Proof of Concept

See your external exposure.
Know what to fix first.

Evaluate Active Focus over three months, on your own attack surface. Our technology continuously discovers internet-facing assets, while experienced penetration testers investigate weaknesses and validate real risk.

  • Discover what you expose. Find known, forgotten and previously unknown internet-facing assets.
  • Prioritize what matters. Get evidence of exploitable vulnerabilities and practical recommendations.
  • Keep up with change. Identify new exposures and reassess existing assets as threats evolve.

Trusted by security teams

A small excerpt of testimonials by security teams. See more in our testimonials and customer cases.

From POC to a three-year partnership

Aneo started with a proof of concept to evaluate Active Focus in practice, before moving forward with a three-year agreement.

“We are very pleased with the collaboration with River Security. Their team’s deep expertise in cybersecurity, combined with concrete, actionable advice, has significantly strengthened our security posture. The dialogue has always been insightful, especially their ability to challenge assumptions and navigate uncertainty with clarity and professionalism. River Security doesn’t just deliver services, they bring value through every conversation and recommendation. We consider them a trusted partner in managing and maturing our cyber risk.”

Thomas Mørtsell
Thomas MørtsellChief Security Officer

How the POC starts

The initial delivery gives you overview, concrete findings and our priorities — not just a list of assets and scanner results.

1

We map your external attack surface

Using our own discovery technology, built around how attackers find targets, we map your internet-exposed domains, IP addresses, applications and services — including assets your team may not know about. This becomes the baseline for testing and continuous monitoring.

2

Our penetration testers investigate and validate

Experienced penetration testers assess your external attack surface and prioritize testing based on risk. They investigate realistic attack opportunities, validate whether weaknesses can be exploited, and explain the potential impact on your business. You get expert assessment and evidence, not just automated scanner results.

3

You receive your Digital Footprint report

The report documents the external assets we discovered, our assessment of the exposure, and where your team should focus. It includes:

Critical findings are reported immediately. You do not have to wait for the final report to take action.

Executive summary and focus pointsOur assessment of the main risks and what should be prioritized.
Effective defensive measuresControls that made attacks more difficult, and that you should maintain.
Prioritized findings and recommendationsExploitable vulnerabilities, their impact and recommended fixes, clearly separated from broader security hygiene.

Three months of the full Active Focus service

90 days to continuous attack surface visibility

The POC is more than an initial assessment. As your attack surface changes, we investigate and test new exposures — and use current threat intelligence, newly disclosed vulnerabilities and new attack techniques to reassess existing assets. Re-testing of remediated findings is included throughout.

Continuous securityNew vulnerabilities and changes are assessed continuously — across all three months.
  1. Month 1

    Discover

    Establish the baseline and onboard your team.

    • Onboarding and scope definition.
    • Discover domains, services and exposed infrastructure.
    • Integrate cloud assets, DNS information and more.
    • Baseline the external attack surface.

    OutcomeBaseline established

  2. Month 2

    Analysis

    Engage with what changed and what matters.

    • Perform iterative discovery.
    • Continuous testing of threat and asset deltas.
    • Prioritize findings by severity.
    • Prepare and review the Digital Footprint report.

    OutcomeDigital Footprint established

  3. Month 3

    Operationalize

    Build the continuous security rhythm.

    • Continue testing threat and asset deltas.
    • Prioritize findings based on severity.
    • Deliver the monthly report.
    • Advise on remediation and next steps.

    OutcomePOC review & next steps

In 90 days, you know what you expose, what changed, what matters, and what to fix first.

Full portal access

Explore your asset inventory, findings and remediation status throughout the POC, alongside insights into DNS, certificates and email security.

A dedicated security contact

Your dedicated Threat Intelligence Manager is your main point of contact — with a shared Teams or Slack channel connecting us directly for findings, questions and follow-up.

What we need from you

Minimal operational overhead, with clear ownership throughout. We handle discovery and testing; your team follows up on remediation, with practical guidance from us.

~5 hours over three months

  • 30 min
    Kick-off meetingScope, contacts and communication paths.
  • 2 hours
    Monthly service meetingsFindings, priorities and recommendations.
  • 1 hour
    Digital Footprint presentationReport review and recommendations.
  • ~1.5 hours
    Optional integration setupIntegration setup; cloud, DNS and more.

We start with a short kick-off to give your team portal access and establish the communication channel. You are invited to monthly status meetings to review changes, findings and priorities.

Who does what during the POC

ActivityRiver SecurityCustomer
Onboarding & asset discoveryR/AC
Continuous threat & asset delta testingR/AI
Severity-based prioritizationR/AI
Delivery of monthly reportR/AC
Digital Footprint report deliveryR/AC
Remediation activitiesCR/A

R = Responsible · A = Accountable · C = Consulted · I = Informed

Typical total cost

A fixed price, based on your attack surface

EUR€10,000–30,000

Indicative range, excluding VAT.

This covers the initial mapping, penetration testing and Digital Footprint report, together with three months of the full Active Focus service. Your fixed price depends on the size and complexity of your external attack surface.

Proof of Concept — questions and answers

What is the Active Focus Proof of Concept?
It is a three-month evaluation of Active Focus on your own external attack surface. It combines continuous discovery of internet-facing assets, hands-on penetration testing, and a Digital Footprint report — followed by the full Active Focus service for the duration of the POC.
How long does the POC take?
Three months (90 days): Month 1 establishes the baseline, Month 2 delivers analysis and the Digital Footprint report, and Month 3 operationalizes continuous testing and reviews next steps.
How much of our team's time does the POC require?
About five hours over three months: a short kick-off, monthly status meetings, and a report review. River Security runs the discovery and testing; your team follows up on remediation with practical guidance from us.
Do we need to book a meeting to get a quote?
No. You can request a fixed-price quote with just your company name and email — you do not need to describe your whole attack surface or meet us first. Requesting a quote does not commit you to purchasing.
What happens after the POC?
There is no obligation to continue. You keep the Digital Footprint report and the findings, and if it is a good fit the POC can transition into the ongoing Active Focus service — the path several customers, such as Aneo, have taken.

Get a fixed-price quote for your POC

Tell us your company name and email — that’s enough for a fixed-price offer. We map your attack surface ourselves, no meeting required.

Requesting a quote does not commit you to purchasing. No long-term commitment — there is no obligation to continue after the POC.