Build Resilience from the Inside Out

Assumed Breach

Put our penetration testers on the inside and ensure your networks can withstand the intrusion.

  1. Instead of waiting for a threat on the inside, River Security emulates it.

  2. Defenses should be built in-depth to not only withstand but to detect. River Security will pin-point the gaps.

  3. With River Security’s specialized methodology, customers gain both long-term strategic security direction and immediate, actionable measures.

Why “Assumed Breach” Matters

Adopting the mindset that users will get breached, and networks must be able to withstand it, is critical. Assumed breach means that River Security assumes the role of a breached user, and helps point out the weaknesses and flaws of the organization in that situation.

Raymond Strandheim, Principal Penetration Tester

Users may unintentionally get breached, but sometimes breach is done by a trusted insider intentionally. Organizations should be able to withstand these risks.

Raymond StrandheimPrincipal Penetration Tester at River Security

Why Customers Benefit from Assumed Breach

Traditional testing spends most of its effort proving whether an attacker can get in. But in practice, initial access is rarely the hard part, a single phished credential, an unpatched service, or a careless third party is often enough. The damaging question is what happens next: how far can an intruder move once they already have a foothold?

Assumed breach answers that question directly. We start from the position of a compromised user or insider and test how well your organization contains, detects, and responds to the intrusion from there. This gives you a realistic picture of your true internal resilience, not just the strength of your outer wall.

  • A realistic view of real-world risk

    Attackers assume they will eventually get in, and so should you. By emulating a breach that has already happened, you see the risks that actually lead to material damage: lateral movement, privilege escalation, and access to sensitive data.

  • Focus budget where it matters

    Skipping the perimeter phase means our testers spend their time where the real impact lives, inside your network. You get more depth, more attack paths, and more actionable findings for the same investment.

  • Validate detection and response

    Prevention will eventually fail; detection is what limits the blast radius. Assumed breach shows whether your SOC, EDR, and monitoring actually catch an intruder moving through the environment, or whether they slip by unnoticed.

  • Test defense in depth

    We pin-point the gaps between your layers, weak segmentation, over-privileged accounts, and blind spots in logging, so defenses hold even after the first control is bypassed.

  • Cover the insider threat

    Not every breach comes from the outside. Assumed breach accounts for the malicious or compromised insider, a blind spot that perimeter-focused testing rarely addresses.

  • Clear, prioritized next steps

    You leave with proof-of-concept impact, a prioritized list of the most critical risks, and both short- and long-term remediation guidance, so you know exactly what to fix first.

Penetration test report

In Practice, What to Expect from our Delivery

Expect a fast paced and hard hitting delivery from our team of penetration testers. On the inside, they will look for gaps through network and application controls, ensuring our customers get a report detailing short and long term best practices, but also highlighting notable defensive measures in play.

After a period of testing, our team will present our customer with a list of the most critical alerts, including proof-of-concept of impact, remediation suggestions and a plan moving forward.

Our Customers Say It The Best

At the core of our comprehensive cyber-security approach is the concept of layered protection, ensuring that we are always at the forefront of the latest and greatest innovations in the industry. That’s where River Security comes in, offering their Active Focus service to keep us ahead of the curve with a constantly evolving attack surface, and even helping us to uncover the unknown. With a dynamic blend of cutting-edge technology and skilled expert verification, paired with lightning-fast agility, we are better equipped to tackle any threat that comes our way.

Arvid Eriksen
Arvid EriksenCISO · Sparebanken NorgeFinance
Read more

We have worked with River Security a while, and since August 2021 we have been on their service, Active Focus. We experience that the service is highly relevant, and it gives us a great benefit when it comes to discovering issues at the earliest possible time.

We know that when we receive a report from River Security, there is an actual issue that they can prove. We like how their reports is concise, and that they offer a solution and expert opinion for both short- and long-term fixes.

The team is very knowledgeable and has taught us a lot when it comes to proactive cyber security. They are agile and clearly has a lot of competence within their field, and we are happy to have them on our side in the ever-changing threat landscape.

Terje Einar Hunvik
Terje Einar HunvikIT Operations Manager · MestaIndustrial
Read more

Azets have had the pleasure of working with River Security and their proactive managed service “Active Focus” since late 2020. The service is unique and innovative, and very suitable for our organization which includes several subsidiaries spanning many European countries, most with their own IT portfolio. One of the differentiating features of River Security is that they focus on real threats and areas that need attention – so we not only know about vulnerabilities, dark web disclosures and other issues, but also how they will affect our business. The focus on a pragmatic and customized approach results in River Security getting integrated into our daily security operations, and we are quickly able to resolve matters.

From day one, the service from River Security has significantly improved our IT-security posture, and we have been supplied with precise, critical and relevant input immediately upon discovery.

We can safely recommend River Security and the service “Active Focus” to anyone who wishes to systemize continuous attack surface management.

Ole-Martin Bækkeli
Ole-Martin BækkeliCISO · AzetsFinance
Read more

As the uncertainty surrounding the situation in Europe continues, security in critical infrastructure is of higher importance than ever. Having an external party look at your company from an attackers’ point of view is crucial to identify weaknesses, but also to confirm good measures already in place.

Through a tendering process, we invited River Security to submit their proposal. They immediately understood the assignment, still they challenged us and brought life to new ideas and concepts.

Endgame was that they suggested a multi-phase delivery covering exactly what we (didn’t know we) needed. This made it easy to conclude what vendor to appoint amongst strong competitors.

They started with conducting an external digital footprint to give us an overview of all our digital assets and continued to perform inside penetration testing both remote and on-site.

At the end of the delivery, they held a thorough workshop to go through their findings and suggested measures to mitigate and reduce the risk of being successfully hacked by cyber criminals.

We receive complete reports from every phase, in addition to an executive summary describing what measures we need to focus on first.

Our experience from working with River Security is exclusively positive. Their competence, adaptability and knowledge sharing are without comparison.

We can safely recommend River Security.

Kåre Teigland
Kåre TeiglandHead of IT · Sogn og Fjordane EnergiEnergy
Read more

More about our service in these selected articles