Independent security assurance

Confidence for systems that cannot afford uncertainty.

ESSA PRIME helps public institutions and critical organizations verify security, reduce operational risk and make informed technology decisions.

Independent assessment Clear executive reporting Actionable remediation

Assurance overview

Critical service environment

VERIFIED
External exposureCONTROLLED
Operational resilienceVALIDATED
Security governanceALIGNED

07

domains

360°

coverage

A+

clarity

Methods aligned with internationally recognized security frameworks

NIS2ISO 27001NIST CSFOWASPMITRE ATT&CK

Built for public trust

Security decisions with public impact deserve independent clarity.

We support public authorities, government agencies, healthcare organizations and critical service providers where continuity, accountability and data protection are non-negotiable.

The same level of rigor is available to private enterprises, technology providers and regulated organizations protecting sensitive data, complex supply chains and business-critical platforms.

01

Government & public administration

02

Critical infrastructure & healthcare

03

Private & regulated enterprises

04

Technology & digital service providers

Capabilities

Security expertise across technology, risk and governance.

From hands-on technical validation to board-level advisory, every engagement is designed to turn findings into measurable resilience.

01 / OFFENSIVE

Penetration Testing

Evidence-led testing of applications, APIs, networks and external attack surfaces.

SSRF · IDOR/BOLA · REQUEST SMUGGLING · DESERIALIZATION · RACE CONDITIONS

02 / ASSURANCE

Security Audits

Independent review of controls, architecture and operating practices against risk and recognized standards.

NIS2 · ISO 27001 · NIST CSF 2.0 · CIS CONTROLS · IEC 62443

03 / ADVERSARY

Red Teaming

Controlled adversary simulations that test people, processes and technology as one defensive system.

AD CS · KERBEROS · C2 TRADECRAFT · EDR EVASION · ATT&CK MAPPING

04 / CLOUD

Cloud & Infrastructure Security

Architecture reviews, configuration assessment and security validation across hybrid environments.

IAM GRAPH · WORKLOAD IDENTITY · K8S RBAC · OIDC TRUST · CONTROL PLANE

05 / GOVERNANCE

Risk & Security Strategy

Pragmatic roadmaps, NIS2 readiness and governance models aligned with organizational priorities.

06 / RESILIENCE

Incident Readiness

Response planning, scenario exercises and post-incident support focused on operational continuity.

07 / ADVISORY

IT & Cybersecurity Consulting

Independent expertise for technology programs, procurements, architecture decisions and complex transformation initiatives—connecting security requirements with delivery reality.

Start a conversation

Technical coverage

We test the control plane, not just the perimeter.

Our assessments follow trust relationships across identity, application, cloud and infrastructure layers. Findings include reproducible attack paths, preconditions, affected principals and validation guidance—not scanner output.

IDENTITY / 01

Identity control planes

Active Directory and Entra ID attack-path analysis: AD CS ESC primitives, delegation abuse, hybrid identity boundaries, OAuth consent, token replay and Conditional Access bypass conditions.

AD DS · ENTRA ID · ADFS · AD CS · KERBEROS · SAML · OIDC/OAUTH 2.0

APPLICATION / 02

Application & API internals

Manual analysis beyond standard OWASP coverage, including business-logic abuse, multi-tenant isolation, parser differentials, cache poisoning and authorization drift across service boundaries.

REST · GRAPHQL · gRPC · WEBSOCKETS · JWT · mTLS · OPENAPI

CLOUD / 03

Cloud privilege paths

Effective-permission analysis across IAM graphs, cross-account trusts, workload identities, metadata services, key management and managed CI/CD execution contexts.

AZURE · AWS · GCP · IAM · KMS · IMDSv2 · TERRAFORM

PLATFORM / 04

Containers & orchestration

Kubernetes control-plane review from admission and RBAC semantics to service-account token exposure, network-policy gaps, runtime escape paths and supply-chain trust.

KUBERNETES · OPENSHIFT · HELM · OPA/GATEKEEPER · COSIGN · SBOM

INFRASTRUCTURE / 05

Network & edge

Segmentation and trust-boundary testing across enterprise networks, remote access, DNS, egress paths and management planes—with protocol-level validation where required.

IPSEC · BGP · DNSSEC · 802.1X · RADIUS · SNMPv3 · ZTNA

OT / 06

OT & cyber-physical environments

Safety-aware architecture and exposure reviews for industrial environments, focused on zone/conduit design, engineering access, remote maintenance and IT/OT boundary risk.

IEC 62443 · OPC UA · MODBUS/TCP · DNP3 · PROFINET · PURDUE MODEL

Deliverable depth

Each material finding is documented with attack graph context, exploitability constraints, evidence, blast radius and a retestable remediation condition.

CWE / CVSS v4.0 / ATT&CK / DREAD-FREE

Our method

Rigorous where it matters. Clear at every step.

A structured engagement model keeps stakeholders informed while giving technical teams the evidence they need to act.

01

Align

Define scope, critical assets, risk context and clear success criteria.

02

Verify

Assess controls and test real-world attack paths with disciplined execution.

03

Prioritize

Translate evidence into risk-based actions for technical and executive audiences.

04

Strengthen

Support remediation and validate that material risks have been resolved.

The ESSA PRIME standard

Independent thinking. Defensible outcomes.

We combine deep technical expertise with the discipline required in regulated and public-sector environments. Our work is direct, discreet and designed to stand up to scrutiny.

Evidence before assumptions

Clarity without compromise

Operating reach European delivery network
LONDON BRUSSELS TILBURG / NL FRANKFURT WARSAW COPENHAGEN
51.5606° N5.0919° EEU / INTL
Netherlands-firstCross-border delivery

Based in the Netherlands. Ready for international assignments.

Our primary focus is the Dutch market, with international delivery available for larger and cross-border programs.

Contact

Start with a confidential conversation.

Tell us what you need to verify, protect or improve. We will respond with a focused next step.

Registered office

ESSA PRIME
Oude Rielseweg 11-8587
5032SH Tilburg
The Netherlands

General enquiries

Project enquiries

Security disclosures

VAT · NL004844433B27 KvK · 90821459