Product Security Assessment

A one-week, fixed-fee assessment that shows where your Product Security effort is fragmented and which gaps actually matter.

Discuss an assessment 1 week · €3,500 fixed fee

Why this assessment exists

Most companies already have security activity. The harder question is whether that activity is aimed at the risks their product and customers actually face. These are the patterns that show up again and again.

Security knowledge lives with a few people

Security depends on a few individuals and periodic testing rather than a system that survives growth and staff turnover.

The work is spread across separate queues

Scanners, pentests, compliance work and tickets each run separately, with no shared definition of what actually matters.

The team cannot separate risk from noise

The team cannot reliably separate findings that represent genuine risk from background noise.

Are existing controls sufficient?

Controls exist on paper, but nobody can show they hold against the threats the product actually faces.

Budget goes to tools without a clear reason

Money is spent on tools and tests without a clear view of where intervention would change the outcome.

Ownership is unclear

Findings move between teams, and no one is accountable for the outcome.

How the assessment works

The assessment examines how your organisation handles the three areas that make up Product Security: Security Architecture, Security Engineering and Continuous Assurance.

That means looking at whether security requirements exist and are usable, whether threat and trust models reflect the real product, whether findings become engineering work, and whether anyone can tell whether a fix actually held.

Day 1

Kickoff and context

Scope, product architecture, customer commitments and the constraints the team works under.

Days 2 to 3

Evidence review

Existing controls, pentest and scanner output, security tickets, SDLC and release process.

Days 3 to 4

Interviews

Conversations with engineering, security, product and leadership to test how security really works.

Day 5

Findings and readout

A prioritised picture of the gaps and a roadmap for what to do about them.

What changes for you

You get a clear order for the work and a shared account of the situation that management, security and engineering can use.

You also get a grounded answer about what you do not need to buy, and a case for the next investment.

You leave with

You get a written account of how Product Security works in your organisation today, covering security architecture, security engineering and continuous assurance. From it comes the three to five systemic gaps that matter most, rather than a list of every issue.

Those gaps become a prioritised roadmap, with owners in mind and verification criteria that give “fixed” a testable meaning. If deeper work is justified, you receive a scoped proposal. If it is not, the assessment stands on its own.

Discuss an assessment

1 week

Elapsed time

€3,500 fixed fee

Fixed fee

No obligation

To continue afterwards

No generic maturity score and no pentest report. There is no obligation to continue either. If deeper work is warranted, I scope a fixed-price engagement in one or more of the three capability areas. If it is not, the assessment stands on its own.

Common questions

Is this a penetration test?

No. A pentest tells you about a point in time and produces findings. This assessment is about whether your product security can turn findings into verified, lasting fixes. If a pentest is the right next step, the assessment will say so.

Is it a maturity assessment?

No. You do not get a generic score or a traffic-light dashboard. You get the small number of systemic gaps that matter for your product, and a prioritised route to closing them.

Who needs to be involved?

Usually three to six people: an engineering lead, whoever handles security day to day, a product or platform owner, and someone senior enough to act on the result. Your involvement is a handful of interviews plus a readout.

What do you need from us?

Access to architecture documentation, existing security reports and tickets, and a few conversations. No production access or sensitive customer data is required.

Do we have to continue afterwards?

No. The assessment is designed to stand on its own. If deeper work makes sense, you receive a scoped, fixed-price proposal; if it does not, you keep the roadmap.

How is it priced and scheduled?

A fixed €3,500 fixed fee for 1 week, agreed before we start. Scheduling starts with a short call to confirm the assessment fits your situation.

Find out where your Product Security is stuck

A short call is enough to tell whether the assessment fits your situation. If it does not, I will say so.