Offensive Security

Together, we keep you one step ahead of attackers.
We support you as a strong partner in all areas of Offensive Security.

Offensive Security

Offensive Security

Offensive Security

Strengthen Your Digital Defence!

Cyberattacks are a reality: data is encrypted, companies are blackmailed, and billions in damages are caused – often, all it takes is a single careless click. The causes are not limited to technical vulnerabilities; unintended human actions are frequently a contributing factor.

Offensive Security is a proactive approach to cybersecurity in which systems, applications, devices, and security measures are assessed from the perspective of real-world attackers. Do you enjoy sports, perhaps even American Football? Some say that as a spectator, you never really understand the rules. Yet one thing becomes immediately clear: the interplay between offense and defence determines success. The same principle applies to modern IT security.

That is why IT security today requires more than mere defence. With our Offensive Security services, we support companies in closing vulnerabilities before damage occurs. We combine technical attack simulations with strategic security consulting and support you from the initial analysis through to the sustainable strengthening of your cyber resilience.

Through penetration testing and red teaming, we assess your security measures under realistic conditions. We think like real attackers, identify technical and organisational vulnerabilities, and test whether your defences can withstand an attack. Our specialised hardware laboratory also enables us to analyse IoT and embedded systems at both the device and communication levels.

In addition, we advise you on building a sustainable cyber defence strategy and provide both operational and strategic support in implementing security measures, governance and compliance requirements. Together, we optimise your individual IT security in a transparent and practical way – efficiently, clearly, and tailored to your company. Our services include secure design and the development of secure solutions from the outset, as well as the establishment of resilient operational and response processes. As your sparring partner, our experienced security experts are available to support you on all security-related topics.

Take Cyber Threats Seriously – Resilience Instead of Mere Reaction

Cyberattacks have long since become a lucrative business. According to a study by the German Digital Association Bitkom, the total damage caused to German companies in 2025 amounted to around €300 billion. At the same time, increasing connectivity, particularly through IoT and cloud technologies, is significantly expanding the attack surface for companies. As digitalisation continues to advance, new attack vectors are constantly emerging that companies need to keep an eye on in order to effectively protect their infrastructure:

These ongoing challenges make it advisable for many companies to seek external expertise in order to sustainably reduce their attack surface and ensure a high level of responsiveness and compliance.

Our service to you is to identify relevant threats and detect vulnerabilities – if required, extending to in-depth technical analyses in our hardware laboratory. In addition, we support and advise you as a strong partner in selecting and implementing appropriate security measures.

Why We Are the Right Partner For Your It Security

If you are looking for a holistic approach to IT security that combines technical expertise with strategic consulting, we are here to support you. What sets us apart:

  • Experienced security experts, penetration testers, and red teamers with relevant certifications and many years of practical experience
  • Broad range of services: secure design of IT solutions and networks, threat identification, vulnerability detection, definition of strategic and operational security measures, and development of sustainable cyber defence strategies
  • State-of-the-art testing laboratory for hardware-level analysis and reverse engineering
  • Assessments from the perspective of real-world attackers for practical and meaningful results
  • Detailed final reports, joint debriefing, and support with implementing appropriate measures upon request
  • Comprehensive security expertise across a wide range of areas: web applications and services, IT/OT infrastructures, embedded systems and IoT, automotive hardware/software, wireless protocols, and mobile applications
  • Tailored solutions adapted to your company and its specific requirements

Our Services

Penetration 
Testing

Identify vulnerabilities in networks, applications, and systems before attackers can exploit them. Our experts assess your solution from the perspective of a real-world attacker and evaluate its security level. You receive a detailed report outlining identified risks and providing concrete recommendations for action.

IoT & Embedded Penetration Testing

We analyse the security of embedded systems and IoT devices, from firmware to hardware. Using our specialised testing laboratory, we examine internal and external interfaces, communication channels, update processes, and backend connections for potential vulnerabilities.

Red
Teaming

Our red teaming services simulate realistic cyberattacks against your organisation. This approach focuses on your organisation’s ability to detect and respond to attacks rather than the number of vulnerabilities identified. The scenarios are individually tailored to your specific objectives.

Offensive Security Consulting

We support you with conceptual and strategic security matters. From security concepts and technical designs to threat and risk analyses, as well as the assessment of vulnerabilities in the context of your organisation, you benefit from our Offensive Security expertise.

Our industry-Specific Solutions

Threat-Led Penetration Testing

Meet the requirements of DORA and strengthen your digital resilience with Threat-Led Penetration Tests based on the TIBER-EU framework. Our experts simulate realistic attacks, identify vulnerabilities, and support you in specifically improving your security measures.

Healthcare Security Assessment

The digitalisation of the healthcare sector is increasing the demands on cybersecurity. We assess systems, applications, and infrastructures for potential vulnerabilities and support healthcare organisations in identifying security risks at an early stage and effectively reducing them.

