Penetration testing and Red team

The only reliable way to know whether your defences hold is to have someone try to break them. Our Red team has done this since 2010: with the same techniques as attackers, but under control, by agreed rules and with a precise report on where we got in and what needs fixing. Tests are carried out by certified ethical hackers (Certified Hacker, Master Certified Hacker). We define the scope together: from a single web portal to a whole company with its locations, employees and suppliers.

Types of tests

How a test runs

  1. 01

    Scope and rules

    Together we define what we test, when, how far we may go and whom we inform; we sign an authorisation and a confidentiality agreement.

  2. 02

    Execution

    Reconnaissance, vulnerability discovery, exploitation and lateral movement; critical findings are reported immediately, not only in the final report.

  3. 03

    Report

    A management summary and a technical part for IT: every vulnerability with severity, proof, business risk and a concrete fix.

  4. 04

    Re-test

    After the findings are fixed we verify that the fixes work and issue a final attestation usable for audits and customers.

Frequently asked questions

Can a test disrupt our operations?

The rules of engagement are set in advance: which systems are excluded, when we test and when we stop. Attacks that could cause an outage are only run with explicit permission and outside working hours.

What is the difference between a vulnerability scan and a penetration test?

A vulnerability scan is done by a tool and lists known weaknesses. A penetration test is done by people who chain vulnerabilities into an actual intrusion, check business logic and show what an attacker would really achieve.

How often should we test?

At least once a year and after every major change: a new portal, a move to the cloud, a merger. Organisations under NIS2 and ISO 27001 thereby meet the requirement for regular testing.

What do we get at the end?

A report with a management summary, vulnerabilities ranked by severity, evidence, concrete fixes and a risk assessment; a presentation of the findings to your team; after remediation a re-test and an attestation.

Who carries out the tests and how do you handle data?

Our own employed ethical hackers with Certified Hacker and Master Certified Hacker credentials, no subcontractors. We work under ISO 27001: access is personal, findings are encrypted and all data is deleted after completion.

How much does a penetration test cost?

It depends on the scope: testing a single web portal is a few days of work, testing a whole company with several locations and social engineering takes weeks. After a short conversation about what you want checked we prepare a fixed-price offer.

Let's find out where you are vulnerable

Tell us what you want checked; within a few days we propose the scope and price of the test.