Logisek

Logisek Stay one step ahead in the digital era with our professional Cyber security and IT Services

Logisek is a leading Cyber Security and IT services firm that was founded in Greece in 2008 and in Romania in 2019 and has since expanded to serve clients on a global scale. With nearly two decades of experience in this field, we specialize in providing comprehensive technological solutions aimed at helping businesses stay secure in the digital world. Our specialized team is committed to maintaini

ng its pioneering position in a constantly changing technological environment, offering our clients the best possible protection against cyber threats. Whether you're seeking cyber security assessments, managed IT services, or cloud solutions, we have the experience needed to support you in achieving your goals. Secure your digital future with the trusted Cyber Security and IT solutions we provide. CONTACT
Stay up to date with Logisek and follow the latest security and IT trends by following our official pages on:

⇢ LinkedIn: /logisek
⇢ Twitter - X: /logisekict
⇢ GitHub: /Logisek
⇢ Instagram: /logisek_ict

_______
[email protected]
☎+30 21 0662 6841

Η 3η και τελευταία μέρα της Beyond Expo 2026 ξεκινά!Σας περιμένουμε όλους σήμερα, 10:00 π.μ. – 7:00 μ.μ., στο HALL 3 | S...
19/06/2026

Η 3η και τελευταία μέρα της Beyond Expo 2026 ξεκινά!

Σας περιμένουμε όλους σήμερα, 10:00 π.μ. – 7:00 μ.μ., στο HALL 3 | Stand E14, για να συζητήσουμε από κοντά για το Offensive Security και τις σύγχρονες προκλήσεις στον χώρο της κυβερνοασφάλειας.

Ένα μεγάλο ευχαριστώ σε όλους όσοι μας επισκέφθηκαν τις δύο προηγούμενες ημέρες, πελάτες, συνεργάτες και new connections. Ήταν χαρά μας να ανταλλάξουμε ιδέες, ανάγκες και προοπτικές συνεργασίας.

Η   συμμετέχει στη BEYOND 2026, τη Διεθνή Έκθεση Τεχνολογίας και Καινοτομίας.Metropolitan Expo Athens17-19 Ιουνίου 20261...
16/06/2026

Η συμμετέχει στη BEYOND 2026, τη Διεθνή Έκθεση Τεχνολογίας και Καινοτομίας.

Metropolitan Expo Athens
17-19 Ιουνίου 2026
10:00 π.μ. - 7:00 μ.μ.
HALL 3 | Stand E14

Σας περιμένουμε!

10/06/2026

Η ψηφιακή ταυτότητα δεν είναι πλέον απλώς ένας κατάλογος χρηστών. Είναι πλέον επιφάνεια επίθεσης. Από IAM και PAM μέχρι cloud...

Η επίθεση ωρίμασε πρώτηIn the new issue of netweek, Thanasis Karpouzas, discusses how offensive security has evolved ove...
10/06/2026

Η επίθεση ωρίμασε πρώτη

In the new issue of netweek, Thanasis Karpouzas, discusses how offensive security has evolved over the last 25 years.

From exposed servers, SQL Injection and perimeter-based security, to cloud, SaaS, APIs, identity attacks and AI-assisted threats, the article highlights a key reality: security is no longer only about the perimeter. It is about continuously testing real attack paths, validating controls, and turning findings into meaningful action.

The piece explains why modern offensive security must go beyond assumptions and checklists. Today, organizations need practical evidence, clear reporting, continuous validation and collaboration between red teams, blue teams and business stakeholders.

We invite you to read the new issue of netweek and explore how controlled helps organizations understand exposure, improve resilience and prepare for the threats of tomorrow.

- https://issuu.com/boussiasmedia/docs/nw_500_e-magazine/56?fr=sOTg3Yjg4MTYyMjc

25 Years of  : From Y2K to AIFor 25 years, netweek has been following the evolution of cybersecurity, from the uncertain...
10/06/2026

25 Years of : From Y2K to AI

For 25 years, netweek has been following the evolution of cybersecurity, from the uncertainty of Y2K to today’s AI-driven threat landscape. The new issue looks back at a quarter century of constant change, growing risks, and the technologies that shaped the way organizations defend their digital assets.

