THINK LIKE AN ATTACKER, ACT AS A PARTNER

Security that goes further.

We do exactly one thing: penetration tests. Individually planned, specialised in physical security, social engineering and OT – with a client portal for every customer and an online-verifiable certificate after every test.

~/access-granted/run-assessment.sh

admin@access-granted:~$ run-assessment

-> Reconnaissance [DONE]

-> Infrastructure [DONE]

-> Active Directory [DONE]

-> Web App Pentest [DONE]

-> Social Engineering [MAIL_TO_HELLO@ACCESS-GRANTED.DE]

-> Physical Pentest [ACTIVE]


[SUCCESS] ACCESS GRANTED

100 %
Pentesting – no system-integrator business, no product sales
14
Certifications (OSCP to Agentic AI Pentester)
3
Focus areas: Physical · Social Engineering · OT
Direct
You talk to the testers themselves, no call center
What sets us apart

Seven reasons companies test with us

There are many pentest providers. The differences rarely lie in the scanner, but in attitude, specialisation and what you hold in your hands after the test.

  1. 01

    Pentesting only. Nothing else.

    We run no system-integrator business, sell no hardware, no licences and no managed services. Whoever finds vulnerabilities and sells the fix in the same breath has a conflict of interest. Our only product is the honest finding.

    No product partnerships, no commissions, no follow-up projects in the background
  2. 02

    Individual instead of one-size-fits-all

    There is no catalogue of pentest S, M and L here. Every scope, approach and offer is derived from your infrastructure, your threat profile and your budget. If a test makes no sense for you, we say so – even if we could sell it.

    Scoping call before every offer, offers with selectable optional items
  3. 03

    Specialised in physical, social engineering and OT

    We test networks and web apps like any good provider. But our focus is where few look: at the factory gate, the reception desk, your employees' inboxes and the control systems of your production. That is often where it is decided whether an attacker has to overcome technical hurdles at all.

    Physical pentest, social engineering, phishing simulation and OT/ICS as dedicated disciplines
  4. 04

    On-site when it is better

    Many providers test remotely only. We come to you when it helps the result: for the physical pentest anyway, but also for an internal infrastructure or Active Directory test. Short paths to your IT, questions answered in conversation rather than by ticket.

    Germany, Austria, Switzerland and across Europe – remote or on your premises
  5. 05

    A client portal for every customer

    From the first offer to the certificate, everything runs through app.access-granted.de: sign offers digitally, findings with recommendations and comments, encrypted exchange of credentials, operational log, report as PDF. No email ping-pong, no Excel list.

    Two-factor login, notifications of your choice, all documents available any time
  6. 06

    Certificate after every pentest – verifiable online

    Cyber insurers, corporate customers and auditors increasingly ask for proof. After every test we issue a certificate with a unique reference code whose authenticity any third party can verify online in seconds.

    Verification at access-granted.de/verify, without asking us or you
  7. 07

    A founder who knows both sides

    Florian Schüssler reconstructed real cyberattacks with the criminal police before simulating them himself as a penetration tester and red teamer. Today he teaches IT security at DHBW. At Access Granted he still tests himself – you talk to the person who runs the test.

    Former criminal police investigator · Red teamer · Lecturer at DHBW
Our focus areas

Testing where few look

Most successful attacks do not start with an exploit, but with an open door, a convincing phone call or a controller that was never meant for the internet.

Of course we also test infrastructure, Active Directory, web apps, cloud and AI – individually or combined into a red-teaming scenario.

Transparency as a system

One portal that accompanies the whole test

Every customer gets access to app.access-granted.de. Everything that would otherwise be scattered across emails, attachments and phone calls comes together there.

Sign offers digitally

Add or remove optional items and sign directly in the portal, even from your phone.

Findings live, not just in the report

Every finding with description, impact, recommendation and affected targets – with comments so questions reach the tester directly.

Exchange credentials encrypted

Share passwords and secrets via the portal vault instead of email. Upload files directly to the project.

Operational log

What was tested when? The log of our activities is viewable and exportable – useful for your SOC and for auditors.

Digital test authorisation

You sign the authorisation letter for the physical pentest in the portal; our testers carry it during the engagement.

Report and certificate as PDF

Both documents are in the portal after completion – available any time, even years later.

