HodeiShield: The European TPRM platform with native NIS2, ENS, and DORA
We simulate real attacks against your infrastructure, applications, and people to uncover vulnerabilities before attackers do. Our team thinks like an adversary so you can defend like a professional.
Every phase ends in your actionable report →
You don't know if your infrastructure would withstand a targeted real attack
Automated vulnerability scans don't detect exploitable business logic
Your internal team lacks the offensive perspective needed
Regulators (NIS2, ENS) require periodic penetration testing
Four pillars that apply to every service and every solution, not a one-off slogan.
The same team that attacks in the pentest runs the SOC and builds the AI models. Offensive insight informs defense, and AI is applied where we already operate, not bolted on as an extra layer.
HodeiShield, our own platform, automates continuous assessment, control mapping, and evidence generation — so manual work no longer sets the pace of regulatory compliance.
Infrastructure on OVHcloud (France/EU). You speak with the people who sign off on the work, not an account manager who forwards your request to another department.
HodeiShield isn't a third-party product we resell: we build and operate it ourselves, and that's what lets us offer faster compliance and evidence that's always current.
Deliverables and results you will receive with this service.
Comprehensive analysis of networks, servers, firewalls, and devices. Identification of misconfigurations, exposed services, and privilege escalation vectors.
In-depth OWASP Top 10 testing: SQL injection, XSS, CSRF, IDOR, broken authentication. Business logic and API analysis.
Static and dynamic analysis of iOS and Android apps. Review of local storage, communications, authentication, and obfuscation.
Simulated phishing campaigns, vishing, pretexting, and physical access testing. We measure your organization's human resilience.
Advanced adversary (APT) simulation with defined objectives. We combine digital, social, and physical techniques over weeks of covert operation.
Two-level reporting: executive summary for management with business risk, and detailed technical report with evidence, PoCs, and prioritized remediation plan.
Discovery, execution, delivery, and follow-up — the framework we follow on every project.
We define scope, rules of engagement, and objectives, and gather intelligence on your attack surface: infrastructure, applications, and people.
We run the controlled attacks following OWASP, PTES, and MITRE ATT&CK, and assess the real impact: data access, lateral movement, and privilege escalation.
We deliver the executive and technical report with findings classified by criticality (CVSS), reproducible evidence, and a prioritized remediation plan.
Free re-test after remediation to confirm vulnerabilities are fixed, with documented evidence for your next audit.
Structured methodology to ensure measurable and repeatable results.
We define scope, objectives, constraints, and communication channels. We sign non-disclosure agreements and legal authorizations.
Intelligence gathering on the organization: external attack surface, technologies, employees, vendors, and potential entry points.
Execution of controlled attacks following OWASP, PTES, and MITRE ATT&CK methodologies. We document every finding with reproducible evidence.
We assess the real impact: access to sensitive data, lateral movement, privilege escalation, and persistence.
We deliver a report with vulnerabilities classified by criticality (CVSS), business impact, and a prioritized remediation plan.
Free re-test after remediation to confirm that vulnerabilities have been effectively fixed.
A real scenario of how we work, not a marketing figure.
A web application pentest finds an IDOR that lets an attacker view other customers' invoices by changing an identifier in the URL. The finding is documented with a reproducible proof of concept, classified as critical under CVSS, and handed to the dev team with the affected code path and the recommended fix — not just the vulnerability's name.
This service is designed for organizations that identify with these profiles.
No names — here's how we work differently, with verifiable facts.
| Criteria | Generalist integrator | Hodeitek |
|---|---|---|
| Focus | Dozens of business lines; cybersecurity is just one of them | 100% cybersecurity and AI |
| Point of contact | An account manager who forwards your request to another department | Direct contact with the founders |
| Regulatory compliance | One-off reports per regulation, manual evidence management | HodeiShield automates evidence and cross-framework NIS2/ENS/DORA mapping |
| Product | Resells third-party licenses | Builds and operates HodeiShield, its own platform |
How what this service already includes relates to NIS2, DORA, and the AI Act — article by article, with no invented coverage.
| Framework | Article | What it requires | How this service helps |
|---|---|---|---|
| NIS2 | Art. 21(2)(f) | Periodically evaluate the effectiveness of cybersecurity risk-management measures. | The pentest and the full Red Team put your controls to the test with real attacks; the CVSS-classified findings report and the remediation re-test provide the evidence for that periodic evaluation — they don't replace the rest of Article 21's measures. |
| DORA | Art. 24–27 | Run a digital operational resilience testing programme, including threat-led penetration testing (TLPT, Art. 26) for entities meeting the criteria. | The full Red Team simulates an advanced adversary over weeks of covert operation — the same approach as a TLPT exercise — and, as noted for financial-sector clients, findings map to DORA's testing requirements. It helps cover the testing programme; it doesn't by itself satisfy the requirements Article 27 of DORA sets for TLPT testers. |
Informational mapping, not legal advice: it describes how what we already do in this service helps comply with or provides evidence for each article — it doesn't replace a compliance assessment tailored to your organization.
Talk to our team of experts to design a plan tailored to your organization's needs.
Response within 24h
Assess, monitor, and govern the cybersecurity risk introduced by your vendors, third-party software, and your organization's Nth-party dependencies.
Hodeitek's team are Spanish regulatory specialists as well as ransomware responders: the controls below apply everywhere, and where we reference Spain's National Security Framework (ENS, set by Spain's National Cryptologic Center, CCN) or the EU's DORA regulation, that's Spain- or EU-specific context for organizations operating there or in its regulated sectors. Comprehensive strategy for prevention, early detection, and rapid response to ransomware attacks.