Training Icon

Information Security

Regardless of your company's size, information security must be at the forefront of your mind. Information security revolves around all aspects of the business and can, or should, touch every department in the company. With constant changes in how business is run and daily shifts in the threat landscape, a solid infosec program is not only needed but required. With decades of experience in information security, Arrakis can help you stabilize your environment and increase the chances of success.


Interested in Cybersecurity Awareness Training? Start your free Risk Assessment.



Visit our online store to purchase training and services


Need to validate the security of your suppliers?  Our Prosikon platform can help reduce your risk.


These solutions can be in several forms:

Vulnerability Assessment - All companies should have a complete understanding of their vulnerabilities and the ability to track and demonstrate improvement. All frameworks require vulnerability assessments to be performed by an internal group, as well as at least an annual 3rd-party vulnerability assessment. Using industry-recognized tools, our professionals will capture and categorize your vulnerabilities for in-scope devices and IP addresses. After our discovery phase, we will manually test each vulnerability to ensure there are no false positives and produce an exceptional report for auditors or other compliance and regulatory bodies. Quite often, our reports and presentations are used in their native form for Board of Directors meetings.

Penetration Testing - Taking our vulnerability assessment one step further, if you wish to make active attempts to penetrate your network, Arrakis personnel can demonstrate how a vulnerability can be exploited to gain access to the network and potentially sensitive information. Penetration testing can be performed externally (from a hacker's perspective) or internally (from an insider threat perspective), and it can demonstrate how easily data can be exfiltrated to an external destination.  Read more about Penetration Testing here and check out our page on Penetration Testing as a Service here.

Wireless Security Testing - Wireless is the current trend, increasing user mobility and device connectivity flexibility. Essentially, technology has evolved to such a point where everything connects to the Internet. Also known as IoT (Internet of Things), companies are increasingly relying on devices to perform specific functions while remaining secure. Arrakis wireless security testing service will evaluate your current wireless infrastructure and security to identify areas for improvement. Additionally, with wireless radiating in all directions, it is always prudent for a company to understand its wireless perimeter to ensure that penetration attempts are not made from the parking lot or the other side of the street.

Social Engineering - The first line of defense in a company is always the individual user. Unfortunately, the weakest link in a company is also the individual user. Using industry-accepted tools/tactics/procedures, Arrakis can deliver a comprehensive social engineering campaign to uncover human weaknesses in your company's security. While in some cases, successful social engineering can lead to personnel changes, in most cases, a successful social engineering campaign provides insight into the effectiveness of computer security awareness training. It can help target specific areas that need additional training. Social engineering can take the form of phishing, phone calls, or social interaction and, aside from phishing, is generally a custom engagement.

Physical Security Testing - While most companies intend to be physically secure, unfortunately, most are not. Arrakis professionals can identify physical security weaknesses and provide an actionable plan to remediate any findings. Arrakis has a long history of uncovering and exploiting physical security weaknesses across a variety of entities, including Fortune 10/50/100 companies, financial institutions, energy (nuclear) facilities, medical facilities, and various government locations. Additionally, most Arrakis personnel have extensive backgrounds in executive protection and can provide physical security consultation for high-risk individuals. To offset a slight increase in testing, Arrakis will also include low-level aerial drone surveillance to reveal top-down weaknesses.

Policy Creation and Policy Review - Quite often, companies have some form of policies in place. Still, most of the time, those policies do not meet auditors' requirements or the company's frameworks. While the company intends to be compliant, the deficient policies do not help and only draw closer the attention of auditors. Arrakis has years of experience writing policy and can help bring you up to speed on the frameworks and improve your success rate when it is time to be audited—one-pager on Policy Creation here.

CISO as a service - Some companies simply do not have the budget, experience, or training to have a CISO or an information security department. While all frameworks require a security department and a CISO, it simply isn't in the budget, or there isn't enough technical work to justify hiring the appropriate personnel. Arrakis can help you act as a trusted advisor to your company's CIO or COO and, in effect, serve as a CISO. Technically, according to the frameworks, someone in the company still must hold the title of CISO; however, none of the frameworks indicate that the actual "work" cannot be outsourced to a reputable 3rd party. Don't be caught short in high-risk compliance areas such as CMMC, GDPR, CCPA, FFIEC, FISMA, PCI, and more.

Network Security Architecture and Design - Even the most well-intentioned companies can make architectural mistakes that increase risk. Does your company have a flat network? Do you have internal controls that prevent users from accessing sensitive HR files? Is the file server that holds all of your company's financial data available to be accessed anywhere within the network? Are your executives isolated and protected from other areas within the network? Who can print to the printers located in the executive area? If you answered yes to any of those basic questions or are unsure about any of them, you are likely not following a comprehensive "defense in depth" network architecture. You are allowing horizontal movement within your network and unfiltered data exfiltration.

Investigations and Forensics - Arrakis personnel are more than capable of handling internal investigations or partnering with law enforcement to help resolve sensitive business investigations. Our trained and certified team of investigative personnel has years of experience and has worked on the most sensitive of cases—one pager on Employee Surveillance here.

Information Security Assessment - While most other companies offer targeted security assessments, such as vulnerability assessments or wireless security testing services, Arrakis can provide an overall, comprehensive assessment that includes all other services. Essentially, all aspects of security are taken into account including security awareness training, architecture, rule sets, vulnerability assessments, social engineering, budgets, processes and procedures, organizations, certification and training, etc... Arrakis strives to approach the overall security assessment from the viewpoint of the regulators and will provide an extensive and detailed report that provides actionable items to remediate findings and reduce risk. Don't be caught short in high-risk compliance areas such as CMMC, GDPR, CCPA, FFIEC, FISMA, PCI, and more. One-pager on Cloud Assessments here; cloud assessments are only part of the service, however, virtually all companies either have a completely cloud-based environment or a hybrid environment.


Contact us by filling out this form - Contact Us


Check out our platforms that help reduce effort and risk

Arrakis has built over several months numerous platforms that can help reduce risk.  Read more here and those platforms are listed below.

- Compliance Chatbot - a free chatbot relating to compliance, cybersecurity, and privacy.
- Prosikon - A feature rich vendor due diligence platform to help increase visibility and provide more information for safer decisions.  Read more here.
- PolicyForge - Build out your policies based on the regulatory environment you care about.  Policy and Procedure Templates are included as well as control mapping.  Read more here.
- Fortuna Risk Compass - Feature rich risk assessment platform that helps you visualize risk and cost better.  Numerous graphical displays and ability to export risks to Prothesis.  Read more here.
- Prothesis PoAM Builder - Build your PoAMs to prove you are mitigating risk and demonstrating maturity.  Expands on Fortuna risks and demonstrates the "why" on the need for PoAMs.  Read more here.
- Mutina SecurePath - Construct your SSPs to meet CMMC, or other frameworks, to provide assurance to external parties.  SSPs are required for CMMC compliance.  Read more here.
- CyberPrep Test Engine - A subscription based practice test platform covering 50+ certifications.  Designed to be more difficult than the actual test to increase certification chances.

Regardless of the platforms, Arrakis suggests contracting professional consultation when seeking certification or compliance.

We are masters at these frameworks and many more.

Our membership in professional organizations

Contact Us