CRA full compliance required 453 days left What it means for you
THZ Networks Under attack? SOS — incident response, any hour of any day

PenTest

Penetration testing

A real attack on your systems, run by people who have done this professionally, ending in a report your engineers can act on and your auditor will accept. Not a vulnerability scan with a cover page.

What a test is actually for

A scanner tells you which doors are unlocked. A test tells you what someone does once they are through one — which credentials they find, how far sideways they move, and whether anybody notices. The second question is the one that decides how bad an incident becomes, and it is the one automated tooling cannot answer.

What you get

  • Reconnaissance, scanning, exploitation, post-exploitation and lateral movement — the full chain, not the first link
  • External, internal and application testing, scoped to what you actually run
  • Findings ranked by what is reachable and exploited in the wild, not by a generic score
  • A technical report for engineers and a summary a board can read
  • A retest after remediation, so the fix is proven and not assumed

HOW IT WORKS

From first call to steady state

  1. Scope and rules of engagement

    What is in, what is out, what we are allowed to do and who to call if something breaks. Agreed and signed before anything starts.

  2. Reconnaissance

    What the internet already knows about you: exposed services, leaked credentials, forgotten hosts, staff details useful for a phishing pretext.

  3. Exploitation

    Getting in. Carefully, with everything logged, so the finding can be reproduced and the fix can be verified.

  4. Lateral movement

    The part that matters. One compromised laptop is an incident; one compromised laptop that reaches the domain controller is a catastrophe.

  5. Reporting and retest

    Written to be acted on: what, where, how bad, how to fix it, and how we verified the fix afterwards.

WHAT THIS ANSWERS

The obligations this covers

This is not a marketing claim. Each of these regimes names the requirement that this service is the answer to, and the page behind it says which clause.

Who this is for. Anyone with an internet-facing system, anyone under DORA (which mandates threat-led testing), and anyone whose insurer or largest customer has started asking for a test report.

Start with a conversation, not a quote

Tell us what you run and what you are being asked to prove. We will say what this would involve at your size, and whether you need it at all.

Get in touch +386 51 249 533