// penetration testing · security audits · compliance readiness
Know where you’re exposed, and what to fix first.
Secure Steps provides penetration testing, security audits and compliance readiness for websites, apps and networks. We find the weaknesses an attacker would use, explain the business risk in plain language, and help you fix them, for organisations in Tunisia and beyond.
- Plain-language reports
- Risk-ranked priorities
- Fixes verified
Services
Security testing, audits and compliance, in plain language.
Every engagement gives you a clear view of risk, a plain explanation of impact, and a remediation path your team can act on.
Security testing
Penetration testing of your websites, apps and networks: we find the weaknesses an attacker would use, before they do.
security testing →Audits and reviews
A structured review of how your systems, architecture and code are built and configured, to catch what a single test can miss.
audits and reviews →Compliance readiness
Know where you stand against standards like ISO 27001 and PCI DSS, and what to fix to be ready for an audit.
compliance readiness →How it works
From scope to verified fixes.
A structured engagement: you know what is covered, how findings are rated and when fixes are confirmed.
Scope
Agree the systems, objectives and timing before any work starts.
Assess
Hands-on testing and review within the agreed scope, confirming real impact and separating noise from the issues that matter.
Report
Findings ranked by risk, with a plain-language summary for leadership and clear fix steps for your team.
Verify
Once fixes are deployed, we retest to confirm each issue is closed.
what you receive
A report leadership can act on.
Every finding is confirmed, ranked by business risk and explained in plain language, with clear fix instructions for your technical team or provider.
- A plain-language summary of your risk for leadership
- Issues ranked by business risk, so you know what to fix first
- Step-by-step fix instructions for your team or IT provider
- A retest to confirm each fix works
Customers could see each other’s invoices
- affected
- Customer billing portal
- impact
- Any signed-in customer could read other customers’ invoices, exposing their financial details.
- risk
- Loss of customer trust and possible regulatory consequences.
- fix
- Check, on every request, that the invoice belongs to the person asking for it.
- status
- Fixed · retest passed
Research
Expertise you can check before you call.
We publish detailed technical write-ups of security challenges we have solved, each ending with what defenders should do. Share them with your technical team, or read more about Secure Steps.
-
Clean Sweep — ECOVACS CGI Command Injection Timing Oracle | NNS CTF
Detailed NNS CTF IoT walkthrough covering firmware extraction, SetFct command injection, timing-oracle design, verification, and defensive lessons.
-
Light-Weight Encryption — Lattice Attack | NNS CTF
Detailed NNS CTF cryptography walkthrough explaining the weak LWE construction, modular lattice, error recovery, CVP step, and equation-level verification.
-
Min beste venn — PCAP Bit Encoding | NNS CTF
Detailed NNS CTF forensics walkthrough explaining how HTTP request multiplicity encoded bytes and how to decode the PCAP reproducibly.