Pentesting (penetration testing)
Penetration testing for infrastructure and applications: we find the vulnerabilities before attackers do and demonstrate their impact. Clear report + retest.
What is a penetration test?
A penetration test (pentest) is a controlled simulation of a real attack on your infrastructure, applications or people, carried out by specialists with your written consent. We find the vulnerabilities before an attacker does, and we show you exactly how serious they are and how to fix them.
Unlike an automated scan, a pentest includes controlled exploitation: we demonstrate the real impact instead of handing you a list of possible issues.
What we test
- External infrastructure — what an attacker on the internet sees and can exploit.
- Internal infrastructure — what happens if an attacker (or a malicious insider) is already on the network.
- Web applications — vulnerabilities in your apps and portals.
- Wi-Fi networks — access points and segmentation.
The exact scope — what’s in the test and what stays out — is something we agree together, from the start.
How a pentest works
- Scoping — what we test, when, and under what rules of engagement.
- Reconnaissance — we map the attack surface.
- Vulnerability identification — manually and with specialised tools.
- Controlled exploitation — we confirm what is genuinely exploitable, without touching production.
- Reporting — findings ranked by risk, with concrete remediation steps.
What you get
- A technical report — each vulnerability, proof of exploitation and remediation steps.
- A management summary — prioritised risks, in non-technical language.
- A presentation session of the results, together with your team.
- A retest after remediation — we confirm the issues have been closed.
Pentest vs. vulnerability scan
A vulnerability scan is automated and produces a list of possible issues. A pentest is done by people: it confirms what is actually exploitable and demonstrates impact — including how several minor issues chain into a serious attack. You need both, but the pentest is what shows you the real risk.
Frequently asked questions
How long does it take? It depends on scope and size; we agree the duration at the start of the project.
Does it disrupt operations? No. We work with clear rules of engagement, precisely so production isn’t affected.
What exactly do I get? A technical report, a management summary, a presentation session and a retest after remediation.
How much does it cost? It depends on the scope and size of the assessment — we provide an estimate on request, based on scope.
Need this service?
Write to us or call directly. A person answers, not a form.