Assumed breach test
How far can an attacker get after an assumed breach?
In an assumed breach test, we start from the assumption that a breach has occurred. A threat scenario determines the assessment: what objective would an attacker pursue in your organisation and which routes are relevant to it?
From question to insight
What we clarify
- How far can an attacker get from the agreed starting point?
- Which measures interrupt the scenario?
- If detection and response are in scope: which further steps are detected and followed up?
When is this relevant?
Start with what you want to know.
You want to know what happens after misuse of an account, workstation or other access. For example, when you want to test the protection of a critical process or understand how technology and detection work together.
The approach
From scenario to insight.
01
Scenario and starting point
We choose a relevant attacker objective and agree the assumed access. Optionally, we substantiate the hypothesis with threat intelligence: information about threats and methods relevant to your organisation.
02
Investigating the attack path
Our ethical hackers examine which further steps are possible. The scenario guides the test. We look at the connections between access, permissions, segmentation and the chosen objective.
03
Evidence and feedback
You receive the demonstrated attack paths, the conditions under which they worked and the measures that make a difference. If detection and response are in scope, we also discuss what was observed and followed up.
What you receive
Insight you can act on.
You see how a targeted attack could develop from the agreed starting point. Together, we translate the findings into priorities for prevention, detection and remediation.
In this assumed breach test, we examine which routes to the chosen attacker objective are possible from an agreed starting position. We agree in advance how this assessment relates to an internal penetration test.

Our approach
From assessment to clear next steps.
Read how we define the scope, carry out the assessment and discuss the results with you. With a dedicated secure data room and evidence-based reporting.
Discuss your assessment.
Tell us what you want assessed. We will help you find an approach that moves you forward.