The 2026 landscape

The window you were defending in has closed.

Not opinion. This is what the field data from 2025 says — half a million hours of incident response and twenty-two thousand confirmed breaches. Read the four numbers below together and the conclusion is hard to avoid: patch cadence is no longer a defence, because exploitation now starts before there is anything to patch.

What we do

Eight ways to find the route first.

Every engagement starts with threat modelling and attack path mapping. What changes is the terrain. Open any of them for the scope, the reasoning, and what lands on your desk at the end.

Attack path mapping

Your last report said zero criticals.
That wasn't a clean bill of health.

Severity is scored per finding. Attackers don't attack one finding at a time. Below are three real-shaped issues from a typical report. Flip the view and read them the way someone breaking in would.

Verbose error messages

Low

Stack traces expose internal hostnames. Informational. Fix when convenient.

Staging API reachable from the internet

Medium

Non-production environment exposed. No customer data present. Medium.

CI service account scoped beyond staging

Medium

Over-permissioned identity. Least-privilege deviation. Medium.

0 Critical · 2 Medium · 1 LowVerdict: acceptable risk. Ship it. Revisit next quarter.
This is not hypothetical

The same shape, in the real world.

Salesloft Drift compromise · UNC6395 · August 2025
Low

Access to a source repository

Attackers sat in Salesloft's GitHub for roughly three months, March to June 2025.

Medium

OAuth tokens for a chat integration

A support chatbot's tokens. On any severity matrix, an integration credential is a medium.

High

API access that skips MFA entirely

Those tokens authenticated straight into Salesforce environments. MFA is not in the path of a valid token.

Critical

700+ organisations, and the keys to the next hop

Exports included AWS keys and Snowflake tokens — the raw material for the following chain. Victims included Cloudflare, Google, Palo Alto Networks, Proofpoint, Tanium and Zscaler.

No single step was a critical. The chain was. And it ran through companies that sell security for a living.

Threat-intelligence-led testing

Everyone says “we think like an attacker.”
Ask them which one.

A generic attacker is a useful fiction for scoping and a poor model of reality. The groups going after a Dutch fintech are not the ones going after a defence supplier, and they don't share a playbook. We start from who is realistically coming for you — then test that, specifically.

The kill chain, and where testing stops

Most engagements end at step three. The breach lives in the other six.

Recon
Initial access
Execution
Persistence
Privilege escalation
Lateral movement
Collection
Exfiltration
Impact
Where a conventional test spends its timeWhere the damage actually happens — and where we keep going
Conventional pentest
ThreatScout
Where does the scope come from?

A methodology template. Largely the same scope as the last client.

Intelligence on the groups currently targeting your sector, and the techniques they actually used last quarter.

What gets tested?

Known vulnerability classes. The OWASP Top 10, walked top to bottom.

The specific paths to your crown jewels — including the ones assembled from findings that are individually boring.

How are findings ranked?

CVSS score, descending. A theoretical 9.1 outranks a reachable 5.3.

By what an attacker reaches from it. A medium that unlocks production outranks a critical behind three controls.

When does it stop?

At proof of exploitability. ‘This is vulnerable.’ Report ends.

At proof of consequence. What it unlocked, how far it went, and where it would have been stopped.

What do you get?

A PDF, sorted by severity, that ages badly and gets read once.

Prioritised paths, remediation your engineers can start on this week, and the intel behind each call.

The practical difference: our reports are shorter. Fewer findings, each one attached to a path someone could actually walk, ranked by what it costs you if they do.

Regulatory alignment · EU & US

The regulator stopped asking if you have controls.
Now they ask if you tested them.

Six frameworks, two continents, one demand: prove your defences hold against a real adversary, on a schedule, with evidence. Several now name penetration testing in law — DORA in the EU, PCI DSS and New York's DFS in the US. Pick one to see the exact article each of our services answers.

European Union
United States

DORA is the one that names our discipline in law. For in-scope entities, threat-led penetration testing is not a best practice you might adopt — it is a legal obligation on a three-year cycle, run against live production.

Read the text
Applies to

Banks, insurers, investment firms, crypto-asset service providers, and their critical ICT providers

Art. 26(1)–(2)

In-scope entities must carry out advanced testing by means of threat-led penetration testing (TLPT) at least every 3 years, covering several or all critical or important functions, performed on live production systems.

This is our core practice, not an adjacent one. Intelligence-led scoping, threat modelling, attack path mapping, and exploitation against the functions that actually matter — designed to the TIBER-EU structure the RTS aligns to.

Art. 26(2)

Scope must include ICT systems, processes and technologies supporting critical or important functions — including those outsourced or contracted to third-party providers.

Attack path mapping treats your third parties as what they are: part of your attack surface. Integrations, OAuth trust, and vendor-held credentials get mapped and tested, not scoped out.

Art. 26(6)

On completion, entities must provide the designated authority with a summary of findings, remediation plans, and documentation demonstrating the test met the requirements — to obtain an attestation.

Our reporting is built to survive that submission: findings, business impact, attack-path context, and remediation plans documented to the standard the attestation process expects.

Art. 27

Testers must meet requirements on suitability, reputation, technical capability, and independence.

We are an independent specialist with no product to sell you afterwards — which keeps the independence question simple.

Testing evidences a control; it doesn't discharge an obligation. We map our work to these articles so your auditors and regulators can follow the line from finding to requirement — we don't sell compliance, and anyone who does is selling you a document, not security.

Methodology

How an engagement actually runs.

Four steps, in this order, every time. The first two are why the third one lands — and they're the two most firms skip.

01

Intelligence

Who is realistically coming for an organisation like yours, and what did they use last quarter? Threat-actor groups, live campaigns, CVEs under active exploitation in your sector. This happens before we write a single test case.

02

Model the paths

That intelligence shapes a model of your architecture — trust boundaries, privilege tiers, crown jewels — and the routes between them. Including the ones assembled from findings that look harmless alone.

03

Test them

Hours go into proving or disproving those specific paths, deeply. Not a thin pass over everything, most of which was never reachable in the first place.

04

Hand it over

Ranked by business impact, with remediation specific enough to start on this week, and the reasoning behind every call. Findings can land straight in Jira as we confirm them.

About Threat Scout

Built by people who spent years on the other side of the alert.

ThreatScout is an offensive security firm in Amsterdam. We find and exploit vulnerabilities the way a real attacker would, then help you close them before anyone else gets the chance.

We were founded by penetration testers and threat intelligence analysts who spent years defending before they moved to offence. That order matters: it's why our reports are written for the person who has to fix the thing, and why we care more about whether you'd have caught it than whether we could find it.

We work with startups, enterprises, fintechs, and cloud-native teams — including security vendors whose own customers run red teams against them before they'll sign. If your buyers test you before they trust you, we're built for that conversation.

Contact

Let's find your attack paths first.

Tell us about your product, your infrastructure, or the release that's making you nervous. We'll scope an assessment around the threats that actually target businesses like yours.