Penetration Testing
A controlled, real-world security test of your network, Active Directory, cloud and applications. We find the weak points a genuine attacker would use, prove the impact safely, and hand you a clear plan to close them, ranked by risk.
In plain terms
What a penetration test actually does for you
A penetration test answers the one question that keeps leaders awake: if a real attacker targeted us today, could they get in, and how far could they go? Instead of hoping the answer is no, you find out in a safe, controlled way, with our team acting as the attacker and documenting every step they were able to take.
We do not simply run an automated scanner and email you the output. Every finding is checked by hand and, where it is safe to do so, demonstrated, so you see real impact, such as reaching sensitive data or gaining full administrator control, instead of a long list of theoretical warnings. You end the engagement knowing exactly where you stand and precisely what to fix first.
It also gives you something a scanner never can: context. Two organisations can have the identical missing patch, and in one it is a minor note while in the other it is the single step between the internet and every customer record. We test the way the pieces fit together in your environment specifically, so the risk rating you receive reflects your business, not a generic database entry.
Scope & coverage
What we test
Network & Active Directory Penetration Testing
Our core strength: external and internal testing that mirrors how a real intrusion spreads, from the internet to full domain control.
- External perimeter and internet-facing services
- Internal network, VLANs and segmentation
- Active Directory, Kerberos, GPO and trust abuse
- Privilege escalation and lateral movement to Domain Admin
- Windows and Linux servers, databases and file shares
Cloud & Hybrid Penetration Testing
Testing the cloud and identity layer that now underpins most organisations, and the seams where on-prem meets cloud.
- Microsoft Azure, Entra ID and Microsoft 365
- Amazon Web Services and IAM roles
- Conditional Access and MFA posture
- Hybrid identity and on-prem to cloud escalation paths
Web Application Penetration Testing
Manual, in-depth testing of the applications your business runs on, well beyond what any automated scanner can find.
- OWASP Top 10 and the OWASP Testing Guide
- Authentication, sessions and access control
- Business-logic flaws unique to your application
- Injection, SSRF, file handling and misconfiguration
API Penetration Testing
The interfaces behind your web and mobile apps are a favourite target, and often the least tested part of the stack.
- REST and GraphQL endpoint enumeration
- Broken object-level authorization (IDOR / BOLA)
- Token, key and OAuth flow abuse
- Rate limiting, mass assignment and data exposure
Wireless, IoT & On-site Access
Where the network meets the physical world: the on-site layer an external test can never reach.
- Wi-Fi security and rogue access points
- Live network ports and NAC bypass
- IoT and embedded devices, and their firmware
- Physical access to workstations and server rooms
Secure Code Review
An optional white-box add-on: reading the source directly to catch flaws that black-box testing cannot see from the outside.
- Source-assisted review of critical components
- Hard-coded secrets, keys and credentials
- Insecure dependencies and supply-chain risk
- Root-cause fixes, not just symptoms
Test types
Black box, grey box or white box
No prior information
Black box
Simulates an external attacker with no access, probing your exposed services, VPN, web portals, mail gateway and cloud entry points.
Limited access
Grey box
An assumed-breach scenario. Shows what an attacker can do once inside: privilege escalation, lateral movement and access to sensitive resources.
Full transparency
White box
Complete information and credentials for the deepest coverage with the fewest blind spots: full validation of architecture and configuration.
Our recommendation: black box plus grey box
For the most realistic picture, we recommend combining the two. A black-box phase shows how far an outside attacker gets on their own; a grey-box phase, starting from a standard user account, reveals the real blast radius of a single stolen password or one successful phishing email. Together they answer both questions that matter: can they get in, and what happens when they do. It is the closest thing to a genuine attack, at a fraction of the cost and risk.
The value
What you gain
A real attacker's perspective
We simulate the methods genuine adversaries use, so you see exactly what they would see and what they could reach, before they do.
Evidence, not guesswork
Every finding comes with a proof of concept, a clear risk rating and concrete remediation steps your team can act on immediately.
Two audiences, one report
An executive summary for management and full technical detail for IT, so the whole organisation can act on the same findings.
