Cybersecurity Assessments

Make your organization’s real risk visible

From a free initial assessment to advanced regulatory compliance evaluations. Every good cybersecurity strategy starts by knowing, with evidence, where you stand.

Assessments are Araucaria’s consultative entry point into cybersecurity. We don’t sell fear or generic vulnerability lists — we deliver real, prioritized, actionable visibility.

Level portfolio

N0FREE

Initial Posture and Exposure Assessment

An honest first look at your public exposure: a brief posture survey plus a non-invasive review of open sources (OSINT) about your domain. The ideal entry point if you’ve never done a formal evaluation.

Includes: Simplified survey · OSINT audit of your main domain (with Heimdall Cyberposture CLI) · 5 to 10 immediate prioritized recommendations.

N1

Basic Posture Assessment

For medium-sized SMEs without their own security team who want to go beyond the initial assessment. An advanced 84-question survey based on NIST CSF 2.0, correlation with actively exploited vulnerabilities, up to 15 prioritized recommendations, and a results presentation meeting.

Who it’s for: Companies with no prior formal cybersecurity evaluation.

N2Core product

Advanced Posture Assessment

For companies with significant digital surface: SaaS, APIs, mobile apps, or multiple domains. Adds social media reconnaissance, basic dark web monitoring, threat intelligence, and full threat modeling (STRIDE + DREAD).

Who it’s for: Mid-size companies with exposed digital assets, without a dedicated security team.

N3

Ley 21.663 Compliance Assessment

For Vital Importance Operators (OIV) or providers with contractual obligations under the Cybersecurity Framework Law. Everything in N2, plus a full gap analysis of the Regulatory Compliance function and audit-ready evidence for Chile’s National Cybersecurity Agency.

Who it’s for: Designated OIVs and providers with regulatory obligations under Ley 21.663.

AppSec

Offensive Security and AppSec

The next step when your organization has SaaS, mobile apps, or APIs that need to go beyond OSINT: web application pentesting, white-box audits (OWASP ASVS), API pentesting, mobile audits, and basic Red Team — coordinated by Araucaria alongside our network of specialized technical partners.

Who it’s for: Organizations with SaaS, mobile apps, or APIs that require offensive testing.

After the assessment

Continuity Advisory

An assessment is a snapshot in time. If you’ve already completed your evaluation and want to keep the momentum without jumping straight to a full managed service, we offer a monthly continuity advisory: periodic posture follow-up, support implementing the prioritized recommendations.

Basic

Available after a level 1 assessment. Periodic follow-up on the most urgent recommendations.

Advanced

Available after a level 2 assessment. Frequent support aligned to your full digital surface.

Premium

Available after a level 3 or AppSec assessment. Focus on continuous regulatory evidence.

Cross-cutting add-on

Dark Web Monitoring

What it is

Continuous dark web surveillance — underground forums, illicit marketplaces, and encrypted channels — detecting information about your organization before it’s used against you.

What we monitor

  • Leaked corporate credentials
  • Data dumps with domain emails
  • Mentions in threat actor forums
  • Leaked internal documents or intellectual property

What value it delivers

  • Early warning before the attack happens
  • Reduces credential exposure time
  • Prevents credential stuffing and identity fraud
  • Direct input for prioritizing remediation

Does your need grow beyond periodic follow-up? The next step is our full Managed Cyberdefense →

Free assessment

Learn your real cybersecurity posture, for free

We deliver a free report based on your answers to a short survey and a non-invasive review of public sources about your domain — no installation, no commitment.

What is an OSINT audit?
It’s a review of all the information about your company that’s already public on the internet — your website, your emails, your security certificates, your subdomains — exactly as someone with bad intentions would see it before attempting anything. We don’t touch your systems or run intrusion tests: we only look at what anyone could find today, and show you how exposed your organization is. We use our own audit tool, Heimdall Cyberposture CLI, to automate this part of the process.

You can choose one option, or both — whatever works best for you.

Already did your assessment and want to move from assessment to 24/7 continuous operation?

Explore Managed Defense