Home/IT Security/Penetration testing

03 · IT Security

Penetration testing

Protect your business from cyber threats. Our penetration tests (pentests) identify real security gaps in your systems, applications and entire infrastructure, ensuring compliance with legal and industry requirements.

48 hfrom inquiry to proposal
OWASP / PTESmethodology
retestincluded

Service details

What is a penetration test?

A penetration test (pentest) is a controlled, authorized attack on your systems carried out by security specialists. Instead of listing theoretical weaknesses, we try to exploit them the way a real attacker would — and show you exactly what could be broken into, what data could leak and how to fix it.

Pentests minimize the risk of a cyberattack and the cost of incidents, and they are required or expected by many regulations and standards: DORA, NIS2 / KSC 2.0, PCI DSS and ISO 27001. Our tests are carried out by certified pentesters, follow OWASP and PTES methodologies and always include a retest after you fix the findings.

OSCPCEHCompTIA Security+CISSPOWASPPTES
IT Security

Our scope of services

What we test

Web applications

Identifying vulnerabilities based on the OWASP Top 10, OWASP ASVS and the latest attack techniques: authentication, sessions, access control, injections, business logic.

OWASP Top 10 · ASVS

APIs

REST and GraphQL interfaces: authorization of every endpoint, data exposure, rate limiting and integration flaws.

OWASP API Security Top 10

Mobile applications

Security analysis of communication, local data storage and authentication, plus reverse engineering of Android and iOS apps.

OWASP MASVS

Servers and network infrastructure

External and internal tests: exposed services, misconfigurations, permissions, Active Directory and resilience to network attacks.

External · internal

Cloud

Configuration and permissions review of cloud environments, eliminating misconfigurations that open the door to attackers.

IaaS · PaaS · SaaS

Organizational security

Social engineering tests, phishing campaigns and a review of security procedures and mechanisms.

Phishing · social engineering

Red Teaming

A comprehensive attack simulation against your organization — no templates, no compromises. See Red Teaming.

Full-scope attack simulation

TLPT for financial entities

Threat-led penetration testing required from significant financial entities under DORA. See TLPT testing.

DORA · TIBER-EU

Continuous scanning

Between pentests, our ReconMore scanner watches your assets for new vulnerabilities every day.

Vulnerability management
Need a pentest before a deadline?

Describe what you want to test — within 48 hours you get a proposal with scope, schedule and price.

Request a proposal

Test approach

Black box, grey box or white box?

We agree the approach with you before the test starts. It determines how much the testers know at the beginning — and how deep they can go in the time available.

ApproachWhat the tester knowsBest for
Black boxNothing but the target — like an external attackerChecking what an outsider can achieve
Grey boxTest accounts and basic documentationMost web apps and APIs — the best balance of depth and realism
White boxFull access to documentation, configuration and often source codeCritical systems where you want the most thorough review

How we work

A pentest in six steps

Scoping and rulesWe agree the targets, approach, test windows and contacts, and sign the authorization and NDA. You get a proposal within 48 hours.
ReconnaissanceWe map the attack surface: hosts, services, application functions and technologies.
Testing and exploitationManual testing supported by tools; we confirm each vulnerability and its real impact without harming your data.
ReportingA report for the management board and a technical report for IT, with evidence and fix recommendations.
Remediation supportWe explain the findings to your developers and administrators and help plan the fixes.
RetestAfter you fix the issues, we verify every finding again — included in the price.

Deliverables

What you get — and what sets us apart

The report

  • Executive summary for the management board, in plain language
  • Technical findings with severity (CVSS) and proof of exploitation
  • Step-by-step reproduction and concrete fix recommendations
  • Retest results confirming what has been fixed
  • A document you can show to auditors and supervisors

Our approach

  • Certified expertise: OSCP, CEH, CompTIA Security+, CISSP and more
  • Full support in remediating identified vulnerabilities
  • Reports tailored to the audience — for the board and for IT
  • Fix verification and retests included
  • Confidentiality and the highest ethical standards

Pentests and regulations

Regular security testing is required by DORA (at least yearly for systems supporting critical functions, plus TLPT for significant entities), by NIS2 / KSC 2.0 as part of assessing the effectiveness of security measures, and by PCI DSS (penetration tests at least once a year and after significant changes). Our reports are ready to be used as evidence.

Questions and answers

Penetration testing FAQ

What is a penetration test?

A penetration test is an authorized, controlled attack on your applications, systems or organization, carried out by security specialists to find and demonstrate real vulnerabilities before criminals do — together with recommendations on how to fix them.

How is a pentest different from a vulnerability scan?

A vulnerability scan is automated and lists potential weaknesses. A pentest is carried out by people: they confirm which weaknesses can really be exploited, chain them together, test business logic that scanners cannot understand and show the real impact. The two work best together — pentests periodically and continuous scanning in between.

How often should we do penetration tests?

At least once a year and after every significant change — a new application, a major release or a change in infrastructure. Regulations set minimums too: PCI DSS requires tests at least yearly and after significant changes, and DORA requires yearly testing of systems supporting critical or important functions.

Can a pentest disrupt our production systems?

We agree test windows, targets and techniques with you in advance and avoid actions that could harm availability or data. If you prefer, we test a staging environment identical to production. You always have a direct contact to stop the test at any moment.

How long does a penetration test take?

It depends on the scope: a single web application takes much less time than an internal infrastructure test or a Red Team exercise. After scoping we give you the exact number of days and the schedule in the proposal, prepared within 48 hours.

What does the report contain?

An executive summary for the management board and a technical part for IT: every finding with its severity (CVSS), evidence of exploitation, steps to reproduce and concrete recommendations — plus the retest results once you have fixed the issues.

Is the retest really included?

Yes. After you fix the findings, we test them again and confirm in the report which issues are closed. It is part of the service, not an extra cost.

Who performs the tests?

Our in-house pentesters, holding certifications such as OSCP, CEH, CompTIA Security+ and CISSP. Every engagement is covered by a written authorization and an NDA, and we follow the highest ethical standards.

Do you test cloud environments?

Yes. We review the configuration and permissions of cloud environments and test the applications and services running in them, following the rules published by the cloud provider.

What does a pentest cost?

The price depends on the scope — the number and complexity of applications, hosts or locations — and on the approach (black, grey or white box). Describe what you want to test and we will send a proposal with scope, schedule and price within 48 hours.

First step

Let's talk about penetration testing.

30 minutes, no slide deck. We'll tell you straight whether this service solves your problem, what scope makes sense and how much it costs.

Book a consultation

A proposal with scope and pricing within 48 hours of the call.

Go to contact