Home / Services / Penetration Testing

Penetration Testing

Controlled, authorised attack simulations against your web applications, APIs, mobile apps, infrastructure, cloud, and physical premises — executed with the same tools and techniques as real adversaries, and reported with findings your team can act on.

Overview

Find it before they do.

A penetration test is a controlled, authorised simulation of a real attack against your systems. We map your true attack surface, exploit what a determined adversary would exploit, and show you exactly how far an intruder could get — and how to stop them.

We go far beyond automated scanning. Every finding is manually verified, contextualised to your environment, and scored with CVSS so your team can prioritise with confidence. You receive clear reproduction steps and concrete remediation guidance — not a PDF that lives in a folder.

We are also one of the very few European practices offering physical penetration testing and full red team engagements with ex-intelligence partners — a capability almost no firm on the continent can match.

“A report your engineers can act on, and your board can understand.”


Capabilities

Every attack surface.

We scope precisely to your objectives and test only what matters — across the full range of modern attack surfaces.

01
Web Application

OWASP Top 10 and beyond — authentication, authorisation, injection, and business-logic flaws, every finding manually verified.

Learn more →
02
API Security

REST, GraphQL, SOAP, and gRPC — BOLA, mass assignment, rate-limit bypass, and data exposure scanners miss.

Learn more →
03
Mobile Application

iOS and Android against OWASP MASVS — storage, network, binary protections, and the backend together.

Learn more →
04
Network & Infrastructure

External and internal testing including Active Directory attack chains, lateral movement, and privilege escalation.

Learn more →
05
Cloud Security

AWS, GCP, and Azure — IAM privilege escalation, storage exposure, and serverless security mapped to real attack paths.

Learn more →
06
Secure Code Review

SAST plus expert manual review to find vulnerabilities at the source, before they reach production.

Learn more →
07
Social Engineering

Simulated phishing, vishing, and pretexting that measure and improve your human-layer resilience.

Learn more →
08
Physical

On-site access-control bypass, tailgating, and impersonation, delivered with ex-intelligence partners.

Learn more →
09
Red Team

Full-scope, multi-vector adversary simulation that tests detection and response, not just controls.

Learn more →
10
PCI DSS Segmentation

Validate that your cardholder data environment is isolated — the segmentation testing PCI DSS requires.

Learn more →
11
Vulnerability Assessment

Broad, expert-triaged discovery and prioritisation of weaknesses across your estate.

Learn more →
12
SaaS Testing

Multi-tenant platform testing — tenant isolation, RBAC, web, and API — to pass enterprise security reviews.

Learn more →
13
AI & LLM Testing

Prompt injection, jailbreaks, data leakage, and insecure agent tooling, aligned to the OWASP Top 10 for LLMs.

Learn more →
14
Grey-Box Testing

Limited-knowledge, authenticated testing — the best balance of realism, depth, and value for most apps.

Learn more →
15
Black-Box Testing

Zero-knowledge testing that simulates a real external attacker with no prior access.

Learn more →
16
White-Box Testing

Full-knowledge testing with documentation, credentials, and source for the deepest coverage.

Learn more →
17
Application Security (AppSec)

End-to-end AppSec — pentesting, SAST/DAST, dependencies, and secure SDLC across the lifecycle.

Learn more →
18
Cloud Security Assessment

Configuration and posture review against CIS Benchmarks and the CSA Cloud Controls Matrix.

Learn more →
19
Cloud Security Testing

Combined cloud posture assessment and active penetration testing across your cloud estate.

Learn more →
20
DDoS Stress Testing

Controlled DDoS simulation to measure how your infrastructure, CDN, and mitigation hold up under attack.

Learn more →
21
OT & ICS Testing

Safe security testing of operational technology, industrial control systems, and SCADA, aligned to IEC 62443.

Learn more →
Methodologies: OWASP Testing Guide OWASP API Top 10 OWASP MASVS PTES OSSTMM NIST SP 800-115 MITRE ATT&CK CVSS v3.1

How we work

Our engagement process

Every engagement follows the same five phases — scoped clearly, with no surprises in delivery.

Phase 01
Scoping

Objectives, scope, rules of engagement, and timeline agreed in writing before any work begins.

Phase 02
Evaluation

Hands-on testing and exploitation across the agreed attack surface. Evidence-based, not opinion-based.

Phase 03
Implementation

Controlled exploitation with regular status updates and immediate escalation of critical findings.

Phase 04
Reporting

CVSS-scored findings with reproduction steps, plus an executive summary for stakeholders.

Phase 05
Finalising

Debrief, remediation support, and a free retest to verify your fixes hold.


FAQ

Penetration testing FAQ

Common questions about scope, cost, and timing.

How much does penetration testing cost?
A penetration test typically costs €2,000–3,500 for a small scope, €4,000–7,000 for a medium application or network, and €8,000–15,000+ for large enterprise environments. A full red team runs €15,000–35,000. Use our online estimator for a tailored figure.
How long does a penetration test take?
Most tests take from 3–5 days for a small scope up to 10–20 days for large environments, plus reporting. Red team engagements run 15–30 days.
What types of penetration testing do you offer?
Web application, API, mobile, network and infrastructure, cloud, source code review, social engineering, physical, and full red team — plus specialisms like PCI DSS segmentation, SaaS, and AI/LLM testing.
What is the difference between black-box, grey-box, and white-box testing?
Black-box uses no prior knowledge (a pure outsider), grey-box uses limited info and standard accounts (the best value for most apps), and white-box adds documentation and source for the deepest coverage.
How often should we run a penetration test?
At least annually, and after any major change or release. ISO 27001, SOC 2, and PCI DSS all expect regular testing.
Will penetration testing disrupt our systems?
No — we agree rules of engagement up front, test carefully, and can use staging environments. Destructive tests are excluded unless explicitly requested.
What do we receive after the test?
A CVSS-scored technical report with reproduction steps, an executive summary, an attestation letter for customers and auditors, and a free retest within 60 days.
Do you offer physical and red team testing?
Yes — we are one of the few European practices offering physical penetration testing and full red team engagements with ex-intelligence partners.

Ready to test your defences?

A 30-minute scoping call costs nothing. A breach costs considerably more.

Book a meeting Send an email