Overview Founded in 2019, Iterasec is a cybersecurity service company providing penetration testing, security audits, application and cloud security, DevSecOps and security compliance services for tech and software engineering companies. With a team of 20 cybersecurity specialists, we are laser-focused on improving the security of various software and cloud products, as well as helping development teams build more secure software. Our clients range from small startups to global multinational companies, such as well-known automotive companies, cloud providers, Fortune 500 companies, etc. Our key services: – Security assessments and penetration testing – Hardware and Firmware security testing – Cloud and Container security audits – Network pentest – Threat Modeling – Managed Application Security – DevSecOps – ISO 27001 / SOC2 / HIPAA / GDPR guided implementation and support
Overview Founded in 2019, Iterasec is a cybersecurity service company providing penetration testing, security audits, application and cloud security, DevSecOps and security compliance services for tech and software engineering companies. With a team of 20 cybersecurity specialists, we are laser-focused on improving the security of various software and cloud products, as well as helping development teams build more secure software. Our clients range from small startups to global multinational companies, such as well-known automotive companies, cloud providers, Fortune 500 companies, etc. Our key services: – Security assessments and penetration testing – Hardware and Firmware security testing – Cloud and Container security audits – Network pentest – Threat Modeling – Managed Application Security – DevSecOps – ISO 27001 / SOC2 / HIPAA / GDPR guided implementation and support
Overview Founded in 2019, Iterasec is a cybersecurity service company providing penetration testing, security audits, application and cloud security, DevSecOps and security compliance services for tech and software engineering companies. With a team of 20 cybersecurity specialists, we are laser-focused on improving the security of various software and cloud products, as well as helping development teams build more secure software. Our clients range from small startups to global multinational companies, such as well-known automotive companies, cloud providers, Fortune 500 companies, etc. Our key services: – Security assessments and penetration testing – Hardware and Firmware security testing – Cloud and Container security audits – Network pentest – Threat Modeling – Managed Application Security – DevSecOps – ISO 27001 / SOC2 / HIPAA / GDPR guided implementation and support
Client Innocode develops a digital media and publishing solution for newspapers and local communities. Goals Innocode engaged Iterasec in a holistic security review of the solution: – Several customer-facing applications– Mobile Apps– API/Backend– Cloud and container security audit Solution and results Before starting the pentest, Iterasec wanted to perform a joint threat modeling exercise. First, Iterasec performed an introductory workshop for the product team, explaining the methodology and basics of threat modeling. Later, after preparing a DFD diagram, Iterasec facilitated two threat modeling sessions with the team. Going forward, Iterasec started with application security testing of the web and mobile applications and API interfaces. The tests followed OWASP ASVS/MASVS but also focused on finding non-obvious vulnerabilities and chaining them into potentially efficient attacks. Next, Iterasec performed a Google Cloud Platform and Kubernetes security audits, mainly relying on CIS Benchmark tools and manual findings analysis. All the findings were summarised in the final pentest report along with the recommendations. Iterasec supported the team in fixing security issues and ensured security fixes were applied correctly. The team consisted of 1 Senior Security Consultant, 2 Pentesters and 1 Delivery Manager.
Client Securrency is a fintech company that provides an infrastructure for digital assets markets. The company engaged Iterasec to perform security testing of the different product components. Cooperation We’ve been working with Securrency for over 3 years now. Initially started with web application penetration testing, Iterasec was also involved in the security of mobile Apps. Iterasec also performed a series of smaller API pentest, allowing the team to build and deploy its product iteratively, ensuring it is secure at each product development leap.
Client Open Social is a company that builds community software for leading organizations like the United Nations, Greenpeace International and the European Commission. Cooperation Open Social reached out to Iterasec in 2021 requesting to build ISO 27001 certification. The first project, Guided ISO 27001 implementation, took about a year and the company successfully passed the certification. After that, we’ve been working on several other projects, including the pentest of the Open Social Drupal-based product, performing security code reviews, incident management consulting, information security training, etc. Iterasec remains a trusted cybersecurity partner for Open Social, providing on-the-spot cybersecurity services. For a small company such as Open Social, this is much more efficient as compared to retaining its own cybersecurity team.
Client Lemberg Solutions is an IoT and Software development company. With more than 200 employees, it develops complex IoT solutions for healthcare, automotive, smart consumer devices and many other industries. Overview In 2020, the company initially reached out to us for consultancy services in implementing the ISMS and ISO 27001 certification. Going forward, many more projects followed, both for Lemberg Solutions (ISO 9001, ISO 13485, internal penetration tests) and well for their clients (security penetration tests of the various customers’ software products). Cooperation Iterasec started with building efficient ISMS in the company that both fulfils ISO 27001 and at the same time is lightweight and efficient in practice. After a year of active preparation using our Guided Compliance Implementation services, Lemberg Solutions became ISO 27001 and ISO 9001 certified. After the first successful project, Iterasec integrated with Lemberg Solutions even more closely. At the moment Iterasec provides a number of services: – Supporting ISMS and acting as Virtual CISO– On-demand compliance support (such as GDPR issues)– Application Security: integration in several client development projects, pentests, secure development lifecycle, DevSecOps– Providing various security training to the engineering and data science teamsResultThe company can focus more on clients and engineering expertise. By closely integrating with the company, Iterasec provides all the benefits of the in-house security team while costing much less both in terms of money and operational efforts. With more than three years of a successful partnership.