The feature highlights how cybersecurity has transformed from a niche technical concern into a strategic priority for every business. It also explores the challenges ahead, from ransomware and cloud security to artificial intelligence and the next generation of cyber threats.

We invite you to read the new issue of netweek and discover this special tribute to 25 years of cybersecurity, sponsored by Logisek.

- https://issuu.com/boussiasmedia/docs/nw_500_e-magazine/52?fr=sOTg3Yjg4MTYyMjc

    Must Be ProvenCloud adoption has moved faster than cloud assurance. An environment is not secure because it is live,...
09/06/2026

Must Be Proven

Cloud adoption has moved faster than cloud assurance. An environment is not secure because it is live, documented, or approved. It is secure only when someone has challenged how it can fail.

A forgotten access key, an exposed storage bucket, a permissive IAM role, or an open management port can become the beginning of a serious compromise.

---

Across and *******on , the same patterns appear again and again:

- Overly permissive IAM with wildcard access.
- Public buckets, blobs, snapshots, and backups.
- Management ports, databases, and Kubernetes APIs exposed too broadly.
- Long-lived secrets in repositories, pipelines, or developer machines.
- Weak logging that confirms the breach only after the damage is done.

Cloud security cannot stop at configuration checklists. Reviews help identify what is obvious.

Cloud pe*******on testing validates what is dangerous.

---

The

- Continuously review IAM.
- Enforce least privilege.
- Remove public exposure by default.
- Rotate and monitor secrets.
- Test cloud attack paths.
- Validate logging, detection, and response.

Cloud security is about proving what your environment can withstand, not assuming it is safe because it supports the business every day. The real risk often lives in the areas we did not have time to challenge, question, or test deeply enough while focused on keeping critical operations running.

https://logisek.com/

Controls Fail Where   BeginA security control only matters if it holds when an attacker follows the path everyone believ...
03/06/2026

Controls Fail Where Begin

A security control only matters if it holds when an attacker follows the path everyone believed they would never find. That is where real maturity is proven.

Most organizations have the right security technologies somewhere in the stack: , segmentation, monitoring, , , access reviews, response playbooks.

But attackers do not move through diagrams. They move through trust relationships, stale credentials, access, over-permissioned accounts, and operational shortcuts.

One exposed third-party credential can be enough to test the whole model.

---

When "Contained" Is Only a Belief

On paper, may look strong. PAM may appear to protect privilege. Monitoring may show coverage. Response teams may have documented escalation paths.

But the real question is not whether these controls exist.

If a compromised vendor credential reaches a poorly configured PAM environment, and privileged access is broader than expected, lateral movement quickly exposes the difference between control ownership and control effectiveness.

---

Tests the Assumption Layer

Red teaming and show whether identity controls, segmentation, detection logic, and response processes work under pressure.

They also reveal the weak joins between systems, teams, vendors, and business processes.

Do not only validate that controls are deployed. Validate that they hold when chained together in the way an attacker would actually use them.

- https://logisek.com

  Is Not the Finish LineIn      , proving a weakness exists is only the beginning. The real value starts when that findi...
29/05/2026

Is Not the Finish Line

In , proving a weakness exists is only the beginning. The real value starts when that finding is translated into what it could mean for production, safety, uptime, and recovery.

Your OT risk register should not be a list of vulnerabilities. It should be a map of operational consequences.

---

Beats Severity

In IT, criticality often follows exploitability, privilege escalation, or data exposure. In OT and environments, the impact picture is different.

A "medium" issue can become a serious operational risk if it affects production visibility, remote maintenance, batch control, safety monitoring, or recovery. CVSS alone cannot explain whether a weakness could delay operations, confuse operators, or disrupt trusted workflows.

---

Need Business Context

Weak credentials, exposed interfaces, poor segmentation, and limited monitoring may look like separate findings.
Together, they can form a realistic path from initial access to operational disruption.

That is why business context matters.

