Proof of who really has access.Your last audit proved the controls exist.
It never proved who used them.
Independent audits of identity, access and your suppliers, with evidence that holds up with auditors and boards.
Almost two decades inside the machine: SOC floors, audit rooms, ransomware recoveries, smart contracts, AI red teams. Block The Chain thinks in attack paths and failure states, then hands you the evidence a regulator accepts and an adversary cannot argue with. One operator. Zero theoretical findings.
Three layers. One operator.
Most audits stop at the surface: policies, scans, checkbox evidence. The failures that matter live deeper, in identities nobody owns and vendors nobody mapped.
SURFACE LAYER
Where auditors look and attackers start. Block The Chain tests whether the controls you documented actually operate, and writes the evidence file the regulator expects to see.
Security Auditing & Compliance
RDI · ISO 27001 · NIST CSFEnd-to-end IT security audits for regulated sectors against RDI, ISO 27001, NIST CSF 2.0 and CIS Controls. Evidence, not opinions.
Vulnerability Management
Tenable · Qualys · OpenVASFrom scanner noise to a ranked remediation program with owners, deadlines and a trend line your board can read.
DEEP LAYER
The part scanners never see: who holds which access, which tokens never expire, which vendor still has a working key, and whether anyone would notice.
SIEM, Detection & Threat Hunting
Sentinel · Splunk · Sumo LogicDetections mapped to the tradecraft that matters for your sector. Logs do not lie, but only if someone is reading them.
Identity, Cloud & Access Audit
Entra · Intune · Zero TrustEvery service account, shared secret and vendor path listed with an owner. Before-and-after numbers, not a policy PDF.
Incident Response & Recovery Validation
Forensics · backup restoreTriage to root cause, then proof that your recovery actually works, tested rather than assumed.
Evidence for Disputes and Whistleblowers
Chain of custody · timelines · expert statementWhen the other side is bigger and owns the systems, the records still tell the truth. The operator acquires them with chain of custody, rebuilds the timeline, names every missing log as a finding, and hands your lawyer a file built to be filed. Size is not an argument. Evidence is.
DARK LAYER
Your systems tested the way the adversary would work them. Scoped, authorised, evidence-grade.
Offensive Assessment & Chain-of-Custody Review
Web · API · Cloud · Supply chainAttack paths, not tool output: access-control weaknesses, identity abuse, misconfigurations from commit to production and from vendor to crown jewels. Every finding reproduced, and the session evidence kept as a legal-grade artefact.
AI Red Team & Agentic Attack Chains
LLM · agents · AI platformsRed-teaming LLM workflows and autonomous agents, then building the guardrails: rate limits, audit logging, input validation, human-in-the-loop. Tested on production AI platforms built from the ground up.
Blockchain & DeFi Security
Slither · Mythril · fuzzingSmart-contract review from static analysis to symbolic execution, plus DeFi threat models for oracles, staking and governance logic. Risks documented before deployment, not after the drain.
Three things. Checked with evidence.
Your controls
Do the controls your last audit listed actually work? Checked, with evidence.
Your people and access
Who can get in, who did, and whether your logs would show it.
Your exposure
What an attacker would try on your apps, cloud or AI tools, with your written permission.
Names withheld. Discretion is part of the work.
Nine operations, codenames only. Each tile opens the problem and the result. Sectors named, clients never.
Five steps. No surprises.
Fixed scope, fixed price, one operator from the first call to the retest. You review the plan before you commit to anything.
Scoping call
Your context, the systems in play, what keeps you up at night. No slide deck, no sales script.
Fixed-price proposal
Scope, method, deliverables, price and date on one page. You decide with the plan in hand.
Evidence gathering
Walkthroughs, configuration reviews, log sampling, testing. Every claim backed by an artefact you can reproduce.
Findings that carry weight
Ranked findings with owners and one action each, written for the engineer and the board in the same document.
Retest and attestation
Fixes verified, the file closed with a signed statement of what was tested and what held.
Three steps. A fixed price.
A 30-minute call
You say what worries you. Nothing to prepare.
A fixed price
In writing within two business days. No hourly surprises.
The work and a retest
A report ranked by real risk, with the evidence behind it, and a retest once it is fixed.
Four rules. No exceptions.
01No scanner ever stopped a breach.
Tools produce alerts. The operator produces decisions: a finding, its evidence, its owner and the one action attached to it.
02Logs don't lie. Missing logs confess.
Timelines are rebuilt from the records that exist. The report states plainly which records do not, and what that means. In a dispute, that sentence is the case.
03The chain ends at the operator.
The person on the call does the work, signs the report and answers for it. No juniors, no subcontractors, no slide decks.
04Zero theoretical findings.
Every item is reproduced before it is written down. What the system permits is documented; what was not proven is not claimed.
One operator. Nothing outsourced.
Who does the work, on what terms, and why the findings hold up. No name on the site by design; everything else is on the table.
No reseller deals, no commissions
No vendor partnerships, no product commissions, no resale margin. Tools are chosen per engagement and named where they matter. The only revenue is the work itself.
The person on the call does the work
Scoping, testing, evidence, report and read-out by the same person, who signs it and answers for it. No subcontracting, no juniors, limited slots stated up front.
Regulated and supervised environments
Telecom, government, finance, healthcare and manufacturing. Legacy and cloud side by side, identity estates nobody owns, AI agents and smart contracts before launch.
Evidence mapped to the standard you answer to
ISO 27001, NIST CSF 2.0, CIS v8, MITRE ATT&CK, RDI and BIO as agreed; OWASP LLM Top 10 for AI work. Findings arrive mapped, so nobody has to translate them afterwards.
Procurement gets a complete pack
Identity documents, data-processing agreement and chain-of-custody statement are part of the standard supplier pack. NDA before any system is named.
Dutch and English, based in the Netherlands
Reports, read-outs and evidence in either language. KvK 84616458. Working across the EU; evidence stays on EU-hosted, encrypted storage and is deleted after hand-over.
One operator. Nothing outsourced.
No products to sell
No partner deals, no commissions. Findings are the only thing delivered.
Start to finish
The person on the call does the work. Nothing is subcontracted.
Your NDA or ours
Names are never published. Evidence stays in the EU.
Hardcore music and hard security as one signal. The first transmission is in production; the channels open with it.
One email starts it.Tell me what to verify. You get a fixed price.
Say what you need checked. A reply within one business day.
Thirty minutes to scope it. A fixed-price proposal within two business days.
One e-mail starts it. Reply within one business day.
- Your organisation and your role
- What you want verified, in a few lines
- The framework you answer to, if any
- Two or three moments that suit you for a 30-minute call