Skip to content

ROS\\TECH — IT-security specialists from Innsbruck

Identity Isolation Assurance

Security by design.

Architecture first.
Tools where they matter.

40+ yrs
Combined expertise
300+
Automated checks
1
Point of contact
Get the architecture right first. Then protect it.

We work alongside your IT team — not instead of it. For the few specialised platforms that matter, we go beyond advice: we implement and run them ourselves. A single point of contact from selection to support — no handoffs, no gaps.

Pillar 01 — Identity Protection

Identity is the perimeter.
How it's built decides everything downstream.

Admin credentials are the highest-value target in any environment. We vault them, broker every privileged session, and enforce least privilege on the endpoint without breaking legacy apps — then isolate Tier-0 so a compromised workstation can never reach your crown jewels.

Privileged Access ManagementVaulting, rotation, session proxying, full audit trails. EPM least-privilege on workstations.
Secure remote accessMFA-enforced, per-system, session-recorded — the opposite of broad VPN. Built for vendor access.
Microsoft admin tiering & PAWTier-0 isolation, privileged workstations, legacy-auth cleanup.
Pillar 02 — Network Isolation

Perimeter firewalls are necessary.
They are nowhere near enough.

Once an attacker is inside, traditional segmentation does little. Host-based firewalling isolates every machine by default; a label-based policy layer compiles intent into rules that auto-adjust as the environment changes — and a visualisation layer maps thousands of flows that never touch a network firewall.

Host-based zero-trust segmentationEvery host isolated; communication only on explicitly permitted paths.
Label-based policyRules follow the workload, not the subnet — maintainable at scale.
Certified segmentation specialistsDeployed on-premise or SaaS. Traffic you couldn't see before, now mapped.
Pillar 03 — Secure Configuration Monitoring

You can't defend what you can't prove is right.

Assurance is continuous: we run curated test and hardening catalogues against your environment on an ongoing basis, rank findings by what an attacker can actually reach — not raw CVSS — and prove fixes held. The engine behind it is Resonate, which we build ourselves.

Continuous assessmentAD, GPO, certificates and cloud — new exposure caught as it appears, not once a year.
Prioritised by exploitabilityThe five findings that chain to Domain Admin, not the two thousand that don't.
Integrated vulnerability scanningOptional CVE coverage, pulled into one findings list.
Meet Resonate ↓

Security configuration,
continuously verified.

The engine behind the assessments we run for you — deep, continuous, read-only

Resonate goes deep into the configuration that decides whether an attacker who gets in can go anywhere — ACLs, GPO coverage, admin tiering, and AD & Entra hardening — across the full range from on-prem to cloud.

resonate — findings · MITRE ATT&CK coverage
Resonate findings view — severity facets, MITRE ATT&CK coverage and prioritised findings Resonate testing view — assessment tree, test runs and linked finding Resonate vulnerabilities view — scanner results grouped by host
01

The lifecycle loop

Assess → prioritise → remediate → re-validate. Automated and manual findings in one place, mapped to MITRE ATT&CK and CIS v8 — so your environment actually improves, not just accumulates reports.

MITRECIS v8
02

Deep configuration analysis

ACLs, GPO coverage, and admin tiering modelled properly — deny precedence, inheritance scope, legitimate-default allowlists. Anyone can dump settings; the hard part is knowing which ones actually matter.

ACLsGPO coverageTier-0
03

AD attack-technique detection

Read-only checks for what attackers actually do — not raw CVEs. Kerberoasting, AS-REP roasting, DCSync, unconstrained & RBCD delegation, SID-history abuse.

KerberoastDCSyncRBCD
04

AD CS / PKI — ESC1–ESC15

Certificate-based domain-takeover coverage, evaluated per template and per CA, with the abusable principals named. The surface commodity scanners never touch.

ESC1ESC8per-template
05

On-prem + cloud hardening

AD and Entra/Azure hardening in a single findings list — tenant policy, privileged roles, workload-identity exposure — via a customer-owned, read-only, revocable Graph app.

Entra IDARM RBAC
06

Attack-path coverage, end to end

We trace escalation across the full range — AD, Entra, PKI, IT infrastructure and client hardening — so findings are ranked by the impact an attacker can actually reach, not just raw severity.

AD → Entrareachable impact

How Resonate runs: a customer-controlled, agent-based collector · read-only access to AD, GPO & Entra · tiering-aware collection (optional) · the portal is never exposed to the public internet.

The team

You talk to the engineer who does the work.

Robert Rostek
Robert Rostek
CEO
Lukas Dötlinger
Lukas Dötlinger
Security Architect
Fabian Ruetz
Fabian Ruetz
Security Architect

Direct technician communication

No account manager relay. The person who understands your environment is the person you speak to.

Hands-on, not hands-off

We don't just point at findings. We fix them with your team and prove they stay fixed.

40+ years, run from the ground up

Helpdesk to sysadmin to security architect to team lead to MSP — we've run the systems we now secure.

References

We serve many industries and sizes.
We keep that private.

Our clients come to us for the work, not to become a logo on our wall. Your security posture is not our marketing. We're glad to arrange a direct reference conversation under NDA.

Critical infrastructureFinancial services ManufacturingPublic sector HealthcareDACH production SME & enterprise
Media presence

Out in the field.

Contact

Let's look at
your environment.

Want it assessed, hardened, and kept that way? Reach out and we'll walk you through exactly how we work — no sales relay.

robert@rostech.at
Hallerstrasse 133 · 6020 Innsbruck

Opens your email app — nothing is sent to a server.