Organisational & physical audit
Assessment of policies, procedures and physical security controls. Analysis of governance, risk management and business continuity.
Our PASSI-qualified auditors assess the security posture of your information systems: penetration testing, configuration reviews, architecture audits and organisational audit.
Audit & assessment
Brightway is a PASSI RGS audit provider qualified by ANSSI. Every engagement results in a detailed, actionable report compliant with your supervisory authorities' requirements. Our auditors cover four scopes issued by ANSSI.
ANSSI qualification
Assessment of policies, procedures and physical security controls. Analysis of governance, risk management and business continuity.
Review of technical choices, network flows and segmentation. Identification of gaps against ANSSI frameworks and sector good practice.
Analysis of system, network, application and exposed-service configurations. Review of permissions, hardening policies and applied patches.
Targeted attack simulations (black-box, grey-box, white-box) on your web applications, internal networks, cloud infrastructure and industrial systems (OT/ICS).
Methodology
Definition of scope, objectives and the level of knowledge of the audited system. Engagement agreement and authorisations signed.
Asset mapping, passive and active analysis depending on scope. Identification of exposure surfaces.
Vulnerability identification, controlled exploitation attempts, privilege escalation and lateral movement within agreed limits.
Detailed report: executive summary, CVSS-rated vulnerability sheets, prioritised recommendations and remediation plan. Presentation to technical teams and executives.
Frameworks
Our experts assess your situation and propose an action plan tailored to your challenges.