Core service

Penetration Testing

A controlled, real-world security test of your network, Active Directory, cloud and applications. We find the weak points a genuine attacker would use, prove the impact safely, and hand you a clear plan to close them, ranked by risk.

Penetration Testing

In plain terms

What a penetration test actually does for you

A penetration test answers the one question that keeps leaders awake: if a real attacker targeted us today, could they get in, and how far could they go? Instead of hoping the answer is no, you find out in a safe, controlled way, with our team acting as the attacker and documenting every step they were able to take.

We do not simply run an automated scanner and email you the output. Every finding is checked by hand and, where it is safe to do so, demonstrated, so you see real impact, such as reaching sensitive data or gaining full administrator control, instead of a long list of theoretical warnings. You end the engagement knowing exactly where you stand and precisely what to fix first.

It also gives you something a scanner never can: context. Two organisations can have the identical missing patch, and in one it is a minor note while in the other it is the single step between the internet and every customer record. We test the way the pieces fit together in your environment specifically, so the risk rating you receive reflects your business, not a generic database entry.

Scope & coverage

What we test

Network & Active Directory Penetration Testing

Our core strength: external and internal testing that mirrors how a real intrusion spreads, from the internet to full domain control.

  • External perimeter and internet-facing services
  • Internal network, VLANs and segmentation
  • Active Directory, Kerberos, GPO and trust abuse
  • Privilege escalation and lateral movement to Domain Admin
  • Windows and Linux servers, databases and file shares

Cloud & Hybrid Penetration Testing

Testing the cloud and identity layer that now underpins most organisations, and the seams where on-prem meets cloud.

  • Microsoft Azure, Entra ID and Microsoft 365
  • Amazon Web Services and IAM roles
  • Conditional Access and MFA posture
  • Hybrid identity and on-prem to cloud escalation paths

Web Application Penetration Testing

Manual, in-depth testing of the applications your business runs on, well beyond what any automated scanner can find.

  • OWASP Top 10 and the OWASP Testing Guide
  • Authentication, sessions and access control
  • Business-logic flaws unique to your application
  • Injection, SSRF, file handling and misconfiguration

API Penetration Testing

The interfaces behind your web and mobile apps are a favourite target, and often the least tested part of the stack.

  • REST and GraphQL endpoint enumeration
  • Broken object-level authorization (IDOR / BOLA)
  • Token, key and OAuth flow abuse
  • Rate limiting, mass assignment and data exposure

Wireless, IoT & On-site Access

Where the network meets the physical world: the on-site layer an external test can never reach.

  • Wi-Fi security and rogue access points
  • Live network ports and NAC bypass
  • IoT and embedded devices, and their firmware
  • Physical access to workstations and server rooms

Secure Code Review

An optional white-box add-on: reading the source directly to catch flaws that black-box testing cannot see from the outside.

  • Source-assisted review of critical components
  • Hard-coded secrets, keys and credentials
  • Insecure dependencies and supply-chain risk
  • Root-cause fixes, not just symptoms

Test types

Black box, grey box or white box

No prior information

Black box

Simulates an external attacker with no access, probing your exposed services, VPN, web portals, mail gateway and cloud entry points.

Limited access

Grey box

An assumed-breach scenario. Shows what an attacker can do once inside: privilege escalation, lateral movement and access to sensitive resources.

Full transparency

White box

Complete information and credentials for the deepest coverage with the fewest blind spots: full validation of architecture and configuration.

Our recommendation: black box plus grey box

For the most realistic picture, we recommend combining the two. A black-box phase shows how far an outside attacker gets on their own; a grey-box phase, starting from a standard user account, reveals the real blast radius of a single stolen password or one successful phishing email. Together they answer both questions that matter: can they get in, and what happens when they do. It is the closest thing to a genuine attack, at a fraction of the cost and risk.

The value

What you gain

A real attacker's perspective

We simulate the methods genuine adversaries use, so you see exactly what they would see and what they could reach, before they do.

Evidence, not guesswork

Every finding comes with a proof of concept, a clear risk rating and concrete remediation steps your team can act on immediately.

Two audiences, one report

An executive summary for management and full technical detail for IT, so the whole organisation can act on the same findings.

Methodology

A proven, safe methodology

01

Kick-off

Scope, test scenarios, timelines, contacts and written authorisation: the clear rules of engagement.

02

Discovery & scanning

Mapping systems, services and versions to build an accurate picture of your real attack surface.

03

Test & exploitation

Controlled validation of vulnerabilities: real impact, privilege escalation and lateral movement, safely.