Overall rating
14 Reviews
Expertise
Accuracy of Cost Estimates
Value for Money
Communication
Accuracy of Timeline
The Project
Cybersecurity
Completed
Jul 2023 - Jan 2024
25000-50000 USD
CTO
Confidential
50 - 249 employees
Overall rating
Expertise
5Accuracy of Cost Estimates
5Communication & Responsiveness
5Accuracy of Timeline
5Value for Money
5Willingness to Refer
Summary
Partnering with Iterasec was a game-changer for our mobile and IoT development company. Their expertise and dedication enabled us to establish a robust ISMS foundation and achieve ISO certifications. The seamless workflow and valuable support provided by Iterasec paved the way for a successful partnership, leaving us highly satisfied with the outcomes.
Project Description
Our decision to partner with Iterasec was driven by our goal to enhance our ISMS and achieve ISO 27001 and ISO 9001 certifications. Iterasec’s expertise in security compliance and project delivery made them the perfect fit for our needs. The project encompassed various stages including planning, implementation, internal audit, and ongoing support. Iterasec’s team, comprised of a Virtual Information Security Manager and a Project Manager, provided invaluable guidance and coordination throughout the certification process.
Pros
Iterasec worked diligently to meet our internal team’s needs and requirements, resulting in us obtaining ISO 27001 and ISO 9001 certifications. Their effective communication and proactive approach made the collaboration seamless. We were impressed by their practical security compliance experience and commitment to delivering high-quality services.
Cons
While we were overall satisfied with the project quality and experience, there were no significant areas for improvement that stood out during our collaboration with Iterasec.
Switched from another provider?
yes
Considered other providers?
yes
The Project
Cybersecurity
Completed
Nov 2023 - Jan 2024
25000-50000 USD
Co-Founder & CTO
Confidential
2 - 9 employees
Overall rating
Expertise
5Accuracy of Cost Estimates
5Communication & Responsiveness
5Accuracy of Timeline
5Value for Money
5Willingness to Refer
Summary
Iterasec’s team was efficient and effective in completing the penetration testing for our PPC auditing company. Their clear instructions and thorough testing outside of our organization were particularly impressive.
Project Description
I discovered Iterasec through a referral and chose them over other options. Our primary form of communication was virtual meetings. They were tasked with executing a penetration test on our platform to meet ISO 27001 requirements.
Pros
Iterasec executed everything according to plan and provided us with weekly progress reports. They gave clear instructions at the beginning of the project and handled most of the testing externally.
Cons
No areas for improvement were identified during our collaboration.
Switched from another provider?
yes
Considered other providers?
yes
The Project
Cybersecurity
Completed
Jan 2022 - May 2023
25000-50000 USD
CTO
Confidential
50 - 249 employees
Overall rating
Expertise
5Accuracy of Cost Estimates
5Communication & Responsiveness
5Accuracy of Timeline
5Value for Money
5Willingness to Refer
Summary
Working with Iterasec was a highly beneficial experience for our software development company. Their meticulous security audits, insightful recommendations, and effective communication made a significant impact on improving our overall security posture.
Project Description
Our collaboration with Iterasec involved a comprehensive security assessment of our software development company’s platform infrastructure and code. Their team conducted in-depth security audits, provided valuable recommendations, and delivered detailed reports to enhance our security measures.
Pros
Iterasec impressively identified numerous risks and configuration vulnerabilities, providing valuable training on threat modeling and secure SDLC processes. They kept us constantly updated and delivered reports in a timely manner, showcasing their expertise in auditing.
Cons
There were no significant drawbacks or areas for improvement during our collaboration with Iterasec. All aspects of their service met our expectations and requirements.
Switched from another provider?
yes
Considered other providers?
yes
The Project
Cybersecurity
Completed
Aug 2020 - Jun 2022
25000-50000 USD
Project Manager
Confidential
10 - 49 employees
Overall rating
Expertise
5Accuracy of Cost Estimates
5Communication & Responsiveness
5Accuracy of Timeline
5Value for Money
5Willingness to Refer
Summary
Working with this company was a valuable experience, as they provided us with a fresh perspective on our security challenges and offered practical solutions for improvement.
Project Description
I chose this vendor based on their reputation as experienced professionals in the cybersecurity field. Our project involved conducting penetration tests on our web application and servers, with the team providing valuable insights and recommendations for enhancing our security measures.
Pros
They delivered a thorough and prioritized list of vulnerabilities, improving our overall security posture. Communication with the team was seamless and effective.
Cons
No specific areas for improvement were identified during our collaboration.
Switched from another provider?
yes
Considered other providers?
yes
Headquarter
L'viv, Volodymyra Velykoho Street
9.9% fee. 18-month guarantee. Top talent, fast.
Enterprise Solutions & Ecommerce Apps
JBHired is a recruitment agency specializing in sourcing senior digital and technology talents for its clients.