Proposal
Ethical Hacker as a Service (EHaaS®)
Instead of negotiating a project every time a new system appears, you engage a volume of hours and call on it when you need to: internal testing, external testing, web applications, mobile apps and retesting after the fixes. We run the monthly planning and the review meeting, and hours left over in the period carry into the renewal. It suits companies that ship often and cannot wait for the next procurement cycle.
No price appears on this page. Scope does: what we do, how we run it, who runs it and what is not included. The people who read your request are the ones who will look after you, and they come back with the proposal and with time to talk it through.
Ethical Hacker as a Service (EHaaS®)
A testing team on hand all year, without a new contract for every test.
How we run it
What this work consists of
Instead of opening a new negotiation for every new system, you contract a volume of testing hours and draw on them when needed: internal testing, external testing, web applications, mobile apps, and retesting after fixes. It is the format for teams that ship often and cannot wait for the next procurement cycle to find out whether what went live can withstand attack.
No test starts without the step that protects both sides: written scope, defined windows, emergency contacts, and formal authorization. Then come the execution, the technical report with every finding, how to reproduce it, and how to fix it, and the retest, which confirms item by item that the gap is closed. Planning is reviewed with you every month, along with hour usage.
On your side, we need formal authorization from whoever owns each environment, contacts who respond if anything goes outside the window, and someone to prioritize with us at the monthly meeting. Hours left over at the end of the period are not lost: they carry over into the renewal.
The options change how you draw on the hours. With a calendar set at the start, the plan is locked from day one, which better fits audit requirements. On demand, the hours stay available and prioritization is revisited every month, at the pace of teams that ship often. The term, twelve to twenty-four months, sets how much room you have to reschedule without losing hours.
How we conduct it, stage by stage
Planning and authorisation
We agree the scope in writing and set the windows, the emergency contacts and the formal authorisations. No test starts without that.
Execution
We run the test cycle within the authorized window and scope, starting with what usually breaks first. Every finding is recorded with the evidence and the step-by-step needed to reproduce it later.
Report
We consolidate the findings into a report where every item comes with severity, evidence and the path to fix it. We write to be read by the people who will act, not to fatten pages.
Retest
Once your team has fixed things, we come back and confirm item by item that the gap closed.
Presentation
A meeting with leadership translating the technical result into business risk and investment decisions. We arrive with the answers to the questions the board always asks: what to attack first, how much effort it takes and what happens if nothing is done.
What is not included
- Fixing the findings, which stays with your teams; we retest to confirm the gap is closed
- Continuous monitoring of the environment, which is security operations, not testing
- Testing third-party environments without formal authorization from their owner, a rule with no exceptions
- Denial-of-service attacks, given the risk of taking down your operation
- Phishing and social engineering campaigns, which have their own service
- Cash refunds for unused hours: what is left carries over into the renewal, it does not become a refund
- Purchasing tools or licenses for your environment, which stay in your company's name when needed
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.