SECURITY FOR YOUR BUSINESS

Understand the risk.
Do something about it.

Etisk Hacker AS helps you identify weaknesses, discover exposure and build better security habits. Much of the knowledge behind our services comes from Marius Jordet, a former hacker and part of our team.

Find the right service

01 / CHOOSE WHERE TO START

Technology. People.
The whole picture.

Choose a service to explore its scope, delivery and how it can support your organisation’s security work.

Penetration test or vulnerability assessment?

Both examine technical weaknesses. The right choice depends on how broadly and deeply you need to test.

NeedVulnerability assessmentPenetration testing
Main questionWhich weaknesses should we prioritise?How could the agreed attack paths be exploited?
ApproachDiscovery and assessment, with controlled testing of selected findings.Defined testing with greater emphasis on connected weaknesses and consequences.
Follow-upPrioritised actions and optional regular scans.Remediation and any retesting by agreement.

02 / REGULATIONS AND DOCUMENTATION

Security you can
demonstrate.

Legal requirements, standards and recommended measures serve different purposes. See how our services can support your work.

Norwegian Digital Security ActNorwegian law · defined scope
REQUIREMENTS / STATUS

The Act and regulations entered into force on 1 October 2025 and apply to specified essential and digital services. For essential services, the regulations detail requirements including risk assessment and security competence (sections 7 and 12).

HOW WE ASSESS THE SERVICE’S CONTRIBUTION

Technical findings and training can support this work. The service does not replace the organisation’s own risk assessment or governance.

GDPR Article 32Legal requirement · proportionate to risk
REQUIREMENTS / STATUS

Security when processing personal data must be appropriate to the risk. Article 32 includes regular testing, assessment and evaluation of security measures where appropriate.

HOW WE ASSESS THE SERVICE’S CONTRIBUTION

Test results and follow-up can support organisational documentation. Scope and frequency require a specific assessment.

DORANorwegian law · financial sector
REQUIREMENTS / STATUS

Norway’s DORA Act entered into force on 1 July 2025. From 1 September 2026, adapted DORA rules also apply to certain other businesses, including financing, debt collection and estate agency firms. The applicable provisions must be assessed for each entity.

HOW WE ASSESS THE SERVICE’S CONTRIBUTION

Testing and training can form part of the relevant security work. An ordinary penetration test is not a TLPT test under DORA’s specific framework.

NIS2Preparation · Norwegian/EEA status
REQUIREMENTS / STATUS

EFTA lists NIS2 as still under consideration for incorporation into the EEA Agreement. It is therefore presented here as preparation for Norwegian implementation, rather than a generally applicable Norwegian legal requirement. Activities in the EU may require a separate assessment.

HOW WE ASSESS THE SERVICE’S CONTRIBUTION

Assessment, testing and learning can help identify areas for improvement before Norwegian implementation.

ISO/IEC 27001:2022Standard · may form part of contracts
REQUIREMENTS / STATUS

ISO/IEC 27001 is a standard for information security management systems. It addresses systematic risk management and continual improvement. A service engagement is not the same as ISO certification.

HOW WE ASSESS THE SERVICE’S CONTRIBUTION

Findings, actions and training can provide evidence within the management system. Relevance and documentation needs are agreed with the client.

NEXT STEP / A NO-OBLIGATION CONVERSATION

Let’s find the right starting point.

Tell us what you need a clearer view of. We’ll help you define a suitable scope.

We agree needs, scope and pricing before starting.
An enquiry carries no obligation to purchase.

How can we help?

Choose a service and tell us a little about your needs.

I would like

Opens your email app with a draft to Eddie. Review it and send it yourself. This form does not store your details.