Penetration testing and Red team
The only reliable way to know whether your defences hold is to have someone try to break them. Our Red team has done this since 2010: with the same techniques as attackers, but under control, by agreed rules and with a precise report on where we got in and what needs fixing. Tests are carried out by certified ethical hackers (Certified Hacker, Master Certified Hacker). We define the scope together: from a single web portal to a whole company with its locations, employees and suppliers.
Types of tests
How a test runs
- 01
Scope and rules
Together we define what we test, when, how far we may go and whom we inform; we sign an authorisation and a confidentiality agreement.
- 02
Execution
Reconnaissance, vulnerability discovery, exploitation and lateral movement; critical findings are reported immediately, not only in the final report.
- 03
Report
A management summary and a technical part for IT: every vulnerability with severity, proof, business risk and a concrete fix.
- 04
Re-test
After the findings are fixed we verify that the fixes work and issue a final attestation usable for audits and customers.
Frequently asked questions
Can a test disrupt our operations?
The rules of engagement are set in advance: which systems are excluded, when we test and when we stop. Attacks that could cause an outage are only run with explicit permission and outside working hours.
What is the difference between a vulnerability scan and a penetration test?
A vulnerability scan is done by a tool and lists known weaknesses. A penetration test is done by people who chain vulnerabilities into an actual intrusion, check business logic and show what an attacker would really achieve.
How often should we test?
At least once a year and after every major change: a new portal, a move to the cloud, a merger. Organisations under NIS2 and ISO 27001 thereby meet the requirement for regular testing.
What do we get at the end?
A report with a management summary, vulnerabilities ranked by severity, evidence, concrete fixes and a risk assessment; a presentation of the findings to your team; after remediation a re-test and an attestation.
Who carries out the tests and how do you handle data?
Our own employed ethical hackers with Certified Hacker and Master Certified Hacker credentials, no subcontractors. We work under ISO 27001: access is personal, findings are encrypted and all data is deleted after completion.
How much does a penetration test cost?
It depends on the scope: testing a single web portal is a few days of work, testing a whole company with several locations and social engineering takes weeks. After a short conversation about what you want checked we prepare a fixed-price offer.