03 · IT Security
Protect your business from cyber threats. Our penetration tests (pentests) identify real security gaps in your systems, applications and entire infrastructure, ensuring compliance with legal and industry requirements.
Service details
A penetration test (pentest) is a controlled, authorized attack on your systems carried out by security specialists. Instead of listing theoretical weaknesses, we try to exploit them the way a real attacker would — and show you exactly what could be broken into, what data could leak and how to fix it.
Pentests minimize the risk of a cyberattack and the cost of incidents, and they are required or expected by many regulations and standards: DORA, NIS2 / KSC 2.0, PCI DSS and ISO 27001. Our tests are carried out by certified pentesters, follow OWASP and PTES methodologies and always include a retest after you fix the findings.
Our scope of services
Identifying vulnerabilities based on the OWASP Top 10, OWASP ASVS and the latest attack techniques: authentication, sessions, access control, injections, business logic.
OWASP Top 10 · ASVSREST and GraphQL interfaces: authorization of every endpoint, data exposure, rate limiting and integration flaws.
OWASP API Security Top 10Security analysis of communication, local data storage and authentication, plus reverse engineering of Android and iOS apps.
OWASP MASVSExternal and internal tests: exposed services, misconfigurations, permissions, Active Directory and resilience to network attacks.
External · internalConfiguration and permissions review of cloud environments, eliminating misconfigurations that open the door to attackers.
IaaS · PaaS · SaaSSocial engineering tests, phishing campaigns and a review of security procedures and mechanisms.
Phishing · social engineeringA comprehensive attack simulation against your organization — no templates, no compromises. See Red Teaming.
Full-scope attack simulationThreat-led penetration testing required from significant financial entities under DORA. See TLPT testing.
DORA · TIBER-EUBetween pentests, our ReconMore scanner watches your assets for new vulnerabilities every day.
Vulnerability managementDescribe what you want to test — within 48 hours you get a proposal with scope, schedule and price.
Test approach
We agree the approach with you before the test starts. It determines how much the testers know at the beginning — and how deep they can go in the time available.
| Approach | What the tester knows | Best for |
|---|---|---|
| Black box | Nothing but the target — like an external attacker | Checking what an outsider can achieve |
| Grey box | Test accounts and basic documentation | Most web apps and APIs — the best balance of depth and realism |
| White box | Full access to documentation, configuration and often source code | Critical systems where you want the most thorough review |
How we work
Deliverables
Regular security testing is required by DORA (at least yearly for systems supporting critical functions, plus TLPT for significant entities), by NIS2 / KSC 2.0 as part of assessing the effectiveness of security measures, and by PCI DSS (penetration tests at least once a year and after significant changes). Our reports are ready to be used as evidence.
Questions and answers
A penetration test is an authorized, controlled attack on your applications, systems or organization, carried out by security specialists to find and demonstrate real vulnerabilities before criminals do — together with recommendations on how to fix them.
A vulnerability scan is automated and lists potential weaknesses. A pentest is carried out by people: they confirm which weaknesses can really be exploited, chain them together, test business logic that scanners cannot understand and show the real impact. The two work best together — pentests periodically and continuous scanning in between.
At least once a year and after every significant change — a new application, a major release or a change in infrastructure. Regulations set minimums too: PCI DSS requires tests at least yearly and after significant changes, and DORA requires yearly testing of systems supporting critical or important functions.
We agree test windows, targets and techniques with you in advance and avoid actions that could harm availability or data. If you prefer, we test a staging environment identical to production. You always have a direct contact to stop the test at any moment.
It depends on the scope: a single web application takes much less time than an internal infrastructure test or a Red Team exercise. After scoping we give you the exact number of days and the schedule in the proposal, prepared within 48 hours.
An executive summary for the management board and a technical part for IT: every finding with its severity (CVSS), evidence of exploitation, steps to reproduce and concrete recommendations — plus the retest results once you have fixed the issues.
Yes. After you fix the findings, we test them again and confirm in the report which issues are closed. It is part of the service, not an extra cost.
Our in-house pentesters, holding certifications such as OSCP, CEH, CompTIA Security+ and CISSP. Every engagement is covered by a written authorization and an NDA, and we follow the highest ethical standards.
Yes. We review the configuration and permissions of cloud environments and test the applications and services running in them, following the rules published by the cloud provider.
The price depends on the scope — the number and complexity of applications, hosts or locations — and on the approach (black, grey or white box). Describe what you want to test and we will send a proposal with scope, schedule and price within 48 hours.
Related services
First step
30 minutes, no slide deck. We'll tell you straight whether this service solves your problem, what scope makes sense and how much it costs.
A proposal with scope and pricing within 48 hours of the call.
Go to contact