SITE
SEKurity is registered in Düsseldorf, which makes us the provider around the corner for companies in the Rhineland. It does not limit us to them: our pentesters work from a range of locations, and we staff every engagement with the ones who fit it technically and are closest to you. That keeps the distances short — for the technical kick-off, for questions during the test window, for the closing presentation, and for work that needs physical access: internal network segmentation, Wi-Fi, client hardening, Active Directory. Whether the site is in Düsseldorf, Hamburg or Vienna changes nothing about how the engagement runs. Travel costs apply as they do anywhere; we itemise them transparently in the quote rather than burying them in the day rate.
Registered office
SEKurity GmbH
Breite Straße 22
40213 Düsseldorf
Nordrhein-Westfalen
02 · SERVICES
Web applications, mobile apps, perimeter, internal infrastructure, Active Directory and SAP. Hand-driven rather than a scanner dump, every finding reproducible and CVSS-rated.
See penetration testingRed team operations and TIBER-EU threat-led testing — for when the question is not the vulnerability list but your own detection and response capability.
See adversary simulationPhishing campaigns and staff training. Classroom sessions are held in person at your site, which tends to work better than a recorded webinar.
See security awarenessNIS-2, DORA, KRITIS, TISAX and the Cyber Resilience Act: advice on whether you are in scope, what counts as evidence, and which tests the regulation actually requires.
See compliance advisory03 · SECTORS
Four patterns recur across sectors and countries often enough that we raise them during scoping as a matter of course. In North Rhine-Westphalia, Germany's densest industrial and services region, simply more often.
Networks grown over decades, where office IT and production were never cleanly separated. The test almost always starts at segmentation and remote maintenance access.
DORA is the driver, and with it the question of whether a conventional pentest is enough or a threat-led test is required. There are strikingly many insurers around Düsseldorf and Cologne — the answer comes out the same across Europe regardless.
KRITIS operators with reporting duties towards the BSI. Scope follows the regulation rather than the budget — which belongs in the quote, not in the report.
Many sites, many endpoints, many suppliers with access. The supply chain is regularly a shorter path into the network than the web application.
04 · ADVISORY
A report listing 40 findings is not yet a basis for a decision. So advisory work, for us, is what comes after it: which findings get fixed first, which can live with a compensating control, what of it is defensible to auditors, insurers or the supervisory board — and what a sensible next test cycle looks like. We support remediation technically and offer a retest for every engagement that confirms the closed gaps in writing.
CONTACT
An intro call costs nothing and rarely runs beyond 30 minutes. After it you will know which scope fits your situation and what it costs — whether you sit in Düsseldorf or in Vienna.