Penetration Testing
87% of companies have critical vulnerabilities that can be exploited within hours. Certified pentesters (OSCP, CEH) conduct controlled attacks and deliver a report with concrete remediation steps - prioritized by business risk.

What is penetration testing?
Penetration testing (pentesting) is a controlled simulation of cyberattacks performed by certified experts (OSCP, CEH, GPEN) to identify security vulnerabilities before real attackers exploit them. The scope covers pentests of web applications, mobile apps, IT infrastructure, and networks — with a full report including Proof of Concept and remediation recommendations delivered within 5 business days.
Critical vulnerabilities can cost millions before you find them
Real attack simulation - concrete results
Reconnaissance
We gather information like a real attacker
Exploitation
We attempt to exploit found vulnerabilities
Report with PoC
Concrete evidence and remediation steps
Pricing Calculator
Get an estimate tailored to your needs.
Pentest Pricing Calculator
Estimate your penetration testing cost in 60 seconds
1 Test Type
2 Scope
3 Additional Options
- Report with PoC and CVSS
- Vulnerability prioritization
- Remediation steps
- Re-test after fixes
- Presentation meeting
- Pentest certificate
Indicative pricing. Exact quote after scope analysis.
2 Million Records Leaked - A Real Story
A fashion e-commerce company lost 2 million customer records (personal data, addresses, order history). SQL injection in the admin panel - found by hackers in 3 hours. The company learned about the breach from the dark web after 2 weeks. Cost: GDPR fine €850,000 + reputation damage.
Without regular penetration testing:
- Critical vulnerabilities remain unknown for years
- Hackers find vulnerabilities faster than you (average 15 days from CVE publication)
- You don’t meet PCI DSS, ISO 27001, and NIS2 requirements
- Breach costs: average $4.45M (IBM, 2023)
Controlled Attack with Concrete Evidence
We don’t just run automated scans. Our pentesters (OSCP, CEH) think like attackers - they chain vulnerabilities, test unusual vectors, look for business logic flaws. You get proof-of-concept showing exactly how you can be attacked.
What you get:
- Tests following OWASP WSTG, PTES, or NIST SP 800-115 methodology
- Vulnerability identification with CVSS 3.1 risk rating
- Proof-of-Concept for each vulnerability found
- Prioritization by business risk (not just technical)
- Detailed remediation steps for IT team
- Executive summary report for management
- Optional: retest after implementing fixes
Who is it for?
This service is for you if:
- You need to meet compliance requirements (PCI DSS requires pentests every 12 months)
- You’re launching a new web application or API to production
- You’re moving to cloud and want to verify configuration security
- You’re subject to NIS2 and need regular security assessment
- You want independent verification of DevSecOps team work
Types of Penetration Tests
External Testing (External Pentest)
Simulated attack from the internet on publicly accessible resources:
- Web applications and APIs
- VPN and RDP servers
- Email infrastructure (Office 365, Google Workspace)
- Public cloud services (S3 buckets, Azure Storage)
- DNS configuration and SSL/TLS certificates
Typical time: 3-7 business days | Price from: €6,000
Internal Testing (Internal Pentest)
Simulated attack from employee or network intruder position:
- Lateral movement in Active Directory
- Privilege escalation
- Access to critical systems and data
- Network segmentation and firewall effectiveness
- Vulnerabilities in internal applications
Typical time: 5-10 business days | Price from: €8,500
Web Application Testing (OWASP Top 10)
Detailed security analysis of web applications:
- Injection (SQL, NoSQL, LDAP, OS command)
- Broken Authentication & Session Management
- XSS (Cross-Site Scripting)
- CSRF (Cross-Site Request Forgery)
- Security Misconfiguration
- Business Logic Flaws
Typical time: 5-15 days (depending on complexity) | Price from: €7,000
Mobile Application Testing
Security analysis of iOS and Android applications:
- Static analysis (SAST) and dynamic analysis (DAST)
- Backend API security
- Sensitive data storage
- Network communication and certificate pinning
- Reverse engineering and tamper protection
Typical time: 7-12 business days | Price from: €9,500
