BrickellTechnologies

About

A Miami cybersecurity firm that does the testing itself.

Brickell Technologies specializes in offensive security: finding out what an attacker could actually do to you, proving it, and helping you close it. No subcontracted testers, no report written by somebody who never saw your environment.

What we are for

Most organizations do not have an accurate picture of their own exposure. They have an asset inventory that is out of date, a scanner report nobody has read past page four, and a general sense that things are probably fine. Then a customer sends a security questionnaire, or an auditor sets a date, or something happens.

Our job is to replace that fog with something specific: here is the path in, here is what it reaches, here is the change that closes it. Whether the answer is comforting is not up to us.

How we work

Small on purpose. The person who takes your scoping call is the person testing your network, which means nothing is lost in a handoff and you can argue about a severity rating with the human who assigned it. That does cap how much work we can take at once, so we book out a few weeks ahead and we would rather tell you that than squeeze you in badly.

Testing is manual. Tools run in the background for coverage, and their output gets verified by hand before it reaches you; if we cannot reproduce a finding, it does not go in the report. What is left is written for two audiences at once, an executive summary somebody non-technical can act on and technical findings your engineers can follow without asking us what we meant.

We also tell you when something is boring. Padding a report with a self-signed certificate on an internal jump box rated "high" burns engineering time that should have gone to the finding on page two, and once you stop trusting the severities you stop reading the reports at all.

What we do not do

We are not a managed security service provider, we do not run a 24/7 SOC, and we do not do incident response. If something is happening right now, call an IR firm; we will happily recommend one and we are useful afterwards, once the question becomes how it happened and what else is open.

We also do not audit our own work. Readiness and assessment have to stay separate people for either to mean anything, which is why our compliance work ends at handoff to an assessor.

Where we work

We are based in Miami and cover Miami, Miami-Dade County, Fort Lauderdale, West Palm Beach for anything needing someone physically present, which means internal network testing, wireless work, and social engineering that involves a building. Web, API, cloud, mobile and external network testing is remote by nature, so those engagements run anywhere in the United States. Being local matters less than it used to, but it still matters when you want somebody in the room for the readout.

Credentials

What the team holds

Procurement asks, so here they are. GXPN and GMOB are the two worth paying attention to; both are practical exams where you have to actually do the thing.

Partner status with CrowdStrike covers the Falcon deployment and tuning work.

Want to know what we would find?

Tell us what you run. We will come back with a scope, a fixed price, and an honest answer about whether you need us yet.