Who we work with
Built for the people who carry the risk.
A cyberattack is a business problem before it is a technical one: lost revenue, damaged customer trust, regulatory attention and time your team cannot spare. Secure Steps tests your website, apps and networks the way a real attacker would, reviews how they are built and configured, and shows where you stand against standards such as ISO 27001 and PCI DSS. Then we tell you in plain language what it means for your business and what to do first.
What you get
Clear answers, not technical noise.
Every engagement is designed to give leadership three things.
Know where you stand.
Which weaknesses matter, how likely they are to be used against you, and what they could mean for customers, revenue and operations.
Know what to fix first.
Every issue is ranked by business risk, so budget and engineering time go where they count most.
Know it is fixed.
Once your team has made the changes, we retest and confirm each issue is closed, so the risk is gone, not just reported.
How we work with you
Simple for you, thorough behind the scenes.
You stay in control of scope and timing. We handle the testing and review, and explain the results.
First conversation
Tell us about your business, what worries you and what is coming up. We reply with a proposed scope before any work starts.
Testing and review
Carried out within the agreed scope and timing, coordinated with your team.
Plain-language report
A summary of the risks for leadership, plus step-by-step fix instructions for whoever maintains your systems.
Retest
Once fixes are in place, we check again and confirm each issue is closed.
Behind Secure Steps
Expertise you can check before you call.
Most firms ask you to take their skills on trust. We publish ours: detailed write-ups of security challenges we have solved, including NNS CTF 2026 and challenges on the CyberTalents platform, covering connected devices, encryption, web applications and more.
You do not need to read them. They are there so your technical team, or anyone advising you, can judge the depth of skill behind every engagement.
- Public research on our Insights page
- Practical guides to web, mobile and infrastructure testing
- Every report written for both leadership and technical teams
Secure Steps
- services
- Penetration testing, security audits and compliance readiness, with fix guidance and retesting
- works with
- Organisations in Tunisia and beyond
- research
- Write-ups by Zied Belghith on our Insights page
- publishing since
- 2022
- contact
- contact@securesteps.tn
Questions leaders ask
Before you get in touch
Straight answers to the questions business owners ask most.
Do I need a technical background to work with you?
No. We explain risks and recommendations in plain language. The technical detail goes into the report, written for whoever maintains your systems.
Will testing disrupt our business?
Scope, timing and rules are agreed with you before anything starts, so you decide what is tested and when.
What will it cost?
It depends on what needs testing or reviewing. Describe the systems and the outcome you need, and we come back with a proposed scope before any work starts.
What do we receive at the end?
A report with every finding ranked by risk, a plain-language explanation of what it means for the business, and step-by-step fix guidance. Once fixes are deployed, a retest confirms each issue is closed.
Talk to us about your business, not just your systems.
Tell us what is coming up, whether a launch, a customer audit or an investor review, and we will suggest where testing, an audit or a readiness review makes the biggest difference.