Specialized Penetration Testing
Beyond standard tests, we run engagements tailored to specific environments and technologies:
- Comprehensive web application penetration testing — deep OWASP Top 10 and business-logic testing
- External IT infrastructure penetration testing — attack surface visible from the internet
- Internal IT infrastructure penetration testing — Active Directory, lateral movement, privilege escalation
- Professional Wi-Fi penetration testing — wireless networks and segmentation
- OT/ICS systems penetration testing — industrial environments (SCADA, PLC)
- Medical systems penetration testing — medical devices and HIS/PACS systems
- Firmware (embedded) penetration testing — IoT and embedded devices
Standards and Compliance
Penetration testing is increasingly a regulatory requirement rather than a best-practice option:
- PCI DSS (req. 11.3, 11.4) — mandatory pentests at least every 12 months and after significant changes
- NIS2 (art. 21) — regular testing of the effectiveness of cybersecurity measures
- DORA — threat-led penetration testing (TLPT) for the financial sector
- ISO 27001 (A.8.8) — technical vulnerability management with periodic verification
- OSSTMM — open methodology for measuring operational security
Pentesting works best as part of a broader process — we combine it with IT vulnerability management, source code vulnerability review, security audits, and compliance projects under KSC and NIS2.
Related Glossary Terms
Learn more about key concepts related to this service:
Contact your account manager
Discuss Penetration Testing with your dedicated account manager.

How we work
Our proven service delivery process.
Scoping
Scope, objectives and rules of engagement (RoE)
Reconnaissance
Passive and active information gathering
Exploitation
Controlled vulnerability exploitation attempts
Reporting
Report with PoC, CVSS and recommendations
Retest
Verification of implemented fixes (optional)
Benefits for your business
What you gain by choosing this service.
Avoid data breaches
Find vulnerabilities before hackers do
Regulatory compliance
Meet NIS2, PCI DSS, ISO 27001 requirements
Budget prioritization
Know where to invest in security
Customer trust
Confirm security with a certificate
Related Articles
Expand your knowledge with our resources.
CVE-2024-58354: repository takeover via pull_request_target workflow in Cal.com (CVSS 9.9)
cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_request_target trigger with the...
Read more →CVE-2026-42933: unintended proxy allowing OT segmentation bypass in Pronetiqs IntraVUE (CVSS 10.0)
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypass OT segmentation....
Read more →CVE-2026-63732: default credential and MCP plugin command injection chain in 9router (CVSS 9.9)
9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL_ONLY network gate via a spo...
Read more →Frequently Asked Questions
Common questions about Penetration Testing.
How much does a penetration test cost?
Penetration test pricing depends on scope. External tests start from €5,500, internal tests from €8,000, and comprehensive web application tests from €7,000. We offer a free quote after defining the scope.
How long does a penetration test take?
A typical penetration test takes 3-15 business days. External tests take 3-7 days, internal tests 5-10 days, and detailed web application tests 5-15 days. We deliver the report within 5 days of completing the tests.
Can a penetration test damage our systems?
No. Tests are controlled and non-destructive. Before testing, we establish rules of engagement (RoE) defining scope and limitations. For production applications, we recommend testing on a pre-prod environment or during a maintenance window.
How often should we do penetration tests?
PCI DSS requires pentests every 12 months and after any major change. NIS2 recommends regular testing. For web applications, we recommend a pentest before going to production and then every 12 months or after major updates.
What's the difference between a vulnerability scan and a penetration test?
A vulnerability scan is an automated tool - fast and cheap but with many false positives. A penetration test is manual work by an expert who chains vulnerabilities, looks for business logic flaws, and provides proof-of-concept. It's like the difference between GPS and a mountain guide.