Two-factor login and notifications

2FA via authenticator app, notifications for new offers, new files or test completion – your choice.

Direct line to the tester

Behind every comment is the person running the test – no ticket system, no call centre.

A certificate anyone can verify

After every pentest we issue a certificate stating client, test period, scope and a unique reference code. Anyone who enters the code at access-granted.de/verify immediately sees whether the document is genuine – without asking us or you.

Who asks for it
  • Cyber insurers when taking out or renewing a policy
  • Customers and corporations auditing their supply chain (TISAX, NIS2, DORA)
  • Auditors and certification bodies (ISO 27001, KRITIS evidence)
  • Management and supervisory bodies as proof of due diligence

The certificate documents the scope and period of the test. It is not a security seal and makes no statement about the current security posture.

Our Values

Six principles, one guiding idea.

Our Guiding Principle

Individual

We act as a partner, not a salesperson – even though we think like an attacker while doing it. That means we only offer you what actually makes sense for your company – no off-the-shelf standard package, but an assessment tailored exactly to your infrastructure, your budget, and your real threat profile.

Holistic

We don't just look at the code. Physical security, human factors, and technical hardening only create a true security picture when combined.

Realistic

We don't simulate theory; we simulate real attackers. Our focus is on the paths a hacker would actually choose today.

Transparent

Honest communication about findings and costs. You have full insight into our methodology and current project progress at all times.

Sustainable

A report is just the beginning. We provide solutions that increase your resilience long-term, rather than just patching holes short-term.

Excellent

Highest certification standards and continuous research guarantee expertise at the cutting edge of offensive security.

From Investigator to Partner

This mindset doesn't come from a textbook, but from the other side of the security line – as an investigator, red teamer, and lecturer.

Origin & Perspective

Cybercrime Investigation at the Criminal Police

Florian Schüssler began his path on the defensive side of IT security, with the Criminal Police. There, he investigated cases of digital crime and reconstructed attack sequences to understand the methods and motives of real attackers. The focus was not only on technical traces but on the psychological factors behind attacks: why specific targets are chosen, where human errors occur, and how attackers exploit time pressure, trust, or lack of knowledge. That experience with real attack mechanisms still shapes the work at Access Granted today.

The Shift in Perspective

Offensive Security, Red Teaming & Real Attack Chains

After his time in government service, Florian moved into offensive IT security. As a penetration tester, red teamer, and security consultant, he simulated real attacks on companies of every size, from small and medium-sized businesses to corporations and critical infrastructure (KRITIS) organizations. The focus was never on isolated vulnerabilities, but on coherent attack chains from initial access through privilege escalation to critical business processes. During this time, he optimized internal security processes, developed tools and methodologies further, and gained experience in highly sensitive environments where security is not optional. That technically deep, strategic perspective still determines how Access Granted works today.

„I don't sell anyone a test they don't need. Security has to fit the company – not the other way around.“ Florian Schüssler
Sharing Knowledge

Research & Teaching at DHBW

Parallel to his practical work, Florian shares his knowledge as a lecturer at the Baden-Württemberg Cooperative State University (DHBW), where he teaches future IT specialists in various areas of IT security, with a focus on real attack methods, threat models, and practical security concepts.

2026

Founding of Access Granted

In 2026, Florian Schüssler founded Access Granted with a clear vision: penetration tests should be honest, efficient, and realistic, not built on standardized checklists but on tailored security assessments that highlight real risks and enable sustainable improvements. Access Granted offers individually coordinated security audits that show how attacks actually happen, with the goal of giving companies a clear picture of their true security situation: transparent, comprehensible, and with real value added.

Florian Schüssler

Florian Schüssler

CEO & Founder

Former Criminal Police Investigator Lecturer at DHBW Stuttgart

B. Sc. Applied Computer Science
Master Professional of Technical Management (CCI)

C-AgAIPenCRTeamerX CRTOCESE CRTPOSCP +8 more ↗

14 credentials, from OSCP (2020) to Certified Agentic AI Pentester (2026)


“Security begins in the mind – not in the code.”

Profile & journey ↗

Ready for honest security?

With us, you speak directly to the experts who actually perform the tests. No call centers, no traditional sales – just real expertise from the very beginning.