ASSESSMENT & PENETRATION TESTING
ASSESSMENT & PENETRATION TESTING
Know exactly which threats matter most to your system, why, and what to fix first, with evidence your authorizing official will accept.
Avalon tells you which threats can realistically reach your systems and data, how likely and damaging each one is, and which fixes matter most, delivered in a form your AO, IG, and leadership will accept.
THE PROBLEM & THE APPROACH
The Challenge
Our Approach
Risk assessments are often stale, copy-pasted, or written to satisfy a checklist rather than describe the threats actually targeting the mission.
Avalon builds engineering-level threat models and uses them as the evidence base for every risk score, so every rating traces to a specific, named attack path, not an assessor's gut feel.
Without threat-informed prioritization, agencies remediate by scanner severity score, so the finding that could actually take the mission down often sits behind fifty findings that cannot.
Likelihood and impact analysis conformant to NIST SP 800-30 produces a prioritized risk register and a remediation roadmap ranked by real mission impact.
Every federal system must have a current risk assessment to obtain and keep its Authorization to Operate, stale or generic assessments are among the most common FISMA and IG audit findings.
Avalon delivers an 800-30-conformant risk assessment and threat model package formatted to drop directly into your authorization package, in six to nine weeks for a typical system.
Systems designed without threat modeling accumulate architectural flaws that surface late, during an assessment, a pen test, or an incident, when they're far more expensive to fix.
Threat modeling embeds early, using STRIDE, PASTA, LINDDUN, or attack trees fit to the system, so design flaws are caught before they're built.
CORE CAPABILITIES
Engineering-level walkthrough of how a system is built and where an attacker or a failure could get in.
NIST SP 800-30-conformant scoring of threat scenarios against your real environment and mission impact.
Deliverables engineered to drop directly into eMASS, CSAM, or Xacta, and into your authorization package.
OUR PROCESS
Confirm the system boundary, finalize the data-call list, submit access requests, and agree the risk scale and report template. (Week 1)
Document review, 6–12 stakeholder interviews, and an architecture walkthrough. (Weeks 2–3)
2–4 facilitated working sessions with system engineers, decomposition, threat enumeration, and ATT&CK mapping. (Weeks 3–5)
Likelihood/impact scoring, correlation with vulnerability evidence, risk determination, and control mapping. (Weeks 5–7)
Draft report, agency factual-accuracy review, final report, and an executive out-brief. (Weeks 7–9)
Validate remediation of top risks, refresh the register, and hand off to remediation or A&A follow-on work.
WHY AVALON
5
Federal Frameworks Addressed
The Only Firm That Integrates Both Halves
Most vendors sell either a compliance-oriented risk assessment or a developer-oriented threat modeling exercise, never both. Avalon uses the threat models as the evidence base for the risk scores, so every rating traces to a named attack path.
The people named in the proposal do the analysis, not bench juniors under a senior name that appears at kickoff and outbrief only.
6–9 weeks to a final report, against a quarter or more for a large-firm equivalent burdened by internal process.
Typically 30 to 50 percent under large-integrator pricing for equivalent scope, with fixed-price certainty.
Avalon assesses nothing it built and recommends nothing it sells, a large integrator that operates or delivers the program has an organizational conflict of interest assessing its own work.
FREQUENTLY ASKED
Straight answers about scope, access, and what this service will, and won't, get you.
Talk to Our Team →5
Federal Frameworks Addressed
No exploitation occurs, this is design-level analysis of what could go wrong and how bad it would be. Many organizations need both, in this order: threat model first, so testing is targeted at what actually matters.
It produces the risk evidence your authorizing official needs, the AO makes the actual authorization decision. We guarantee the quality of the analysis, never the authorization outcome.
Scan data is evidence, not analysis, and a register where everything is rated 'high' is the symptom this service exists to fix. We consume your existing data as an input and convert it into threat-informed prioritization your AO can act on.
True, and agencies should use CISA where they can get it. But CISA's assessment capacity has contracted sharply and queues are long. Avalon delivers on your schedule and tailors the threat models to your specific system.
A single moderate-impact system runs 6–9 weeks. A portfolio of 3–5 related systems runs 3–4 months, and an enterprise or High-Value-Asset engagement runs 4–6 months with a phased, per-system deliverable structure.
No. This engagement uses read-only document access and workshop time only, no agent, appliance, or software installation in your environment, which shortens your security review materially.
Fair question, and here's what protects you anyway: named senior key personnel with individually documented track records, a fixed price that transfers delivery risk to Avalon, and a bounded 6–9 week engagement that's inherently low-risk to trial.
Talk to Avalon about scoping a risk evaluation and threat modeling engagement for your system.