How Secfix Closed the Gap Between Annual Pentests and Constant Code Changes

Link copied!
Jorge Monteiro

Jorge Monteiro

CEOEthiack

June 26, 2024

Secfix helps SMBs achieve ISO 27001 and TISAX compliance in weeks instead of months. Their customers trust them with the audit trail of their entire security programme. That trust has to be earned every day.

Annual pentests were costing too much and proving too little

Grigory, Secfix's co-founder and CTO, was already running pentests regularly. The problem wasn't intent: it was economics and frequency.

Pentests are expensive. Expensive means infrequent. Infrequent means that every code deployment in between was an unverified change to the attack surface, and Secfix was deploying often. The compliance product evolved every week. Validation didn't.

Grigory needed continuous, in-breadth testing to complement deep periodic pentests, not replace them.

A platform deployed in minutes, integrated into the workflow

Secfix added a DNS record, selected the assets to test, and Ethiack was running. Hackian started validating exploitability across Secfix's external attack surface continuously, with real-time alerts, prioritised risk scoring, and automated retesting that confirms when a fix has actually worked.

The annual pentests stayed for in-depth scope. Continuous validation closed the gap between them.

Having the reliability of an automated pentesting tool improves our security posture and helps our engineers write better, more secure code.I really like the product and how easy it is to use it! I’d recommend it to other small startups as well. It will cover the essentials and is actually affordable.

Grigory EmelianovCo-Founder & CTOSecfix

The reports do double duty: they drive engineering's prioritisation queue, and they translate security investment into language stakeholders understand.

Selling compliance and need to prove your own continuously? Start a free 30-day trial →

Don’t wait for the attack.

Secure Your Future with Ethiack

Try Ethiack

If you're still unsure convince yourself with a 30-day free trial. No obligation. Just testing.

signup(datetime.now());

def hello(self): print("We are ethical hackers")

class Ethiack: def continuous_vulnerability_discovery(self: Ethiack): self.scan_attack_surface() self.report_all_findings() def proof_of_exploit_validation(self: Ethiack): self.simulate_attack() self.confirm_exploitability() self.validate_impact()

while time.time() < math.inf: ethiack.map_attack_surface() ethiack.discover_vulnerabilities() ethiack.validate_exploits() ethiack.generate_mitigations() ethiack.calculate_risk() ethiack.notify_users() log.success("✓ Iteration complete")

>>> show_testimonials() They found vulnerabilities no one else did. Fast, real, and actionable results. It's like having a red team on call. >>> check_socials()

signup(datetime.now()) meet(ethiack)

def actionable_mitigation_guidance(ethiack): ethiack.generate_mitigation_steps() ethiack.prioritize_fixes() ethiack.support_teams() def attack_surface_management(ethiack): while time.time() < math.inf: ethiack.map_attack_surface() ethiack.monitor_changes() def quantifiable_risk_reduction(ethiack): ethiack.check_risk_metrics() ethiack.calculate_delta() return ethiack.report_real_risk()

Activate AI penTesting

Start a Free 30-day trial
Ethiack — Autonomous Ethical Hacking for continuous security Continuous Attack Surface Management & Testing