Frequently asked questions about our services
What each practice covers, where the boundaries between them sit, and how an engagement starts.
On this page
Choosing a service
Offensive security
Incident response and digital forensics
Governance and compliance
Choosing a service
What cybersecurity services does OKIOK provide?
OKIOK provides offensive security, governance and compliance, incident response, digital forensics, cybersecurity consulting, identity compliance services and custom cybersecurity solutions. Our specialists work as one team, so an engagement can draw on several practices when needed.
I know I have a cybersecurity problem, but not which service I need. Where do I start?
Start with the problem, risk or requirement you are trying to address. Our experts can help determine what needs to be done, which expertise is required and the most practical way to move forward.
Can OKIOK combine several services in the same engagement?
Yes. Cybersecurity challenges rarely fit neatly into one discipline. A compliance initiative may require penetration testing, an incident may lead to digital forensics and remediation work, and a strategic consulting mandate may involve identity, architecture or custom development expertise. OKIOK brings the required specialists together around the same objective.
Offensive security
What is the difference between a penetration test and a vulnerability assessment?
A vulnerability assessment primarily identifies known vulnerabilities, typically using automated tools. A penetration test goes further: our experts actively attempt to exploit weaknesses and combine them into attack paths to determine what a real attacker could achieve.
How quickly can OKIOK perform a penetration test?
Penetration tests can typically be scheduled within two weeks, depending on team availability, scope and client priorities. When there is an urgent requirement, OKIOK can often mobilize much faster, in some cases with as little as one day’s notice.
How much does a penetration test cost?
The answer depends primarily on the scope of the test: the size of the attack surface, the types of testing required and the depth of testing expected.
A short discussion with one of our experts is enough to establish the appropriate breadth and depth of the engagement and provide a quote. In practice, penetration tests can range from a few thousand dollars for a focused assessment to tens of thousands of dollars for broader or more complex engagements.
Incident response and digital forensics
Can OKIOK help during an active cybersecurity incident?
Yes. Our incident response specialists help assess and contain the incident, eradicate the threat, restore operations and determine what happened. Digital forensic expertise can be brought in when evidence must be collected, preserved or analyzed.
What is the difference between incident response and digital forensics?
Incident response focuses on containing the threat, limiting damage and getting the organization back to business. Digital forensics focuses on identifying, preserving and analyzing electronic evidence to establish what happened and, when necessary, produce evidence that can withstand legal or regulatory scrutiny.
Governance and compliance
Can OKIOK help us prepare for a cybersecurity certification or audit?
Yes. We help you understand the requirements, assess your current posture, identify and close gaps, implement the required controls and prepare the evidence auditors expect. Our compliance expertise includes ISO/IEC 27001, SOC 2, PCI DSS, TGV, CPCSC and other regulatory and industry frameworks.
Can we perform an identity access review without implementing an IGA platform?
Yes. With Identity Compliance as a Service (ICaaS), OKIOK runs the access review for you using RAC/M Identity. There is nothing to deploy: you receive the findings, remediation information, completed review and evidence required for audit or compliance purposes.
Consulting and custom solutions
Can OKIOK provide a CISO or cybersecurity expertise without us hiring full-time staff?
Yes. OKIOK can provide strategic advice, act as your virtual CISO, deliver a defined project or place experienced cybersecurity specialists within your team. The engagement model depends on the level of responsibility, expertise and capacity you need.
What if no commercial cybersecurity product meets our requirements?
OKIOK can design and develop a custom solution when off-the-shelf products cannot meet your functional, security, integration, performance or cost requirements. This can range from a specialized security component to a complete business-critical system.
Still have a question?
Tell us about the problem you are trying to solve and the requirements you have to meet.