04

Reporting

Findings ranked by risk, each with evidence, an attack scenario and concrete remediation guidance.

05

Debrief workshop

A walkthrough of the findings with your team.

06

Retest

We confirm the key findings are actually closed.

PTESOWASP Testing GuideOWASP Top 10MITRE ATT&CKCVSS v3.1 / v4Supports NIS2 and ISO 27001

For the technical reader

Under the hood

Testing follows recognised industry standards and clearly defined phases, so results are structured, transparent and repeatable. We work to the PTES methodology and the OWASP Testing Guide, map attacker behaviour to MITRE ATT&CK, and score every issue with CVSS v3.1 or v4 so severity is objective and comparable.

We chain findings the way an attacker does. A single low-severity information leak, a forgotten service on an old operating system and a weak password are each unremarkable alone, but together they can form a path from the public internet to full domain compromise. Our job is to find and prove that path before someone with bad intentions does, and to show you exactly where to break the chain.

Everything runs within an agreed scope and testing window, with no denial of service, no destructive actions and no changes to production data. Critical findings are reported the moment we confirm them, through a direct channel, not weeks later in a report.

Practically, an engagement blends automated tooling with heavy manual effort. Scanners are useful to map the surface quickly, but they produce noise and miss anything that requires understanding, chained logic, authentication flows, trust between systems, business rules. A human tester validates every result, discards the false positives that would waste your team's time, and pursues the handful of issues that actually lead somewhere. What lands in your report is signal, each item confirmed and, where safe, demonstrated end to end.

Deliverables

What you receive

Executive summary

Clear, business-level conclusions written for management and decision makers, no jargon required.

Technical findings by risk

Every issue classified from Critical to Low with a CVSS score, so your team always knows what to fix first.

Evidence for every finding

Screenshots, logs and a proof of concept for each issue, so nothing is theoretical and everything is verifiable.

Prioritised remediation plan

Concrete, actionable fixes: urgent security measures first, strategic improvements next.

Debrief workshop

A walkthrough of the findings with your team, including questions and answers and next steps.

Retest of key findings

Confirmation that the most important gaps have actually been closed after your team has fixed them.

Who it's for

When you need a penetration test

You face NIS2, ISO 27001, DORA or client security requirements and need independent evidence of testing.
You build or run web applications, APIs, or cloud services that hold sensitive or valuable data.
You have never had an independent test, or your last one was more than a year ago.
You have just completed a migration, a merger, or a major release and want to be sure nothing was left exposed.
You had a near miss or a scare, and leadership now wants a clear, evidence-based read on your real exposure.
Your board is asking “are we secure?” and you need an answer grounded in facts, not assumptions.

Why it matters

Across Croatia and the Netherlands, the most damaging incidents keep starting the same way: an exposed remote-access service, an unpatched end-of-life server, a weak password. In external assessments we keep finding paths toward full network compromise through public, unauthenticated services running long outdated firmware. A penetration test finds that door, and closes it, long before a criminal walks through it.

Questions & answers

Penetration testing: questions and answers

How long does a penetration test take?

It depends on scope, but a focused test is usually one to three weeks of testing, followed by the report and a retest of the fixes. We agree the timeline with you up front so there are no surprises, and we can prioritise the most critical systems if you are working to a deadline.

Will the testing disrupt our systems or cause downtime?

No. We do not perform denial-of-service attacks, we take no destructive actions, and we make no changes to production data. Everything runs within an agreed testing window, and there is a direct channel to pause immediately if anything sensitive comes up.

Should we choose black box or grey box testing?

For most organisations we recommend both, in two phases. Black box shows how far an outside attacker gets on their own; grey box, from a standard user account, reveals the damage a single stolen password or successful phishing email could do. Together they give the most realistic picture at a sensible cost.

How often should we test?

At least once a year, and after any significant change: a major release, a cloud migration, a new integration, or a merger. Many regulations and client contracts now expect at least annual testing as a baseline.

Do you just run an automated scanner?

No. Scanners help us map the surface quickly, but every finding is verified by hand and the real value comes from manual testing: chaining issues, abusing business logic, and reaching genuine impact that no tool can find on its own.

Is everything confidential?

Yes. Every engagement is fully authorised, covered by an NDA, and tightly scoped. Your systems, data, and findings are treated as strictly confidential and are never shared or reused.

Free intro call, no obligation

Tell us what you run. We will tell you how we would test it.

A short call with one of the founders to agree scope, then a quote for that scope. You talk to the tester, not a sales team.

Book a free intro call