SECURITY FOR YOUR BUSINESS
Understand the risk.
Do something about it.
Etisk Hacker AS helps you identify weaknesses, discover exposure and build better security habits. Much of the knowledge behind our services comes from Marius Jordet, a former hacker and part of our team.
Find the right service01 / CHOOSE WHERE TO START
Technology. People.
The whole picture.
Choose a service to explore its scope, delivery and how it can support your organisation’s security work.
Penetration testing
Test realistic attack paths within an agreed scope.
Explore the service 02 / ASSESSVulnerability assessment
Understand your technical weaknesses and which actions matter most.
Explore the service 03 / DETECTDark web monitoring
Discover exposed information and signs of misuse of your business identity.
Explore the service 04 / PRACTISEPhishing simulations
Understand how employees respond to realistic fraudulent messages.
Explore the service 05 / LEARNSecurity training videos
12 accessible training videos a year about safer digital choices.
Explore the service 06 / KEYNOTESStart with a wake-up call.
Keynotes with Eddie Strandengen make digital security practical, engaging and easy to understand.
Explore the keynotePenetration test or vulnerability assessment?
Both examine technical weaknesses. The right choice depends on how broadly and deeply you need to test.
| Need | Vulnerability assessment | Penetration testing |
|---|---|---|
| Main question | Which weaknesses should we prioritise? | How could the agreed attack paths be exploited? |
| Approach | Discovery and assessment, with controlled testing of selected findings. | Defined testing with greater emphasis on connected weaknesses and consequences. |
| Follow-up | Prioritised actions and optional regular scans. | Remediation and any retesting by agreement. |
02 / REGULATIONS AND DOCUMENTATION
Security you can
demonstrate.
Legal requirements, standards and recommended measures serve different purposes. See how our services can support your work.
Norwegian Digital Security ActNorwegian law · defined scope
The Act and regulations entered into force on 1 October 2025 and apply to specified essential and digital services. For essential services, the regulations detail requirements including risk assessment and security competence (sections 7 and 12).
Technical findings and training can support this work. The service does not replace the organisation’s own risk assessment or governance.
GDPR Article 32Legal requirement · proportionate to risk
Security when processing personal data must be appropriate to the risk. Article 32 includes regular testing, assessment and evaluation of security measures where appropriate.
Test results and follow-up can support organisational documentation. Scope and frequency require a specific assessment.
DORANorwegian law · financial sector
Norway’s DORA Act entered into force on 1 July 2025. From 1 September 2026, adapted DORA rules also apply to certain other businesses, including financing, debt collection and estate agency firms. The applicable provisions must be assessed for each entity.
Testing and training can form part of the relevant security work. An ordinary penetration test is not a TLPT test under DORA’s specific framework.
NIS2Preparation · Norwegian/EEA status
EFTA lists NIS2 as still under consideration for incorporation into the EEA Agreement. It is therefore presented here as preparation for Norwegian implementation, rather than a generally applicable Norwegian legal requirement. Activities in the EU may require a separate assessment.
Assessment, testing and learning can help identify areas for improvement before Norwegian implementation.
ISO/IEC 27001:2022Standard · may form part of contracts
ISO/IEC 27001 is a standard for information security management systems. It addresses systematic risk management and continual improvement. A service engagement is not the same as ISO certification.
Findings, actions and training can provide evidence within the management system. Relevance and documentation needs are agreed with the client.
Checked on 18 September 2026. Scope, exemptions and sector-specific requirements must be assessed for each organisation. This overview is general information, not legal advice. No individual service guarantees full compliance or certification.
NEXT STEP / A NO-OBLIGATION CONVERSATION
Let’s find the right starting point.
Tell us what you need a clearer view of. We’ll help you define a suitable scope.
We agree needs, scope and pricing before starting.
An enquiry carries no obligation to purchase.