A finding becomes meaningful when it is tied to the workflow, asset, or operational dependency it could impact. Could this path affect operator visibility? Could it delay maintenance? Could it interfere with recovery? Could it create confusion during a production window?

---

The Best Deliverable Is a

Strong OT helps teams decide what to fix now, what needs a maintenance window, what requires compensating controls, and what belongs in a longer-term resilience plan.

In OT security, the best question is not "What did we find?" It is: "What should we do next, and why?"

- https://logisek.com

The   Behind the Crown JewelMost     conversations start with the PLC. That makes sense, but attackers often ask a diffe...
26/05/2026

The Behind the Crown Jewel

Most conversations start with the PLC. That makes sense, but attackers often ask a different question: "Which system already has the tools, trust, and context to control it?"

The most revealing system is often not the controller. It is the workstation sitting quietly beside it, holding the logic, tools, and access everyone trusts.

---

The Trusted Attackers Want

In many environments, the engineering workstation is not just another endpoint. It is the system used to configure, troubleshoot, maintain, and program controllers.

It may contain project files, vendor software, saved connection profiles, historical backups, controller logic, USB workflows, license tools, and privileged access into sensitive OT networks. In practical terms, compromising the system that programs the can be more dangerous than attacking the controller directly.

---

Why Context Beats

If attackers compromise an engineering workstation, they may be able to open a legitimate vendor application, load an existing project, connect through saved settings, and follow normal maintenance workflows.

That gives them three things defenders should care deeply about: context, tooling, and trust.

Project files can reveal logic, tag structures, IP addresses, device names, process assumptions, safety interlocks, and network paths. Saved credentials and shared engineering accounts can reduce the need for exploitation. USB workflows and vendor support access can create quiet movement paths between IT, vendors, and OT.

---

What Safe Should Prove

A strong engineering workstation assessment does not need to disrupt or modify live controller logic.

It should safely answer questions like:

- Can non-engineering users access project files?
- Are credentials stored in vendor tools or remote clients?
- Are shared accounts still active?
- Can the workstation reach controllers, HMIs, historians, or license servers?
- Are engineering actions visible in logs and change-control workflows?

The goal is not reckless exploitation. The goal is attack-path clarity.

- Instead of only asking, "Can someone exploit the PLC?"
- Ask, "What could an attacker do if they compromised the workstation used to program the PLC?"

- https://logisek.com

Network First, Testing SecondIn   and    , the first   move should not be a scan. It should be understanding what the ne...
22/05/2026

Network First, Testing Second

In and , the first move should not be a scan. It should be understanding what the network is quietly telling you.

The Real Risk Is in the

One of the biggest mistakes in OT security is treating industrial environments like IT networks with unfamiliar protocols. They are not. A , , , engineering workstation, vendor , jump host, or backup server may not just be another asset. It may be part of a production process, a fragile legacy dependency, or a trusted pathway into critical operations.

---

Is Offensive Security

A meaningful OT starts with knowing what exists. Not an outdated spreadsheet, but a real view of assets, communication flows, network devices, remote access points, firewall rules, and trust relationships.

In OT, the attack path is often hidden in the architecture: a flat route between zones, vendor access landing too deep, engineering tools reaching too many PLC networks, or backups exposing project files and process context.

---

Before Aggressive Testing

Listening to traffic, reviewing configurations, mapping conduits, validating asset lists, and understanding normal behavior should come before noisy testing. Once the map is built, the right questions become sharper:

Can IT reach OT through an approved path?
Can vendor access bypass monitoring?
Can the SOC detect suspicious activity around historians, jump hosts, or engineering workstations?

---

Real OT offensive security is not about proving a controller can be disrupted. It is about understanding the environment deeply enough to identify paths that could become operational risk.

You cannot protect what you cannot see. You also cannot safely test what you do not understand.

- https://logisek.com

Address

Koropí

Opening Hours

Monday 09:00 - 18:00
Tuesday 09:00 - 18:00
Wednesday 09:00 - 18:00
Thursday 09:00 - 18:00
Friday 09:00 - 18:00

Telephone

+302106626841

Alerts

Be the first to know and let us send you an email when Logisek posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Logisek:

Share