Real-World Offensive Security · Specialists in Attacks No SIEM Will Ever Catch
Think like an Attacker, Act as a Partner
Your organisation has vulnerabilities you don't know about. Attackers will find them anyway — through technology, deception, and the unlocked door to your server room. We find them first: with tailored penetration tests, clear recommendations, and a focus on physical pentesting, social engineering & OT/ICS.
NIS2 support
Clear final report
Free initial consultation
NIS2 support
·
BSI baseline-oriented
·
Available internationally
·
Remote & on-site
Economic damage
289 bn €
Cybercrime costs Germany more each year than the entire automotive industry generates in revenue.
Bitkom Wirtschaftsschutz 2025
Affected companies
87 %
of German companies were victims of data theft, sabotage, or industrial espionage in the past twelve months.
Bitkom Wirtschaftsschutz 2025
The human factor
68 %
of confirmed data breaches involve the human element, according to Verizon — whether through error or social engineering. Technology alone is not enough: people remain the decisive attack surface.
Verizon DBIR 2024
Ransom payments
0,8 bn €
was paid to ransomware groups worldwide in 2024 according to the latest estimates — a decline from 2023's record year. At the same time, the number of attacks hit a new all-time high: prevention remains cheaper than ransom.
Chainalysis Crypto Crime Report 2025
The Dilemma of Choice
Penetration Test Modules: Our Services
From physical security to Active Directory – every module can be booked individually or combined into a comprehensive security assessment.
(Translated from German) Our collaboration with Florian Schüssler has been exceptionally professional and trustworthy from the very beginning. He has repeatedly carried out extensive penetration tests for Kreiskliniken Reutlingen, identifying not only technical vulnerabilities but also communicating them clearly, comprehensibly, and in a practice-oriented way. I'd particularly like to highlight his ability to see security as more than just an audit assignment. Florian was available to us as a competent point of contact at all times, answered questions quickly and thoroughly, and supported us in prioritizing and implementing appropriate measures. His recommendations are consistently pragmatic, solution-oriented, and tailored to our organization's specific needs. Especially in a hospital environment, where information security and availability are equally critical, this combination of technical excellence, reliability, and collaborative advisory support is invaluable. We can recommend Florian Schüssler and AccessGranted without reservation and look forward to continuing our collaboration.
More references and project examples available on request.
Frequently Asked Questions about Penetration Testing
Costs depend on the scope, complexity of your systems, and chosen test depth. After a free initial consultation you receive a transparent fixed-price offer – no hidden costs. For guidance: a web app pentest typically starts from €2,500, a full physical assessment from €3,500. For combined scope packages (e.g. infrastructure + AD + social engineering) we create individual offers – often cheaper than booking separately.
Depending on the module and scope, the actual testing takes between one and five working days. We communicate critical findings during the test – you are never in the dark. You receive the full final report within five working days of test completion. The entire process from initial consultation to final presentation typically takes two to four weeks. Accelerated timelines are available on request.
Yes. The NIS2 directive requires affected organisations to regularly review their security measures – penetration tests are a central and authority-recognised instrument for this. Our structured, risk-prioritised reports provide the evidence you need for internal and external audits, and help map findings to the NIS2 requirements catalogue.
Absolutely. Before testing begins, we jointly define clear scope boundaries, exclusion zones, and no-go systems. Every activity is fully logged. If unexpected impacts occur, we stop immediately and notify your contact in real time. In well over 99% of all tests there were no operational disruptions whatsoever.
A vulnerability scan is an automated tool that identifies known weaknesses from signatures. A penetration test goes much further: our experts think and act like real attackers, chain multiple vulnerabilities together, and test business logic as well as physical access. The result is not a generated CVE report, but a realistic picture of your actual security posture.
Yes. We conduct pentests remotely and on-site across Europe. Remote tests (web app, infrastructure, AD) are location-independent. For physical assessments and social engineering we travel to your site – including outside Germany. Simply let us know your location and we will find a solution.