Why we exist
Much of the security industry is built for volume. Engagements are scoped to a fixed block of hours, worked through a checklist, and treated as finished the moment the report is delivered. It is a profitable way to operate, and it rarely leaves a client knowing much more than they did at the start.
NedSec was built on the opposite priorities. Every engagement is led by a senior tester who specialises in that kind of work, and we would rather take on fewer clients and stay with them, across retests, architecture changes, and next year’s assessment, than push out as many reports as we can. Real security work depends on expertise that cannot be rushed, and on knowing a client well enough to see how their risk changes over time.
How we work
- Senior testers, start to finish. The people who scope the engagement run it. No hand-off to a junior team once the statement of work is signed.
- Tools and testers together. Automated tooling and AI give us reach across the whole target, which leaves our testers free to chase the leads that turn smaller issues into real impact.
- Reproducible findings. Every finding has clear steps, evidence, a severity rating, and a concrete remediation, written for the team that owns the fix.
- Retest included. We re-test what we reported once you have remediated and reissue a clean report for your customers and auditors.
The team
We are a group of testers with backgrounds in application security, network and Active Directory attacks, mobile, and blue-team operations. Between us we have sat on both sides - building and defending systems in-house, and being brought in to break them.
We keep the team small on purpose. It is the only way we have found to hold every engagement to the same standard, whoever runs it.
Where we are
Based in Europe, working across European and North American time zones.