Technical Assurance & Offensive Security
Identity, Access & Zero Trust Review
Most breaches are an identity problem wearing a technical costume.
The situation
What the client receives
Schedule of deliverables
- Identity estate and privilege model assessment
- MFA and SSO coverage analysis including bypass and fallback paths
- Privileged access management design
- Joiner-mover-leaver process and access recertification design
- Zero trust architecture roadmap proportionate to the estate
- Entra ID / Okta / directory hardening review
Frameworks and standards
Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.
- NIST SP 800-207
- ISO/IEC 27001 A.5.15–A.5.18
- NIS2 Art. 21(2)(i) / (j)
Related services
Discuss this engagement
Tell us about your directory, privilege model and access review practice and we will set out the scope, the method and the reporting format.