Welcome to AKASEC

Covert Cyber Operations.

Welcome to AKASEC, where innovation meets cybersecurity excellence. Specializing in black teaming and offensive cybersecurity assignments, we emulate sophisticated threat actors, including state-sponsored groups known as advanced persistent threats (APTs).

At AKASEC, we go beyond hacking. With our vast experience working in the highest echelons of the Dutch government – we pioneer cutting-edge solutions to fortify your digital defenses against the ever-evolving cyber landscape.

New: Continuous Red Teaming — the same tradecraft, running against your environment every day instead of two weeks a year. Local AI on our own hardware, supervised by our operators.

What We Offer

Continuous Red Teaming ★★★★★
Black Teaming ★★★★★
SOC use case testing ★★★★
Offensive Tooling ★★★★
Red Teaming (ART + TIBER-NL) ★★★
Assessments ★★
Reconnaissance ★★

Click on About Us to learn more.

We are AKASEC.
We hack & protect.

Introduction

Who we are.

At AKASEC, we don't just hack; we innovate and safeguard. Our core proficiency revolves around pushing the boundaries of your digital defense mechanisms, employing advanced techniques to simulate the attack of a state or state-sponsored group, commonly referred to as advanced persistent threats (APTs).

As seasoned experts in hacking and protection, with our experience in the highest echelons of the Dutch government, we specialize in conducting comprehensive Black Teaming and Red Teaming exercises that mirror real-world cyber threats. We do not only identify vulnerabilities but we also fortify your defenses against the most sophisticated adversaries.

With a commitment to staying ahead of the curve, we also weaponize our development expertise to create cutting-edge offensive tooling and secure (mobile) communications to ensure your sensitive information remains confidential and protected against eavesdropping or unauthorized access.

Trust AKASEC to be your strategic partner in the ever-evolving landscape of cybersecurity, where innovation and vigilance are paramount.

Reconnaissance

Mapping all your online assets.

With Reconnaissance we map all the online assets of an organization, such as web servers, domain names, IP addresses, but also the footprint of the organization and even that of its employees. What does a hacker see that you don't? And how will a hacker use this information in an attack on your infrastructure to reach the crown jewels of the organization?

Want this as a recurring service? AKASCAN, our curated asset discovery platform, maps your external attack surface every month — AI-assisted, validated by our specialists.

Assessment

Answering a specific security question.

The Assessment aims to answer a specific security question. For example:

  • "What are the risks of our external attack surface?"
  • "Which open ports can be found within our external attack surface?"
  • "A new vulnerability has been published. Are we vulnerable?"
  • "Is our application secure enough to be made accessible via the internet?"
  • "What 'low hanging fruit' can be found in our web or mobile app?"
The security question is answered through automated and additional manual testing.

Penetration Test

Mapping digital vulnerabilities.

An important characteristic of a pentest is: a clear scope. A pentest is usually carried out on a web or mobile application or within (part of) an office network to expose as many digital vulnerabilities as possible within a short period of time. Through a combination of automated and manual testing (and a lot of creativity), the hackers try to gain unauthorized access to information and/or systems within the scope of the assignment.

The product of this test is a report with an overview of all vulnerabilities found - ranked by severity of the finding (CVSS score) - and advice with which the vulnerabilities can be resolved. The report is often explained during a presentation.

Red/Black Teaming

Advanced digital attacks.

Both Black Teaming and Red Teaming use simulated, realistic attacks to evaluate digital security. Both digital and physical attacks are carried out on systems, buildings and people (social engineering). An 'out of scope' is only agreed in exceptional cases, for example when a physical location is really not allowed to be entered due to various regulations.

Black Teaming specifically focuses on covert attacks carried out without the organization's knowledge (with approval, of course). For example, the test will take place in the year 2026, but the organization does not know exactly when, nor does the CISO.

Red Teaming takes a broader approach that evaluates the organization's overall security policy and may involve collaboration with internal and external security teams (defenders, or Blue Team). And of course, if required, we work via accepted frameworks such as MITRE ATT&CK® and the Dutch Advanced Red-Teaming (ART) framework, launched by the DNB.

Both forms are valuable for organizations that have already taken security measures and want to test and/or increase their cyber resilience. We base our attacks on a pre-agreed type of attacker (script kiddies, hacktivist, whistleblower, criminal, state). The 'insider threat' scenario in particular is increasingly discussed in organizations where the risk of corporate espionage is high.

