The window you were defending in has closed.
Not opinion. This is what the field data from 2025 says — half a million hours of incident response and twenty-two thousand confirmed breaches. Read the four numbers below together and the conclusion is hard to avoid: patch cadence is no longer a defence, because exploitation now starts before there is anything to patch.
Negative. Exploitation now routinely begins before the patch exists. In 2018 you had 63 days.
From intrusion to handing your network to whoever monetises it. In 2022 that window was over eight hours.
Vulnerability exploitation has overtaken stolen credentials as the leading way in.
Up from 32. Defenders slowed down by a third while attackers moved to exploiting pre-patch.
Up 60% year over year. Your attack surface includes software you didn't write.
Double last year's 15%. The breach that ends you often began as someone else's overlooked foothold.
$10.22M in the United States — a record high, up 9% year over year.
The lowest in nine years, and still eight months of someone else inside your environment.
Eight ways to find the route first.
Every engagement starts with threat modelling and attack path mapping. What changes is the terrain. Open any of them for the scope, the reasoning, and what lands on your desk at the end.
Your last report said zero criticals.
That wasn't a clean bill of health.
Severity is scored per finding. Attackers don't attack one finding at a time. Below are three real-shaped issues from a typical report. Flip the view and read them the way someone breaking in would.
Verbose error messages
Stack traces expose internal hostnames. Informational. Fix when convenient.
Staging API reachable from the internet
Non-production environment exposed. No customer data present. Medium.
CI service account scoped beyond staging
Over-permissioned identity. Least-privilege deviation. Medium.
The same shape, in the real world.
Access to a source repository
Attackers sat in Salesloft's GitHub for roughly three months, March to June 2025.
OAuth tokens for a chat integration
A support chatbot's tokens. On any severity matrix, an integration credential is a medium.
API access that skips MFA entirely
Those tokens authenticated straight into Salesforce environments. MFA is not in the path of a valid token.
700+ organisations, and the keys to the next hop
Exports included AWS keys and Snowflake tokens — the raw material for the following chain. Victims included Cloudflare, Google, Palo Alto Networks, Proofpoint, Tanium and Zscaler.
No single step was a critical. The chain was. And it ran through companies that sell security for a living.
Everyone says “we think like an attacker.”
Ask them which one.
A generic attacker is a useful fiction for scoping and a poor model of reality. The groups going after a Dutch fintech are not the ones going after a defence supplier, and they don't share a playbook. We start from who is realistically coming for you — then test that, specifically.
The kill chain, and where testing stops
Most engagements end at step three. The breach lives in the other six.
A methodology template. Largely the same scope as the last client.
Intelligence on the groups currently targeting your sector, and the techniques they actually used last quarter.
Known vulnerability classes. The OWASP Top 10, walked top to bottom.
The specific paths to your crown jewels — including the ones assembled from findings that are individually boring.
CVSS score, descending. A theoretical 9.1 outranks a reachable 5.3.
By what an attacker reaches from it. A medium that unlocks production outranks a critical behind three controls.
At proof of exploitability. ‘This is vulnerable.’ Report ends.
At proof of consequence. What it unlocked, how far it went, and where it would have been stopped.
A PDF, sorted by severity, that ages badly and gets read once.
Prioritised paths, remediation your engineers can start on this week, and the intel behind each call.
The practical difference: our reports are shorter. Fewer findings, each one attached to a path someone could actually walk, ranked by what it costs you if they do.
The regulator stopped asking if you have controls.
Now they ask if you tested them.
Six frameworks, two continents, one demand: prove your defences hold against a real adversary, on a schedule, with evidence. Several now name penetration testing in law — DORA in the EU, PCI DSS and New York's DFS in the US. Pick one to see the exact article each of our services answers.
DORA is the one that names our discipline in law. For in-scope entities, threat-led penetration testing is not a best practice you might adopt — it is a legal obligation on a three-year cycle, run against live production.
Read the textBanks, insurers, investment firms, crypto-asset service providers, and their critical ICT providers
In-scope entities must carry out advanced testing by means of threat-led penetration testing (TLPT) at least every 3 years, covering several or all critical or important functions, performed on live production systems.
This is our core practice, not an adjacent one. Intelligence-led scoping, threat modelling, attack path mapping, and exploitation against the functions that actually matter — designed to the TIBER-EU structure the RTS aligns to.
Scope must include ICT systems, processes and technologies supporting critical or important functions — including those outsourced or contracted to third-party providers.
Attack path mapping treats your third parties as what they are: part of your attack surface. Integrations, OAuth trust, and vendor-held credentials get mapped and tested, not scoped out.
On completion, entities must provide the designated authority with a summary of findings, remediation plans, and documentation demonstrating the test met the requirements — to obtain an attestation.
Our reporting is built to survive that submission: findings, business impact, attack-path context, and remediation plans documented to the standard the attestation process expects.
Testers must meet requirements on suitability, reputation, technical capability, and independence.
We are an independent specialist with no product to sell you afterwards — which keeps the independence question simple.
Testing evidences a control; it doesn't discharge an obligation. We map our work to these articles so your auditors and regulators can follow the line from finding to requirement — we don't sell compliance, and anyone who does is selling you a document, not security.
How an engagement actually runs.
Four steps, in this order, every time. The first two are why the third one lands — and they're the two most firms skip.
Intelligence
Who is realistically coming for an organisation like yours, and what did they use last quarter? Threat-actor groups, live campaigns, CVEs under active exploitation in your sector. This happens before we write a single test case.
Model the paths
That intelligence shapes a model of your architecture — trust boundaries, privilege tiers, crown jewels — and the routes between them. Including the ones assembled from findings that look harmless alone.
Test them
Hours go into proving or disproving those specific paths, deeply. Not a thin pass over everything, most of which was never reachable in the first place.
Hand it over
Ranked by business impact, with remediation specific enough to start on this week, and the reasoning behind every call. Findings can land straight in Jira as we confirm them.
Built by people who spent years on the other side of the alert.
ThreatScout is an offensive security firm in Amsterdam. We find and exploit vulnerabilities the way a real attacker would, then help you close them before anyone else gets the chance.
We were founded by penetration testers and threat intelligence analysts who spent years defending before they moved to offence. That order matters: it's why our reports are written for the person who has to fix the thing, and why we care more about whether you'd have caught it than whether we could find it.
We work with startups, enterprises, fintechs, and cloud-native teams — including security vendors whose own customers run red teams against them before they'll sign. If your buyers test you before they trust you, we're built for that conversation.
Let's find your attack paths first.
Tell us about your product, your infrastructure, or the release that's making you nervous. We'll scope an assessment around the threats that actually target businesses like yours.