OT Security
Check

The increasing connectivity of production facilities and critical infrastructure creates new risks for OT and IT environments. We support you with risk assessments, the design of secure architectures and governance structures to not only strengthen resilience but also meet regulatory requirements such as NIS-2.

Our Hardware Lab – We Test Your Entire Ecosystem, From App and Cloud to Hardware

We conduct comprehensive analyses of IoT and embedded devices and have the expertise and equipment required to assess your devices on multiple levels while delivering precise, reproducible results.

In our specialised wireless testing environment, we use a shielding enclosure to isolate test devices, such as TCUs and LTE modules. This effectively minimises interference and sources of disruption. Using various wireless analysis and testing systems, we examine a wide range of wireless technologies, including 2G, 4G (LTE), 5G, LoRaWAN, ZigBee, Wi-Fi, NFC, RFID, and Bluetooth. For analysing mobile communications, we operate a test network with our own base station. This enables us to monitor communication channels and analyse data transmissions in detail. Our test environment also allows us to capture and selectively manipulate over-the-air (OTA) firmware updates.

In addition to the wireless testing environment, our laboratory is equipped with a dedicated hardware testing station. It is designed to examine a wide range of device types both in their intact state and through targeted hardware manipulation attempts. Using various analysis tools, including logic analysers, digital oscilloscopes, and debuggers, we can precisely analyse interfaces and bus systems such as UART, SPI, and JTAG. For non-invasive testing, we use PCB holders and test probes. Upon request, we also perform more invasive manipulation and extraction attempts, for example, to access internal data stored in memory.

Laporarbeitsplatz

Excellence & Expertise

We ensure that our experts are highly qualified and continuously develop their skills. This allows us to combine certified expertise with many years of practical security experience. Our qualifications are reflected, among other things, in the following certifications:

  • Altered Security Red Team Professional for Azure (CARTP)
  • BSI IT-Grundschutz Praktiker
  • Certified Information Systems Security Professional (CISSP)
  • Certified Red Team Lead (CRTL)
  • Certified Red Team Operator (CRTO)
  • Certified Red Team Professinal (CRTP)
  • GIAC Experienced Penetration Tester (GX-PT)
  • GIAC Penetration Tester (GPEN)
  • GIAC Reverse Engineering Malware (GREM)
  • ISTQB® Certified Tester (CTFL)
  • ISTQB® Certified Tester - Advanced Level Testmanager
  • IT-Sicherheitsbeauftragter (ITSiBe) / Chief Information Security Officer (CISO)
  • OffSec Certified Expert (OSCE)
  • OffSec Certified Expert³ (OSCE3)
  • OffSec Certified Professional (OSCP)
  • OffSec Experienced Penetration Tester (OSEP)
  • OffSec Exploit Developer (OSED)
  • OffSec Web Expert (OSWE)
  • SANS IoT Penetration Testing (SEC556)
Rote Hintergrund

We Actively Contribute to Improve Cybersecurity

In targeted hacking sessions, our team systematically analyses commercially available hardware and software products for security vulnerabilities. We responsibly disclose any vulnerabilities identified to the respective manufacturers as CVEs and subsequently publish the findings in security advisories and accompanying technical articles.

By sharing our expertise transparently with the security community, we contribute to strengthening cybersecurity across the entire industry. An overview of our published vulnerabilities and technical articles can be found here.

Contact us!

Dr. Antje Winkler

Dr. Antje Winkler

Partner | Offensive Security
View bio
Luca Pascal Rotsch

Luca Pascal Rotsch

Manager | Offensive Security
View bio

Offensive Security FAQ at BDO Cyber Security GmbH

Traditional security measures such as firewalls, antivirus software, and EDR/NDR systems provide an important foundation. However, only when they are put to the test under real-world attack conditions you can determine their efficacy. Our Offensive Security experts take the perspective of a real-world attacker and uncover vulnerabilities before criminals can exploit them.

There is no one-size-fits-all solution for cybersecurity. The suitability of selected measures depends on a company’s individual starting point, industry, and risk situation. Instead of investing in technologies across the board, it is worth first conducting an honest assessment of the current situation based on a few key questions:

  • Are proven structures and plans in place?
    Emergency plans and processes need to be documented, but they are of little use if they exist only on paper and do not work in an emergency. Their effectiveness should be tested through regular emergency exercises.
  • Are measures effective and tested?
    To know what effective defence looks like, you first need to know what you actually need to protect against. Threat and risk analyses help to better assess potential threats and define appropriate measures. Penetration tests reveal whether existing security measures actually work or whether critical gaps remain despite existing security solutions.
  • Are attacks reliably detected?
    Without functioning detection and response capabilities, attackers often remain undetected in the network for weeks or months. Attack simulations, for example as part of red teaming, show how effectively attacks are detected in practice and where blind spots exist.
  • Who will help me in an emergency?
    Clear responsibilities and response processes determine how quickly and effectively a company can respond to an incident. To ensure that specialised incident response providers can provide rapid support in an emergency, it is advisable to establish contact and complete onboarding at an early stage.

