Skip to content
FictiveBox
Cybersecurity

Security engineered into the product, not bolted on at audit time.

Threat modeling, zero-trust IAM, compliance automation and incident response practices for organizations operating under SOC 2, ISO 27001, HIPAA, GDPR and TS 50701. Evidence pipelines instead of annual fire-drills.

Capabilities

What we deliver

Threat modeling

STRIDE, PASTA and attack-tree workshops integrated with engineering sprints.

Penetration testing

Application, infrastructure, mobile and IoT pentesting with retest and remediation guidance.

Zero-trust IAM

Workload identity, short-lived credentials and continuous verification across human and machine actors.

Compliance automation

Evidence collection pipelines wired to Drata, Vanta or in-house GRC platforms.

Rail cybersecurity

TS 50701 and EN 50126 alignment for safety-relevant railway software.

Incident response

Runbooks, tabletop exercises and 24/7 retainer support with measurable MTTR.

Outcomes

Why teams choose FictiveBox

SOC 2 Type II with zero exceptions on first attempt
TS 50701 conformity package signed off by independent assessor
MTTR cut to under 45 minutes for critical incidents
Continuous compliance with no annual audit fire-drills
Stack

Tools & technologies

VaultOktaSnykWizDatadogDrataBurp SuiteOPASBOM/CycloneDXSLSA
FAQ

Common questions

What does FictiveBox's cybersecurity and compliance service include?
Threat modelling, penetration testing, zero-trust identity and access management, compliance automation with evidence pipelines, rail cybersecurity aligned to TS 50701, and incident response practice.
Which standards and frameworks does the work align to?
SOC 2, ISO 27001, HIPAA, GDPR and TS 50701. These are the frameworks engineering pipelines are built against; the goal is continuous evidence rather than an annual audit scramble.
What does compliance automation mean in practice?
Control evidence is produced by the pipeline as a by-product of building and deploying software, rather than assembled by hand before an audit. That means the current state of controls is observable at any time instead of only at audit season.
What is TS 50701 and who needs it?
TS 50701 is the cybersecurity specification applied to railway applications, including rolling stock and trackside software. It is relevant to operators, OEMs and suppliers delivering software into rail environments, and it is a specific focus of our railway practice.
Which security tools are used?
Vault, Okta, Snyk, Wiz, Datadog, Drata, Burp Suite, OPA, SBOM generation with CycloneDX, and SLSA provenance.

Ready to engineer your next platform?

Book a 30-minute consultation with a senior solutions architect. No slide deck. Just answers.

Schedule a call
Talk to an Expert