On request
Attack surface reviews
Alongside the writing, Netivaleo takes on a small number of attack-surface reviews. This page explains what that involves, plainly. It isn't a productised service, and there's nothing to buy from a page.
What it is
A look at what your organisation exposes, from the outside and, where it's useful, from the inside. The point is a clear, honest picture of where the real risk sits, and a short list of what to fix first, rather than a dump of every theoretical finding.
How it's done
- Authorised. Nothing happens without a written, agreed scope. Anything active is limited to systems inside it.
- Passive by default. The mapping doesn't touch your running systems, which is what makes it safe for OT and industrial environments. Active checks are the exception, agreed in advance, and never run against OT.
- Identification, not exploitation. We confirm that a risk is real without exploiting it, and we don't report anything as "confirmed vulnerable" from the outside.
- Evidence you keep. You get a clear write-up and a dated record you own, useful for showing your own board or regulator that the work was done.
What it isn't
Not governance or compliance consulting, not a managed platform to run, not a pentest. Netivaleo does the technical part and is explicit about where that ends. If a gap turns out to be a network-security one, we can help close it; if it's outside our remit, we'll say so.
If it's useful to you
There's no form to fill in and no follow-up sequence. If this would help, email cs@netivaleo.com with a sentence or two about what you run, and we'll take it from there.