Continuous Red Teaming

Adversary emulation, every day.

Your attack surface changes weekly; an annual engagement tests a snapshot. With Continuous Red Teaming, our platform performs continuous OSINT, external attack surface monitoring, exposure checks against newly published vulnerabilities and authorized active assessment — every day, at machine tempo.

It runs on AKASEC's own GPU hardware in our own datacenter in the Netherlands — local AI, not a hyperscaler — operates fail-closed against an explicitly authorized target list, and every finding is triaged by the same operators who run our covert engagements.

Read more on the dedicated page: Continuous Red Teaming.

SOC Use Case Testing

Testing the configuration and effectiveness of a SOC.

The organization has a - or uses an external - Security Operations Center (SOC) that monitors the most important digital assets (crown jewels). But how can the organization be sure that the SOC will effectively detect the attackers and mitigate their attacks? Have the SOC tested by having attackers trigger specific use cases with simulated attacks.

  • Validate the effectiveness of detection rules against real-world attack scenarios at all threat levels.
  • Stay at the forefront of evolving cyber threats through continuous testing and refinement.
  • Custom testing methodologies to assess unique use cases and security requirements.
  • Ensure that the SOC is technically properly configured to detect actual attackers.
  • Ensure that investments in the SOC deliver optimal results in protecting your digital assets.

Security Partnership

Structurally increasing digital security.

Hackers are extremely creative, goal-oriented and do not give up easily. Instead of having a security test carried out once a year, more and more organizations understand that attackers are constantly inventing new techniques to get past your defenses and that it is therefore important to provide resistance at the same level.

The Security Partnership is for two types of organizations:

  • The organization that has asked itself the question "Where do we want to be in the future in the field of information security?" and wants to learn and build cyber resilience throughout the year based on a Gap Analysis and Security Roadmap; and
  • The organization that is still at the beginning and benefits from structural support and continuous advice to increase cyber resilience.
With a Security Partnership, we provide the organization with continuous advice and feedback by acting as a sparring partner on security issues and by carrying out scoped assessments.

VIP Research

Mapping digital risks in personal privacy and security.

Nowadays, a lot of information about our private lives is posted online. This can happen through our own actions or because authorities publish sensitive data on the internet. In situations where there is an (acute) threat, it is essential that this sensitive information is removed or modified from the internet as quickly as possible.

AKASEC has the ability, at the request of an individual, to search for sensitive information that poses a risk to personal security. Using our specialized OSINT skills, we map this sensitive information so that the individual can attempt to have this information deleted or modified.

Offensive Tooling

From custom XDR bypass to secure software.

Did you know that Hackers are often also masters of software programming? They write custom code in various programming languages to exploit software vulnerabilities or bypass defenses.

The hackers at AKASEC all have a background as software developers and use their talents not only for the above, but also for developing offensive tooling such as automated attacks, command & control solutions (C2), secure software development training, and for the development of secure communication solutions (check out ZT-ONE.com).

ZT-ONE

Our secure mobile communications solution.

Afraid that a hacker is watching or listening in on sensitive conversations? Or do you want to blend in with the crowd by mixing your network traffic with other "noisy" traffic? AKASEC has developed a secure, encrypted mobile communications solution based on commercial hardware and software (COTS) that allows you to blend in with the crowd and stay protected from prying eyes.

The ZT-ONE is a mobile device (Google Pixel) that runs a highly secured version of Android: GrapheneOS. Apps cannot access sensor information such as geolocation and all network traffic is forced through the secure, encrypted Zero Trust connection due to our special user-centric policies.

You can optionally choose to monitor the ZT-ONE devices, so that immediate action can be taken based on deviations from normal traffic (alert). For more information, visit the website: https://zt-one.com

TIBER-NL

Red Teaming & Preparation Services.

At AKASEC, we do not only work via the Advanced Red Teaming (ART) framework, but we also specialize in high-impact Red Team operations under the TIBER-NL framework – the Threat Intelligence-Based Ethical Red teaming programme governed by De Nederlandsche Bank (DNB). We’ve supported multiple organizations as an official Red Team Provider (RTP), simulating sophisticated Advanced Persistent Threats (APTs) to test the real-world resilience of critical financial infrastructure.

