Your sector, its real attack surface, and what we test.
Darkmoon is the same engine for everyone: 50 specialist agents, 142 tools, findings proven by exploitation. What changes by sector is where the exposure is, which data is at stake, which rules apply, and whether you run it yourself or order a managed engagement. Pick your sector.
S.03Sector familyProfessional services
Firms that hold other people's secrets: client files, deeds, accounts, candidates.
Law firms
Privileged files, escrow payments and partner inboxes in one tenant: a single compromised mailbox exposes every matter.
Accounting firms
One firm holds the payroll, bank details and tax files of hundreds of client companies, and attackers know the filing calendar.
Notaries
Completion-day funds, identity documents and electronic deeds move through one office mailbox: the ideal target for payment diversion.
HR, recruitment & payroll
CVs, identity numbers, salaries and bank details of thousands of people sit behind candidate portals and payroll accounts built for speed.
S.04Sector familyHealthcare
Patient data, connected devices and a care activity that cannot stop.
S.05Sector familyFinancial services
Payment flows, identities and a resilience-testing regime of their own (DORA).
S.06Sector familyIndustry & manufacturing
IT and OT estates meeting on the plant floor, with production as the hostage.
S.07Sector familyTechnology & SaaS
Code shipped daily, cloud by default, customers who ask for proof.
S.08RegulationNIS2: who is actually in scope, and what testing has to do with it.
A profession is never in scope on its own. NIS2 lists sectors and entity types, applies size thresholds, and leaves the detail to each member state's transposition. Our guide separates the entities the Directive names from the organisations that only feel it through customers and suppliers, and shows where a validated penetration test fits in an Article 21 risk-management programme. Darkmoon does not certify compliance. Public administrations: in scope at central and regional level, local authorities pending the French law. NIS2 Annex I lists public administration entities of central government and, after a risk-based assessment, of regional level. Local authorities are covered only where a member state extends the Directive to them: the French bill does so above a 30 000-inhabitant threshold, and that law is not in force as of October 2026. Until it is, public bodies find their situation, and what a penetration test contributes, in the guide.
S.09NextNot sure which page is yours? Describe the target, we scope it.
A guided order form, a legal framework signed online, a flat rate, and an expert who calls you back for scoping.