Methodology
A proven, safe methodology
Kick-off
Scope, test scenarios, timelines, contacts and written authorisation: the clear rules of engagement.
Discovery & scanning
Mapping systems, services and versions to build an accurate picture of your real attack surface.
Test & exploitation
Controlled validation of vulnerabilities: real impact, privilege escalation and lateral movement, safely.
Reporting
Findings ranked by risk, each with evidence, an attack scenario and concrete remediation guidance.
Debrief workshop
A walkthrough of the findings with your team.
Retest
We confirm the key findings are actually closed.
For the technical reader
Under the hood
Testing follows recognised industry standards and clearly defined phases, so results are structured, transparent and repeatable. We work to the PTES methodology and the OWASP Testing Guide, map attacker behaviour to MITRE ATT&CK, and score every issue with CVSS v3.1 or v4 so severity is objective and comparable.
We chain findings the way an attacker does. A single low-severity information leak, a forgotten service on an old operating system and a weak password are each unremarkable alone, but together they can form a path from the public internet to full domain compromise. Our job is to find and prove that path before someone with bad intentions does, and to show you exactly where to break the chain.
Everything runs within an agreed scope and testing window, with no denial of service, no destructive actions and no changes to production data. Critical findings are reported the moment we confirm them, through a direct channel, not weeks later in a report.
Practically, an engagement blends automated tooling with heavy manual effort. Scanners are useful to map the surface quickly, but they produce noise and miss anything that requires understanding, chained logic, authentication flows, trust between systems, business rules. A human tester validates every result, discards the false positives that would waste your team's time, and pursues the handful of issues that actually lead somewhere. What lands in your report is signal, each item confirmed and, where safe, demonstrated end to end.
Deliverables
What you receive
Executive summary
Clear, business-level conclusions written for management and decision makers, no jargon required.
Technical findings by risk
Every issue classified from Critical to Low with a CVSS score, so your team always knows what to fix first.
Evidence for every finding
Screenshots, logs and a proof of concept for each issue, so nothing is theoretical and everything is verifiable.
Prioritised remediation plan
Concrete, actionable fixes: urgent security measures first, strategic improvements next.
Debrief workshop
A walkthrough of the findings with your team, including questions and answers and next steps.
Retest of key findings
Confirmation that the most important gaps have actually been closed after your team has fixed them.
Who it's for
When you need a penetration test
Why it matters
Across Croatia and the Netherlands, the most damaging incidents keep starting the same way: an exposed remote-access service, an unpatched end-of-life server, a weak password. In external assessments we keep finding paths toward full network compromise through public, unauthenticated services running long outdated firmware. A penetration test finds that door, and closes it, long before a criminal walks through it.
Questions & answers
Penetration testing: questions and answers
How long does a penetration test take?
It depends on scope, but a focused test is usually one to three weeks of testing, followed by the report and a retest of the fixes. We agree the timeline with you up front so there are no surprises, and we can prioritise the most critical systems if you are working to a deadline.
Will the testing disrupt our systems or cause downtime?
No. We do not perform denial-of-service attacks, we take no destructive actions, and we make no changes to production data. Everything runs within an agreed testing window, and there is a direct channel to pause immediately if anything sensitive comes up.
Should we choose black box or grey box testing?
For most organisations we recommend both, in two phases. Black box shows how far an outside attacker gets on their own; grey box, from a standard user account, reveals the damage a single stolen password or successful phishing email could do. Together they give the most realistic picture at a sensible cost.
How often should we test?
At least once a year, and after any significant change: a major release, a cloud migration, a new integration, or a merger. Many regulations and client contracts now expect at least annual testing as a baseline.
Do you just run an automated scanner?
No. Scanners help us map the surface quickly, but every finding is verified by hand and the real value comes from manual testing: chaining issues, abusing business logic, and reaching genuine impact that no tool can find on its own.
Is everything confidential?
Yes. Every engagement is fully authorised, covered by an NDA, and tightly scoped. Your systems, data, and findings are treated as strictly confidential and are never shared or reused.