Read more about our TIBER-NL experience: here

Start A Conversation

Visit Our Office

Wilhelmina van Pruisenweg 104
2595 AN The Hague
Netherlands

KvK/CC: 92701280
Trademark: click here

Continuous Red Teaming.

Your attack surface changes weekly. Your red team should too. AKASEC runs continuous adversary emulation against your organization — within an explicitly authorized scope, on our own sovereign infrastructure, supervised by the operators who run our covert engagements.

The gap

Annual testing, weekly change.

Most organizations test their resilience once or twice a year. Meanwhile the environment changes every week: new subdomains, new cloud tenants, new suppliers, new vulnerabilities published against software you were not running last quarter. An attacker does not wait for your next scheduled engagement — and eleven months is a long time for an exposed test environment to sit unnoticed.

Continuous Red Teaming closes that gap. The same offensive tradecraft we apply in scoped engagements, running against your environment every day instead of two weeks a year.

What it does

Concrete work, at machine tempo.

Our platform performs the repeatable parts of an offensive operation continuously, and our operators direct and validate it:

  • Continuous OSINT and reconnaissance of your organization, brand and personnel footprint.
  • External attack surface monitoring: new hosts, services, panels and certificates as they appear.
  • Exposure checks when new vulnerabilities are published against technology you actually run.
  • Drift detection: changes against your known baseline, flagged and investigated.
  • Authorized active assessment of findings that warrant it — validated by hand before it reaches you.

Authorized scope only

Fail-closed by design.

The first question about continuous testing should not be what it can find, but what it is allowed to touch. Our platform operates against an explicit, written target list agreed with you before anything runs. Anything outside that list is blocked and the attempt archived — the system fails closed, it does not improvise scope.

Active techniques beyond passive discovery are only used where the engagement agreement authorizes them, and destructive actions are never automated. You know at all times what may be touched, what happens to findings, and where the logs live.

Sovereign by design

Local AI, on our own hardware.

Most attack surface platforms ship telemetry about your organization to a hyperscaler's cloud, in someone else's jurisdiction, and pipe your data through third-party AI APIs. We don't. The analysis runs on AKASEC's own GPU hardware, in our own datacenter in the Netherlands — local AI models, never a hyperscaler cloud or a third-party AI service. Your findings, logs and target data stay with one accountable Dutch counterparty, not a chain of foreign subprocessors.

Operator-supervised

Machine tempo, human judgment.

Automation finds signals; it does not decide what matters. Every finding is triaged by AKASEC operators — the same specialists who run our Black Teaming and Red Teaming engagements, with backgrounds in the highest echelons of the Dutch government and experience in TIBER-style regulated engagements. What reaches you has been judged by someone who has used findings like it in a real operation.

What you receive

A cadence, not a report shelf.

  • Immediate alerts on material change: a new exposure, a leaked credential, a reachable panel that was not there yesterday.
  • Periodic reporting with validated findings, evidence, and prioritized recommendations — readable by your board and actionable by your engineers.
  • Quarterly review with the operators: trends, structural weaknesses, and where the next scoped engagement pays off.

How it fits

Discovery feeds emulation. Emulation feeds defense.

Continuous Red Teaming builds on the discovery layer of AKASCAN, our curated external asset discovery service: AKASCAN maps what is publicly visible; Continuous Red Teaming validates what it means under authorized active testing.

The output feeds directly into your defense: findings become SOC use cases we can test, detection gaps become engineering work, and each scoped Red or Black Team engagement starts from an up-to-date picture instead of a six-month-old inventory.

Credentials

Who you are trusting.

AKASEC is a Dutch company (KvK 92701280) based in The Hague. Our operators have backgrounds in the highest echelons of the Dutch government and experience with regulated engagements in the Dutch financial sector. Our methodology aligns with MITRE ATT&CK, and personnel working on government and critical infrastructure engagements are screened.

Start the conversation

A brief first, a pilot second.

Request the technical brief for a document you can circulate internally: deployment model, authorization controls, data handling and reporting cadence. Or start with a scoped pilot on a single authorized domain and judge the output yourself.

Get in touch!

Start A Conversation

Visit Our Office

Wilhelmina van Pruisenweg 104
2595 AN The Hague
Netherlands

KvK/CC: 92701280
Trademark: click here

Discovery Layer

Not ready for continuous testing? Start with passive discovery: AKASCAN maps your external attack surface every month — no active testing, self-serve intake.

Shareable Link

Forward this offer: akasec.com/continuous-red-teaming