NOT JUST REPORTS. CONCRETE SOLUTIONS.
VAPT THAT TESTS YOUR DEFENSES FOR REAL.

Do You Really Know How Secure Your Company Is?

Laws, regulations, certifications, and insurance
do they truly protect your business, or just drain resources with nothing measurable to show?
VAPT (Vulnerability Assessment & Penetration Testing)
is the most effective way to find out!

We are trusted ethical hackers, ready to collaborate with top management and decision-makers. We identify security gaps in your IT infrastructure, assess your employees’ awareness, and test your company’s defenses. All in a safe and controlled manner, with operational risk reduced to the minimum, thanks to our professionalism and proven offensive capabilities, always guided by ethical values and maximum responsibility towards our clients.

Frequently Asked Questions About VAPT

When is the right time for a VAPT?

Annually, to monitor IT security. When implementing major technological changes or infrastructure updates. To comply with regulatory and compliance deadlines, addressing any gaps not covered in previous audits. After a security incident or suspected cyber attack.

Why is our VAPT different?

We don't need any inside information. A signed contract, an NDA, and a defined scope are enough. Then, we act like real attackers, conducting reconnaissance and real attack campaigns to identify vulnerabilities exactly as a malicious actor would.

Why is it essential for national or multinational companies listed on the stock market or supported by investment funds?

Reducing reputational risk and protecting stock value. A cyber attack can directly impact investor confidence, cause stock value drops, and damage corporate reputation. VAPT helps prevent targeted attacks, ensuring operational continuity and brand protection before vulnerabilities are exploited.

Our Expertise

Advanced technical skills in cybersecurity

Who we work with

Trusted where a breach is not an option

Our clients build and run critical systems: industrial and manufacturing environments, digital identity and authentication platforms, cloud and multi-tenant SaaS, healthcare, and the e-mail infrastructure their business depends on.

How we work

We follow the path a real attacker takes

Every engagement runs end to end, from first contact to verified fix.

  1. Reconnaissance & attack surface analysis
  2. Vulnerability assessment & manual exploitation
  3. API, authentication-flow & multi-tenant isolation testing
  4. Mail infrastructure analysis, red teaming & social engineering
  5. Remediation validation

What we’ve tested

The platforms enterprises actually run on

We don’t test in a lab. Our work spans the systems you depend on every day:

Microsoft 365 · Exchange · Postfix · Proofpoint · Keycloak · SPF/DKIM/DMARC · DNS & mail routing · REST APIs · mobile & backend APIs · web applications · identity & authentication platforms · multi-tenant architectures · SaaS environments · cloud infrastructure

Remediation Effectiveness

We do not stop at vulnerability identification.

Our assessments include practical remediation guidance, exploit validation, configuration hardening, attack chain analysis and post-remediation verification focused on reducing real-world attack surface and improving operational resilience.

Research & Innovation

From DeepSec Vienna 2025 to an RDAP extension registered with IANA

Registrar reliability: from a conference talk to an IANA-registered RDAP extension
Alessandro Bertoldi (Bertoldi Cybersecurity)
DeepSec talk, ideas and revisions: Enrico Bertoldi, Simon Pietro Romano, Emanuele Galdi, Giovanni Minotti
IETF Internet-Draft: Alessandro Bertoldi and Simon Pietro Romano (University of Naples Federico II)

At DeepSec Vienna 2025 we showed how registrars can be the weakest link in a company's security chain and proposed a Reliability Scoring for registrars. That proposal became an Internet-Draft discussed in the IETF REGEXT working group, which defines how an assessment result travels inside an RDAP response (transport, not judgement). On 6 October 2026 IANA registered the extension identifier reliabilityAssessment with Bertoldi Cybersecurity as the contact. The draft is a work in progress, not an IETF standard, and is on the agenda of IETF 127 in San Francisco.

GCVE Numbering Authority

GNA 128

bcsec is a GCVE Numbering Authority. We assign and publish vulnerability identifiers for the issues our research uncovers, in GCVE-BCP-05 format and from our own infrastructure. A finding is therefore documented and citable regardless of any single authority's publication queue.