Compromise Assessment
Find out whether attackers are already inside your environment.
Integrity360's Compromise Assessment service provides a targeted investigation of your IT environment to identify evidence of current or historic malicious activity.
Using endpoint, network and cloud data alongside threat intelligence-led analysis, our Incident Response specialists look for signs of compromise that may have evaded existing security controls and provide clear recommendations for remediation.
What Is a Compromise Assessment?
A Compromise Assessment is a point-in-time investigation designed to determine whether an organisation has experienced, or is currently experiencing, malicious activity within its environment.
Integrity360 analyses available endpoint, network and cloud data for indicators and behaviours associated with compromise, including unauthorised access, suspicious account activity and evidence of attacker persistence.
The assessment helps establish whether threats are present, identify potential historic compromise and provide practical recommendations for investigation and remediation.
NCSC assured Cyber Incident Response
Integrity360 is an assured provider under the National Cyber Security Centre's Cyber Incident Response scheme, giving organisations additional confidence in the expertise and capabilities supporting our response to serious cyber incidents.
Our Compromise Assessment service draws on the same Incident Response and investigative expertise to help organisations identify evidence of malicious activity and determine whether further response or remediation is required.
Benefits of comprehensive analysis
-
Identify past or current breaches
-
Proactively prevent future breaches
-
Gained peace of mind from an IR expert review of your environment
-
Prove ‘clean bill of health’ to interested parties
-
Reduce risk and show evidence of due diligence
-
Network logs assessment
-
Endpoints assessment (EDR)
-
Cloud logs assessment
-
Dark Web / Brand Abuse search and review
-
Threat Intelligence led Threat Hunt
-
Comprehensive report with recommendations
Gain greater confidence in your environment
A Compromise Assessment provides evidence-based insight into whether signs of current or previous malicious activity are present within the assessed environment.
Where compromise is identified, Integrity360 can help determine the next steps for containment, investigation and remediation. Where no evidence of compromise is discovered, the assessment provides greater assurance based on the systems, data and time period reviewed.
Why choose Integrity360 for a Compromise Assessment?
-
Threat Intelligence-led analysis
Threat intelligence helps focus investigation on relevant attacker behaviours, indicators and techniques.
-
Coverage across your environment
Analyse endpoint, network, cloud and identity data to build a broader picture of potential compromise.
-
Actionable findings
Receive clear findings and prioritised recommendations rather than simply another set of security alerts.
-
Wider Incident Response support
If evidence of active compromise is discovered, Integrity360 can provide Emergency Incident Response, Digital Forensics and remediation support.
Our other Incident Response services include:
Emergency Incident Response
Incident Response Preparedness
Digital Forensics
Compromise Assessment FAQs
How does a Compromise Assessment work?
A Compromise Assessment typically begins by defining the systems and data sources to be reviewed. Security specialists then analyse endpoint, network, cloud and identity data for signs of malicious activity, validate suspicious findings and provide clear recommendations for remediation or further investigation.
What is the difference between a Compromise Assessment and a vulnerability assessment?
A vulnerability assessment looks for weaknesses that attackers could potentially exploit. A Compromise Assessment looks for evidence that an attacker may already have exploited a weakness and gained access to the environment. The two services are complementary but answer different security questions.
What is the difference between a Compromise Assessment and threat hunting?
A Compromise Assessment is usually a focused, point-in-time investigation designed to determine whether evidence of compromise is present. Threat hunting is a more proactive process that searches for hidden attacker activity using hypotheses, threat intelligence and behavioural analysis, often as part of an ongoing security programme.
What is the difference between a Compromise Assessment and Incident Response?
A Compromise Assessment is used to determine whether evidence of malicious activity or compromise exists. Incident Response is activated when an incident requires containment, investigation, eradication and recovery. If a Compromise Assessment identifies active compromise, the engagement may escalate into a full Incident Response investigation.
What are Indicators of Compromise?
Indicators of Compromise, or IoCs, are pieces of evidence that may suggest malicious activity has occurred. Examples can include suspicious IP addresses, malicious files, unusual authentication activity, unexpected processes, attacker infrastructure and other artefacts linked to known or suspected threats.
Can a Compromise Assessment detect a previous cyber attack?
Yes. Where sufficient evidence remains available, a Compromise Assessment can identify signs of historic attacker activity as well as current compromise. The ability to investigate previous incidents depends on factors such as log retention, endpoint data availability and how much time has passed since the suspected activity occurred.
Can a Compromise Assessment identify an attacker currently in our environment?
It can help identify evidence that an attacker is currently active within the assessed environment. This may include suspicious authentication, malicious processes, unusual network activity or persistence mechanisms. If active compromise is confirmed, immediate Incident Response may be required to contain and investigate the threat.
What systems are reviewed during a Compromise Assessment?
The exact scope depends on the organisation and available data. An assessment may include endpoint and EDR data, network and security logs, cloud environments, user identities, authentication activity and other relevant security telemetry needed to identify signs of compromise.
How long does a Compromise Assessment take?
The duration depends on the size and complexity of the environment, the amount of data available and the scope of the assessment. A focused assessment may be completed relatively quickly, while larger environments or investigations involving multiple data sources may require more extensive analysis.
Do we need to suspect a breach before requesting a Compromise Assessment?
No. Organisations may request a Compromise Assessment for additional assurance even when there is no confirmed incident. It can be useful following suspicious activity, a major vulnerability, an acquisition, a third-party incident or whenever greater confidence is needed that existing controls have not been bypassed.
Can a Compromise Assessment investigate cloud environments?
Yes. Where relevant data is available, a Compromise Assessment can include cloud platforms and SaaS environments. Analysis may focus on suspicious authentication, compromised identities, unusual access patterns, malicious applications and other evidence of unauthorised activity.
Can a Compromise Assessment identify compromised user accounts?
Yes. Identity and authentication data can be analysed for signs of account compromise, including unusual sign-ins, suspicious access patterns and other activity inconsistent with normal user behaviour. Findings can help determine whether additional accounts or systems may also require investigation.
What happens if evidence of compromise is discovered?
If malicious activity is identified, the findings are validated and the organisation is advised on the appropriate next steps. Depending on the severity of the compromise, this may include immediate containment, Digital Forensics, credential remediation, further threat hunting or escalation to Emergency Incident Response.
Does a Compromise Assessment prove that our environment is secure?
No assessment can guarantee that an environment is completely secure. A Compromise Assessment provides evidence-based assurance based on the systems, data sources and time period reviewed. If no signs of compromise are found, this means no evidence was identified within the scope of the assessment, rather than proving that compromise is impossible.
Speak to an expert
London: +44 20 3397 3414
Sofia: +359 2 491 0110
Cape Town: +27 08 606 25673
Johannesburg: +27 08 606 25673