We do exactly one thing: penetration tests. Individually planned, specialised in physical security, social engineering and OT – with a client portal for every customer and an online-verifiable certificate after every test.
admin@access-granted:~$ run-assessment
-> Reconnaissance [DONE]
-> Infrastructure [DONE]
-> Active Directory [DONE]
-> Web App Pentest [DONE]
-> Social Engineering [MAIL_TO_HELLO@ACCESS-GRANTED.DE]
-> Physical Pentest [ACTIVE]
[SUCCESS] ACCESS GRANTED
There are many pentest providers. The differences rarely lie in the scanner, but in attitude, specialisation and what you hold in your hands after the test.
We run no system-integrator business, sell no hardware, no licences and no managed services. Whoever finds vulnerabilities and sells the fix in the same breath has a conflict of interest. Our only product is the honest finding.
There is no catalogue of pentest S, M and L here. Every scope, approach and offer is derived from your infrastructure, your threat profile and your budget. If a test makes no sense for you, we say so – even if we could sell it.
We test networks and web apps like any good provider. But our focus is where few look: at the factory gate, the reception desk, your employees' inboxes and the control systems of your production. That is often where it is decided whether an attacker has to overcome technical hurdles at all.
Many providers test remotely only. We come to you when it helps the result: for the physical pentest anyway, but also for an internal infrastructure or Active Directory test. Short paths to your IT, questions answered in conversation rather than by ticket.
From the first offer to the certificate, everything runs through app.access-granted.de: sign offers digitally, findings with recommendations and comments, encrypted exchange of credentials, operational log, report as PDF. No email ping-pong, no Excel list.
Cyber insurers, corporate customers and auditors increasingly ask for proof. After every test we issue a certificate with a unique reference code whose authenticity any third party can verify online in seconds.
Florian Schüssler reconstructed real cyberattacks with the criminal police before simulating them himself as a penetration tester and red teamer. Today he teaches IT security at DHBW. At Access Granted he still tests himself – you talk to the person who runs the test.
Most successful attacks do not start with an exploit, but with an open door, a convincing phone call or a controller that was never meant for the internet.
Of course we also test infrastructure, Active Directory, web apps, cloud and AI – individually or combined into a red-teaming scenario.
Every customer gets access to app.access-granted.de. Everything that would otherwise be scattered across emails, attachments and phone calls comes together there.
Add or remove optional items and sign directly in the portal, even from your phone.
Every finding with description, impact, recommendation and affected targets – with comments so questions reach the tester directly.
Share passwords and secrets via the portal vault instead of email. Upload files directly to the project.
What was tested when? The log of our activities is viewable and exportable – useful for your SOC and for auditors.
You sign the authorisation letter for the physical pentest in the portal; our testers carry it during the engagement.
Both documents are in the portal after completion – available any time, even years later.
2FA via authenticator app, notifications for new offers, new files or test completion – your choice.
Behind every comment is the person running the test – no ticket system, no call centre.
After every pentest we issue a certificate stating client, test period, scope and a unique reference code. Anyone who enters the code at access-granted.de/verify immediately sees whether the document is genuine – without asking us or you.
The certificate documents the scope and period of the test. It is not a security seal and makes no statement about the current security posture.
Six principles, one guiding idea.
We act as a partner, not a salesperson – even though we think like an attacker while doing it. That means we only offer you what actually makes sense for your company – no off-the-shelf standard package, but an assessment tailored exactly to your infrastructure, your budget, and your real threat profile.
We don't just look at the code. Physical security, human factors, and technical hardening only create a true security picture when combined.
We don't simulate theory; we simulate real attackers. Our focus is on the paths a hacker would actually choose today.
Honest communication about findings and costs. You have full insight into our methodology and current project progress at all times.
A report is just the beginning. We provide solutions that increase your resilience long-term, rather than just patching holes short-term.
Highest certification standards and continuous research guarantee expertise at the cutting edge of offensive security.
This mindset doesn't come from a textbook, but from the other side of the security line – as an investigator, red teamer, and lecturer.
Florian Schüssler began his path on the defensive side of IT security, with the Criminal Police. There, he investigated cases of digital crime and reconstructed attack sequences to understand the methods and motives of real attackers. The focus was not only on technical traces but on the psychological factors behind attacks: why specific targets are chosen, where human errors occur, and how attackers exploit time pressure, trust, or lack of knowledge. That experience with real attack mechanisms still shapes the work at Access Granted today.
After his time in government service, Florian moved into offensive IT security. As a penetration tester, red teamer, and security consultant, he simulated real attacks on companies of every size, from small and medium-sized businesses to corporations and critical infrastructure (KRITIS) organizations. The focus was never on isolated vulnerabilities, but on coherent attack chains from initial access through privilege escalation to critical business processes. During this time, he optimized internal security processes, developed tools and methodologies further, and gained experience in highly sensitive environments where security is not optional. That technically deep, strategic perspective still determines how Access Granted works today.
„I don't sell anyone a test they don't need. Security has to fit the company – not the other way around.“ Florian Schüssler
Parallel to his practical work, Florian shares his knowledge as a lecturer at the Baden-Württemberg Cooperative State University (DHBW), where he teaches future IT specialists in various areas of IT security, with a focus on real attack methods, threat models, and practical security concepts.
In 2026, Florian Schüssler founded Access Granted with a clear vision: penetration tests should be honest, efficient, and realistic, not built on standardized checklists but on tailored security assessments that highlight real risks and enable sustainable improvements. Access Granted offers individually coordinated security audits that show how attacks actually happen, with the goal of giving companies a clear picture of their true security situation: transparent, comprehensible, and with real value added.
CEO & Founder
Former Criminal Police Investigator Lecturer at DHBW Stuttgart14 credentials, from OSCP (2020) to Certified Agentic AI Pentester (2026)
“Security begins in the mind – not in the code.”
Profile & journey ↗With us, you speak directly to the experts who actually perform the tests. No call centers, no traditional sales – just real expertise from the very beginning.