Security knowledge lives with a few people
Security depends on a few individuals and periodic testing rather than a system that survives growth and staff turnover.
A one-week, fixed-fee assessment that shows where your Product Security effort is fragmented and which gaps actually matter.
Most companies already have security activity. The harder question is whether that activity is aimed at the risks their product and customers actually face. These are the patterns that show up again and again.
Security depends on a few individuals and periodic testing rather than a system that survives growth and staff turnover.
Scanners, pentests, compliance work and tickets each run separately, with no shared definition of what actually matters.
The team cannot reliably separate findings that represent genuine risk from background noise.
Controls exist on paper, but nobody can show they hold against the threats the product actually faces.
Money is spent on tools and tests without a clear view of where intervention would change the outcome.
Findings move between teams, and no one is accountable for the outcome.
The assessment examines how your organisation handles the three areas that make up Product Security: Security Architecture, Security Engineering and Continuous Assurance.
That means looking at whether security requirements exist and are usable, whether threat and trust models reflect the real product, whether findings become engineering work, and whether anyone can tell whether a fix actually held.
Day 1
Scope, product architecture, customer commitments and the constraints the team works under.
Days 2 to 3
Existing controls, pentest and scanner output, security tickets, SDLC and release process.
Days 3 to 4
Conversations with engineering, security, product and leadership to test how security really works.
Day 5
A prioritised picture of the gaps and a roadmap for what to do about them.
You get a clear order for the work and a shared account of the situation that management, security and engineering can use.
You also get a grounded answer about what you do not need to buy, and a case for the next investment.
You get a written account of how Product Security works in your organisation today, covering security architecture, security engineering and continuous assurance. From it comes the three to five systemic gaps that matter most, rather than a list of every issue.
Those gaps become a prioritised roadmap, with owners in mind and verification criteria that give “fixed” a testable meaning. If deeper work is justified, you receive a scoped proposal. If it is not, the assessment stands on its own.
1 week
Elapsed time
€3,500 fixed fee
Fixed fee
No obligation
To continue afterwards
No generic maturity score and no pentest report. There is no obligation to continue either. If deeper work is warranted, I scope a fixed-price engagement in one or more of the three capability areas. If it is not, the assessment stands on its own.
No. A pentest tells you about a point in time and produces findings. This assessment is about whether your product security can turn findings into verified, lasting fixes. If a pentest is the right next step, the assessment will say so.
No. You do not get a generic score or a traffic-light dashboard. You get the small number of systemic gaps that matter for your product, and a prioritised route to closing them.
Usually three to six people: an engineering lead, whoever handles security day to day, a product or platform owner, and someone senior enough to act on the result. Your involvement is a handful of interviews plus a readout.
Access to architecture documentation, existing security reports and tickets, and a few conversations. No production access or sensitive customer data is required.
No. The assessment is designed to stand on its own. If deeper work makes sense, you receive a scoped, fixed-price proposal; if it does not, you keep the roadmap.
A fixed €3,500 fixed fee for 1 week, agreed before we start. Scheduling starts with a short call to confirm the assessment fits your situation.
Application Security finds and fixes bugs. Product Security keeps the security properties of your product true over time. Here is the practical difference.
Read moreProduct Security Engineering turns security requirements and threat models into engineering work that ships and stays fixed.
Read moreWhy findings pile up and how to verify a fix really removed the risk instead of marking it resolved.
Read moreA short call is enough to tell whether the assessment fits your situation. If it does not, I will say so.