CREST-Accredited Offensive Security and Penetration Testing for SLED Agencies

Public sector organizations are expected to protect critical systems, sensitive data and essential services while operating with limited resources, complex technology environments and security requirements that continue to evolve. State and local agencies, school systems and other public institutions also face a challenge that many commercial organizations do not: when a critical service is disrupted, the people who depend on it often have no alternative.
OSec helps public sector organizations understand where they are genuinely exposed before an attacker finds out first.

For 15 years, OSec’s offensive security specialists have tested real environments against the techniques used by ransomware groups, criminal operators and sophisticated adversaries. Across more than 250,000 hours of offensive security work, our focus has remained the same: go beyond identifying theoretical vulnerabilities and determine what an attacker could actually exploit, how far they could move and which critical systems or data they could ultimately reach.
Our professional services are led by experienced security operators and include penetration testing, red and purple team engagements, ransomware readiness, threat hunting, incident readiness, AI red teaming, OT/ICS security testing and security program advisory.

For state, local and education organizations, testing can also be scoped with public sector security and compliance requirements in mind, including CJIS, StateRAMP and IRS Publication 1075. Engagements can be aligned with established testing methodologies such as NIST SP 800-115, OWASP and PTES, helping agencies produce meaningful evidence for security teams, auditors, leadership, insurers and other stakeholders.

OSec’s approach is built around proving risk rather than generating another list of potential findings. Our operators validate vulnerabilities, examine how individual weaknesses can be chained together and prioritize findings according to the real-world impact they could have on the organization.

That matters for public sector teams that may be responsible for protecting dozens of systems with only a handful of security or IT professionals. Instead of leaving teams with hundreds of scanner alerts to investigate, OSec focuses remediation efforts on the exposures that create credible paths to compromise.
Every penetration testing engagement includes actionable remediation guidance from the operators who performed the testing, along with a retest after remediation to confirm that identified weaknesses have been properly addressed.

Across OSec penetration testing engagements, 92% surface at least one critical issue. Finding those issues through controlled testing gives agencies the opportunity to remediate them before they become an incident that disrupts the services their communities rely on.

Does OSec's penetration testing satisfy CJIS, StateRAMP and IRS Pub 1075 requirements?

OSec can scope and document penetration testing engagements with CJIS, StateRAMP and IRS Publication 1075 requirements in mind. Testing provides validated findings, remediation guidance and documentation that can support an agency’s security assessment, compliance and audit activities.

Engagements can also be aligned to established methodologies including NIST SP 800-115, OWASP and PTES. Specific compliance obligations and testing requirements are confirmed during scoping.

How is this different from a vulnerability scan or an automated pen test?

A vulnerability scanner identifies potential weaknesses based largely on signatures, configurations and known vulnerabilities. OSec’s penetration testers go further by attempting to validate whether identified weaknesses can actually be exploited and determining what an attacker could reach as a result.

Operators may chain multiple weaknesses together to demonstrate how an initial foothold could lead to lateral movement, privilege escalation or access to sensitive systems. This gives security teams evidence of which exposures represent meaningful risk rather than another unprioritized list of potential findings.

Can a small agency with a two- or three-person IT team afford this?

That is most of our public sector work. Engagements are fixed-scope and sized to public budgets, findings are prioritized so a lean team works the handful that matter instead of a spreadsheet of a thousand, and remediation guidance comes from the operator who found the issue, so you are not left translating a report on your own. Retesting after you remediate is included.

Will testing disrupt live citizen services or operational technology?

Testing is carefully scoped to minimize operational disruption. Before an engagement begins, OSec and the customer establish written rules of engagement, testing windows, communication procedures, escalation contacts and stop conditions.

Testing involving operational technology and industrial control systems receives additional consideration because availability and safety are critical. These engagements use deliberately controlled testing methodologies appropriate to the environment and can be aligned with ISA/IEC 62443 principles.

What do we actually receive at the end of an engagement?

A scoped plan with agreed rules of engagement up front; expert-led exploitation carried out by senior operators; a prioritized report that rates each finding against the service it puts at risk rather than CVSS alone; a walkthrough of findings with your team; full remediation guidance; and a free retest once the fixes are in.