services

What I do, and how it works.

TheOtherCompany is an independent practice.
The person who scopes the engagement is the one who tests, writes the report and presents it to your teams.

Discuss your scope → reply within a few business days

Core

Penetration testing and security audit

Web and API, Android, cloud infrastructure, Linux systems, hardware, attack simulation (phishing, physical intrusion).

Teach

Training & mentoring

Teaching in schools, in-company training, mentoring people starting out.

Defend

Consulting and support

Incident response and forensics, hardening, awareness, vulnerability management support.

Research

Research and open source

Public projects and coordinated vulnerability disclosure. Not a commercial offering: the public, verifiable proof of my work.

New to this? See what a penetration test is, the difference with an audit and what drives the price.

walkthrough

How a penetration test runs

The steps are always the same. Only the duration and scope change.

  1. Scoping

    A conversation to understand your objectives, constraints and what really matters to you. I turn it into a written proposal: scope, approach (black, grey or white box), duration and price.

  2. Rules of engagement

    Before any test: written authorisation signed by an entitled person, a precise target list, time windows, emergency contacts, forbidden actions and stop conditions.

  3. Testing

    Carried out within the agreed scope and windows. A critical vulnerability found along the way is reported to you immediately, without waiting for the report.

  4. Report

    An executive summary and a technical breakdown for your teams. Each finding comes with proof, a severity, an exploitation scenario and a realistic fix recommendation.

  5. Debrief

    A meeting to present the results, answer questions and help prioritise fixes.

  6. Retest

    Once fixes are applied, I check they are effective and update the report.

severity

Readable severity

Findings are ranked across four levels, from the CVSS score or a scale agreed with you at scoping, taking your context into account.

  • Critical
  • High
  • Medium
  • Low
deliverables

What you receive, concretely

Executive summary

One page: overall risk level and three priorities, no jargon.

Technical detail

Per vulnerability: proof, CVSS severity, reproduction steps, fix.

Fix tracking

A table to steer remediation and prepare the retest.

Debrief

A meeting with your teams to prioritise and answer questions.

An anonymised sample report is available on request.

Let's discuss your needs

Got a scope in mind? Let's map it out. Single day rate of €1,100 (excl. VAT).

Reply within a few business days, no commitment.