
Dr. Antje Winkler
Offensive Security
Cyberattacks are a reality: data is encrypted, companies are blackmailed, and billions in damages are caused – often, all it takes is a single careless click. The causes are not limited to technical vulnerabilities; unintended human actions are frequently a contributing factor.
Offensive Security is a proactive approach to cybersecurity in which systems, applications, devices, and security measures are assessed from the perspective of real-world attackers. Do you enjoy sports, perhaps even American Football? Some say that as a spectator, you never really understand the rules. Yet one thing becomes immediately clear: the interplay between offense and defence determines success. The same principle applies to modern IT security.
That is why IT security today requires more than mere defence. With our Offensive Security services, we support companies in closing vulnerabilities before damage occurs. We combine technical attack simulations with strategic security consulting and support you from the initial analysis through to the sustainable strengthening of your cyber resilience.
Through penetration testing and red teaming, we assess your security measures under realistic conditions. We think like real attackers, identify technical and organisational vulnerabilities, and test whether your defences can withstand an attack. Our specialised hardware laboratory also enables us to analyse IoT and embedded systems at both the device and communication levels.
In addition, we advise you on building a sustainable cyber defence strategy and provide both operational and strategic support in implementing security measures, governance and compliance requirements. Together, we optimise your individual IT security in a transparent and practical way – efficiently, clearly, and tailored to your company. Our services include secure design and the development of secure solutions from the outset, as well as the establishment of resilient operational and response processes. As your sparring partner, our experienced security experts are available to support you on all security-related topics.
Cyberattacks have long since become a lucrative business. According to a study by the German Digital Association Bitkom, the total damage caused to German companies in 2025 amounted to around €300 billion. At the same time, increasing connectivity, particularly through IoT and cloud technologies, is significantly expanding the attack surface for companies. As digitalisation continues to advance, new attack vectors are constantly emerging that companies need to keep an eye on in order to effectively protect their infrastructure:
These ongoing challenges make it advisable for many companies to seek external expertise in order to sustainably reduce their attack surface and ensure a high level of responsiveness and compliance.
Our service to you is to identify relevant threats and detect vulnerabilities – if required, extending to in-depth technical analyses in our hardware laboratory. In addition, we support and advise you as a strong partner in selecting and implementing appropriate security measures.
If you are looking for a holistic approach to IT security that combines technical expertise with strategic consulting, we are here to support you. What sets us apart:
Identify vulnerabilities in networks, applications, and systems before attackers can exploit them. Our experts assess your solution from the perspective of a real-world attacker and evaluate its security level. You receive a detailed report outlining identified risks and providing concrete recommendations for action.
We analyse the security of embedded systems and IoT devices, from firmware to hardware. Using our specialised testing laboratory, we examine internal and external interfaces, communication channels, update processes, and backend connections for potential vulnerabilities.
Our red teaming services simulate realistic cyberattacks against your organisation. This approach focuses on your organisation’s ability to detect and respond to attacks rather than the number of vulnerabilities identified. The scenarios are individually tailored to your specific objectives.
We support you with conceptual and strategic security matters. From security concepts and technical designs to threat and risk analyses, as well as the assessment of vulnerabilities in the context of your organisation, you benefit from our Offensive Security expertise.
Meet the requirements of DORA and strengthen your digital resilience with Threat-Led Penetration Tests based on the TIBER-EU framework. Our experts simulate realistic attacks, identify vulnerabilities, and support you in specifically improving your security measures.
The digitalisation of the healthcare sector is increasing the demands on cybersecurity. We assess systems, applications, and infrastructures for potential vulnerabilities and support healthcare organisations in identifying security risks at an early stage and effectively reducing them.
The increasing connectivity of production facilities and critical infrastructure creates new risks for OT and IT environments. We support you with risk assessments, the design of secure architectures and governance structures to not only strengthen resilience but also meet regulatory requirements such as NIS-2.
We conduct comprehensive analyses of IoT and embedded devices and have the expertise and equipment required to assess your devices on multiple levels while delivering precise, reproducible results.
In our specialised wireless testing environment, we use a shielding enclosure to isolate test devices, such as TCUs and LTE modules. This effectively minimises interference and sources of disruption. Using various wireless analysis and testing systems, we examine a wide range of wireless technologies, including 2G, 4G (LTE), 5G, LoRaWAN, ZigBee, Wi-Fi, NFC, RFID, and Bluetooth. For analysing mobile communications, we operate a test network with our own base station. This enables us to monitor communication channels and analyse data transmissions in detail. Our test environment also allows us to capture and selectively manipulate over-the-air (OTA) firmware updates.
In addition to the wireless testing environment, our laboratory is equipped with a dedicated hardware testing station. It is designed to examine a wide range of device types both in their intact state and through targeted hardware manipulation attempts. Using various analysis tools, including logic analysers, digital oscilloscopes, and debuggers, we can precisely analyse interfaces and bus systems such as UART, SPI, and JTAG. For non-invasive testing, we use PCB holders and test probes. Upon request, we also perform more invasive manipulation and extraction attempts, for example, to access internal data stored in memory.

We ensure that our experts are highly qualified and continuously develop their skills. This allows us to combine certified expertise with many years of practical security experience. Our qualifications are reflected, among other things, in the following certifications: