Annually, to monitor IT security. When implementing major technological changes or infrastructure updates. To comply with regulatory and compliance deadlines, addressing any gaps not covered in previous audits. After a security incident or suspected cyber attack.
We don't need any inside information. A signed contract, an NDA, and a defined scope are enough. Then, we act like real attackers, conducting reconnaissance and real attack campaigns to identify vulnerabilities exactly as a malicious actor would.
Reducing reputational risk and protecting stock value. A cyber attack can directly impact investor confidence, cause stock value drops, and damage corporate reputation. VAPT helps prevent targeted attacks, ensuring operational continuity and brand protection before vulnerabilities are exploited.
Advanced technical skills in cybersecurity
Who we work with
Our clients build and run critical systems: industrial and manufacturing environments, digital identity and authentication platforms, cloud and multi-tenant SaaS, healthcare, and the e-mail infrastructure their business depends on.
How we work
Every engagement runs end to end, from first contact to verified fix.
What we’ve tested
We don’t test in a lab. Our work spans the systems you depend on every day:
Microsoft 365 · Exchange · Postfix · Proofpoint · Keycloak · SPF/DKIM/DMARC · DNS & mail routing · REST APIs · mobile & backend APIs · web applications · identity & authentication platforms · multi-tenant architectures · SaaS environments · cloud infrastructure
We do not stop at vulnerability identification.
Our assessments include practical remediation guidance, exploit validation, configuration hardening, attack chain analysis and post-remediation verification focused on reducing real-world attack surface and improving operational resilience.
From DeepSec Vienna 2025 to an RDAP extension registered with IANA
Registrar reliability: from a conference talk to an IANA-registered RDAP extension
Alessandro Bertoldi (Bertoldi Cybersecurity)
DeepSec talk, ideas and revisions: Enrico Bertoldi, Simon Pietro Romano, Emanuele Galdi, Giovanni Minotti
IETF Internet-Draft: Alessandro Bertoldi and Simon Pietro Romano (University of Naples Federico II)
At DeepSec Vienna 2025 we showed how registrars can be the weakest link in a company's security chain and proposed a Reliability Scoring for registrars. That proposal became an Internet-Draft discussed in the IETF REGEXT working group, which defines how an assessment result travels inside an RDAP response (transport, not judgement). On 6 October 2026 IANA registered the extension identifier reliabilityAssessment with Bertoldi Cybersecurity as the contact. The draft is a work in progress, not an IETF standard, and is on the agenda of IETF 127 in San Francisco.
GNA 128
bcsec is a GCVE Numbering Authority. We assign and publish vulnerability identifiers for the issues our research uncovers, in GCVE-BCP-05 format and from our own infrastructure. A finding is therefore documented and citable regardless of any single authority's publication queue.