Offensive security in accounting firms, accounting BPO and accounting SaaS platforms.
Why now
Accounting concentrates financial data of hundreds of client companies in a single firm. Ransomware here is not one company's problem — it's all clients at once. Tax fraud and payroll diversion are direct impacts.
Applicable regulation
/attack-surface
Every engagement is designed for your environment. The points below are part of our standard playbook for this sector — final scope is adapted to your stack and contract.
Sage, Domínio, Contmatic, integration with tax/payroll.
eSocial, salary line fraud, salary diversion.
EFD, NF-e, NFS-e, credit fraud.
Unauthorized access to documents of other client companies.
Immutability against ransomware, realistic RTO.
/methodology
Automated scanners find what's documented. Real attackers find what isn't. 90% of the work is manual — performed by specialists holding OSCP, CISSP, CRTO and GPEN.
Target mapping, OSINT, footprint, sector-specific threat modeling.
Deep enumeration, complementary scanning, manual exposure identification.
Manual validation with controlled PoC, finding chaining, escalation.
Executive + technical, step-by-step replication, mapped to applicable regulation.
/why-trust
Engagements in accounting BPO and medium/large firms.
Technical assessment recognized in highly regulated, mission-critical environments — the pentest that finds what nobody had found before.
Douglas Lopes
Founder · CEO · intrus.io
/faq
Yes. Audit of eSocial integration, EFD-Reinf, client segregation and event integrity.
Pentest assesses the protection gap. We recommend immutable backups, admin segregation and mandatory MFA.
/contact
Schedule a confidential meeting. Within 48h we'll send a proposal with scope, timeline and pricing.