PenTest
Penetration testing
A real attack on your systems, run by people who have done this professionally, ending in a report your engineers can act on and your auditor will accept. Not a vulnerability scan with a cover page.
What a test is actually for
A scanner tells you which doors are unlocked. A test tells you what someone does once they are through one — which credentials they find, how far sideways they move, and whether anybody notices. The second question is the one that decides how bad an incident becomes, and it is the one automated tooling cannot answer.
What you get
- Reconnaissance, scanning, exploitation, post-exploitation and lateral movement — the full chain, not the first link
- External, internal and application testing, scoped to what you actually run
- Findings ranked by what is reachable and exploited in the wild, not by a generic score
- A technical report for engineers and a summary a board can read
- A retest after remediation, so the fix is proven and not assumed
HOW IT WORKS
From first call to steady state
-
Scope and rules of engagement
What is in, what is out, what we are allowed to do and who to call if something breaks. Agreed and signed before anything starts.
-
Reconnaissance
What the internet already knows about you: exposed services, leaked credentials, forgotten hosts, staff details useful for a phishing pretext.
-
Exploitation
Getting in. Carefully, with everything logged, so the finding can be reproduced and the fix can be verified.
-
Lateral movement
The part that matters. One compromised laptop is an incident; one compromised laptop that reaches the domain controller is a catastrophe.
-
Reporting and retest
Written to be acted on: what, where, how bad, how to fix it, and how we verified the fix afterwards.
WHAT THIS ANSWERS
The obligations this covers
This is not a marketing claim. Each of these regimes names the requirement that this service is the answer to, and the page behind it says which clause.
- 444 days left AI Act Up to €35 M or 7% of turnover
- 453 days left Cyber Resilience Act Up to €15 M or 2.5% of turnover
- In force now RED / EN 18031 Product refused or withdrawn from the market
- In force now DORA Up to 2% of global turnover
Who this is for. Anyone with an internet-facing system, anyone under DORA (which mandates threat-led testing), and anyone whose insurer or largest customer has started asking for a test report.
THE REST OF IT
Delivered by the same team
Start with a conversation, not a quote
Tell us what you run and what you are being asked to prove. We will say what this would involve at your size, and whether you need it at all.