Penetration Test
Penetration Test
Application penetration test, code review, reverse engineering, ethical hacking and APT test against cyber threats
Proactively protect your web shop, internet banking platform, mobile app, ICS (SCADA / DCS), IoT device or IT infrastructure via penetration test, code review, reverse engineering or APT test by our certified penetration testers and security researchers.
ISO 27001 Security Audit
ISO 27001 Security Audit
ISO-compliant assessment of your information security landscape
Analyze and benchmark your information security level based on international standards (ISO 27001, ISO 27002, SANS 20, IEC 62443, NERC CIP, etc.) to plan your IT budget for security mitigation measures.
Incident Response & IT Forensics
Incident Response & IT Forensics
Fast, professional reaction to cyber attacks and unwanted digital activities plus court-proof investigation
Respond appropriately and effectively to malware infection, hacker attack, fraud, data theft and other criminal or unwanted digital activities with the support of our certified IT security and forensics experts.

Oneconsult group is your renowned Swiss cyber security services partner since 2003 with offices in Switzerland and Germany and 1300+ completed security projects worldwide. Get expert advice from an owner-managed and vendor-independent consultancy with 30+ highly qualified experts, including certified penetration testers (OPST, OPSA, OSCP, GXPN), digital forensics specialists (GCFA, GCFE, GREM), ISO security auditors (ISO 27001 Lead Auditor) and dedicated IT security researchers to solve even your most demanding information security challenges. Together we address your external and internal threats such as malware infections, hacker attacks and APT as well as digital fraud and data leakage with core services like penetration tests / ethical hacking, real-life APT tests and ISO 27001 security audits. In case of emergency, Oneconsult’s incident response & IT forensics team supports you with around-the-clock expert assistance (24 h x 365 days).

Events

18-10-2017: Schlossgeflüster, «You have been hacked!» (Workshop in German)

with Yves Kraft (Branch Manager Bern, Senior Penetration Tester & Security Consultant at Oneconsult AG)

«You have been hacked!» – Why it can hit anyone and what you can do against it [more]

Das Grundrauschen in unserer Umgebung – Reverse Engineering von Funksignalen mit Software Defined Radio (SDR) (Video Oneconsult Vortrag)

In this talk in German also held at the Digicomp Hacking Day 2017, Yves Kraft (Branch Manager Bern, Senior Penetration Tester & Security Consultant at Oneconsult AG) illustrates how radio signals of everyday objects are analyzed. [more]

News & Advisories

CAA, the new control against unintended certificate mis-issue

by Gregor Wegberg

With the introduction of Certification Authority Authorization (CAA) domain holders can specify the Certificate Authorities authorized to issue certificates for the domain. This article in German explains CAA and its use.

[more]

Bring Your Own Key (BYOK) und Bring Your Own Encryption (BYOE) - die Lösung aller Sicherheitsprobleme in der Cloud?

by Immanuel Willi

This Oneconsult Security Advisory in German illustrates the strenghts and the weaknesses of BYOK and BYOE and provides food for thought on their sensible use. [more]

Pen Tester's Diary

Falsch gesetzte User-Berechtigungen: Hacker's Paradise

by Marco Wohler

There are different strategies and means to protect a server or client against attacks from inside or outside. This article in German deals with file and folder rights, since these are often neglected. [more]

Trau schau wem – (Un)Sicherheit von signierter Software unter Windows

by Jan Alsenz & Rafael Scheel

This article in German demonstrates how a design security flaw discovered by Oneconsult can be abused in the Microsoft UAC mechanism to allow any scripts and programs to fake a supposedly genuine Microsoft signature.
[more]

Our customers value our expertise and vast project experience of over

0

Penetration test projects, over 850 of which OSSTMM-compliant

0

Application penetration test projects of banking solutions, online shops, mobile apps, ICS (SCADA/DCS), IoT devices, ERP and CRM solutions, CMS, VoIP systems, etc.

0

Security auditse.g. according to ISO 27001, ISO 27002, industry specific guidelines (ISO 27015, 27019, 27799, etc.) or SANS Critical Security Controls

Methods and Standards

Our approach is customized to meet our clients’ specific needs as well as based on «best practice». In addition to our own methods, we also rely on industry-proven standards.

Holding

Oneconsult International AG
Schuetzenstrasse 1
8800 Thalwil
Switzerland

Tel +41 43 377 22 66
Fax +41 43 377 22 77
info@oneconsult.com

Switzerland

Headquarters
Oneconsult AG
Schuetzenstrasse 1
8800 Thalwil
Switzerland

Tel +41 43 377 22 22
Fax +41 43 377 22 77
info@oneconsult.com

Oneconsult AG
Baerenplatz 7
3011 Bern
Switzerland

Tel +41 31 327 15 15
Fax +41 31 327 15 25
info@oneconsult.com

Germany

Oneconsult Deutschland GmbH
Agnes-Pockels-Bogen 1
80992 Munich
Germany

Tel +49 89 248820 600
Fax +49 89 248820 677
info@oneconsult.com