Get in touch
Penetration testing

Penetration testing and vulnerability assessment: find the weaknesses before others do

Controlled testing and vulnerability scanning of your systems, with a clear report on what to fix first. We handle the engagement from agreeing the scope to retesting.

A vulnerability assessment finds known weaknesses by scanning and prioritises them. Penetration testing goes a step further: with an agreed scope and written authorisation, it tries to exploit them as an attacker would, to show what is really at risk.

We do not test without written authorisation and an agreed scope.

What is included
  • Scope and rules of engagement, agreed in writing
  • External network testing (what is visible from the internet)
  • Internal network testing
  • Web application testing
  • Vulnerability scanning, once or on a recurring basis
  • Report with risk ranking and remediation guidance
  • Presentation of findings to management and retest after fixes

Frequently asked questions

What is the difference between a vulnerability assessment and a penetration test?

A vulnerability assessment is mainly automated scanning that finds known vulnerabilities and ranks them. A penetration test includes manual exploitation attempts, to show which vulnerabilities are actually exploitable and what an attacker could achieve.

How often should it be done?

Usually at least once a year and after significant changes to systems. Vulnerability scanning can be more frequent, for example quarterly.

Will it affect my systems?

We plan the tests with you, with agreed time windows and exclusions for critical systems. Some tests carry an inherent risk of disruption, which is why we define it beforehand and in writing.

Does NIS2 require it?

The Directive asks for policies on vulnerability handling and on assessing the effectiveness of security measures. Penetration tests and vulnerability assessments are one way to document these.