The answers to these questions show where the greatest need for action lies. Based on this, a prioritised cyber defence strategy tailored to the company can be developed instead of implementing measures “on suspicion.” Professional security consulting can help assess your current situation and define appropriate next steps. Feel free to get in touch with us!

A penetration test specifically examines individual systems, applications, or networks for technical vulnerabilities – usually within a clearly defined timeframe and with a fixed test scope. The objective is to find and document as many security vulnerabilities as possible.

Red teaming goes one step further. It simulates a realistic attack on the entire company – usually without informing the internal IT or security teams. In addition to technical vulnerabilities, organisational and human factors are also tested. This approach focuses less on the number of vulnerabilities found and more on whether and how an attack remains undetected and how the company responds to it (Detection & Response).

In principle, the security level of all systems whose compromise could result in business disruptions, or security or data protection incidents should be assessed regularly. This includes:

  • Corporate networks and external infrastructure: Unsecured services, misconfigured perimeter systems, weak authentication and authorisation mechanisms, and connected third-party systems can serve as entry points for attackers into the corporate infrastructure.
  • Internet-accessible web applications and APIs: Undiscovered vulnerabilities in external web applications can be directly exploited from the internet and may enable unauthorised access to sensitive data, data loss, or operational disruptions. In addition, APIs often form the basis of modern applications and business processes. Regular API penetration tests help identify authentication, authorisation, and data processing flaws at an early stage.
  • Cloud environments: Cloud environments introduce new risks, particularly through misconfigurations, insecure permissions, and exposed management interfaces.
  • Mobile apps: If data stored locally on end devices is insufficiently protected against third-party access, insecure communication channels are used, or inadequate authentication mechanisms are implemented, attackers may gain access to confidential information, obtain unauthorised access, or compromise app functionality.
  • Critical internal applications: As critical systems often consolidate central functions, sensitive data, and extensive permissions, a successful attack can lead to significant business disruptions, substantial financial losses, or risks to security and compliance.
  • IoT and embedded devices: IoT devices are often permanently connected to networks, cloud services, and other systems, making them potential attack points. Since new vulnerabilities, outdated software, or changed configurations can create new risks at any time, regular security assessments are important.

The frequency and scope of assessments should be based on the risk profile, regulatory requirements, and importance of the respective system. Security assessments are particularly recommended before go-live and whenever major changes are made to systems or the underlying architecture.

The quality of security services such as penetration testing, red teaming, and security consulting depends largely on the provider’s experience. Companies should therefore not focus solely on price, but particularly on technical expertise, transparency in the approach, and the quality of the results.

Important selection criteria include:

  • Experience and expertise: The team should have demonstrable experience in the relevant area. Depending on the project context, this may include experience with comparable environments, technologies, and industries.
  • Qualifications: Certifications and comparable qualifications can be a good indicator of technical expertise. Depending on the focus area, these may include certifications from OffSec (OSCP, OSCE, OSEP, OSED, OSWE) and GIAC (GPEN, GX-PT, GREM) in penetration testing, CRTL, CRTO, and CRTP in red teaming, as well as CISSP or BSI IT-Grundschutz-Praktiker in security consulting.
  • Public engagement: Active contributions to the security community are an indication of well-founded expertise – for example, through the provider’s own publications, recommendations and insights, responsible disclosure of CVEs, presentations at specialist conferences, or contributions to the development of public tools, projects, and standards.
  • Reliable communication: Security is not a one-time project, but an ongoing process. A good service provider should therefore not only be a reliable point of contact during the project but also provide long-term support.

The framework of BDO Cyber Security GmbH is based on established, up-to-date standards. Depending on the specific project objectives, the following guidelines and standards are used in particular.

Penetration Testing:

  • OWASP Web Security Testing Guide (WSTG)
  • OWASP Mobile Application Security Testing Guide (MASTG)
  • OWASP IoT Security Testing Guide (ISTG), as well as a test case catalogue for hardware devices developed and maintained by BDO Cyber Security GmbH
  • Test case catalogue for IT infrastructures and infrastructure components, developed and maintained by BDO Cyber Security GmbH

Red Teaming:

  • MITRE ATT&CK Framework
  • Lockheed Martin Cyber Kill Chain
  • Threat-Led Penetration Testing in accordance with the Digital Operational Resilience Act (DORA), further development of the Threat Intelligence-based Ethical Red Teaming Framework (TIBER)

Security Assessments:

  • CIS Benchmarks for security audits and hardening checks
  • OWASP Threat Modelling for threat analysis and BSI Standard 200-3 for risk analysis
  • Requirements catalogues from regulatory frameworks, standards, and guidelines, such as NIS2, the Cyber Resilience Act, the BSI’s industry-specific security standards (B3S), as well as ETSI EN 303 645 and ETSI TS 103 701