Before someone else finds your weak spots.

Pentests from the web app to the front door, tailored to your organisation.

NIS2-compliant KRITIS experience TISAX-ready DORA basic testing
87%
of German companies were recently hit by data theft, espionage or sabotage
Bitkom Wirtschaftsschutz 2025
€202bn
damage caused by cyberattacks in Germany, every year
Bitkom Wirtschaftsschutz 2025

Classic IT security measures alone often fall short. Attackers are just as happy to walk through an unlocked door, talk an inattentive employee into something or go after a networked production line. A penetration test uncovers the weaknesses you actually have, before a real attacker does.

Our modules, in the order an attacker meets them

1

What can be reached from outside

No access yet. We test what is visible and reachable without logging in.

Reconnaissance

Shows which traces of you attackers can find online.

Shows which traces of you attackers can find on the open internet: metadata, old accounts, publicly reachable systems. Often the first step before a targeted attack.

Web-App Pentest

Uncovers security flaws in your web applications (OWASP).

Uncovers security flaws in your web applications and APIs along the OWASP catalogue. Checks the authorisation logic too, not just known CVEs.

Infrastructure Pentest

Finds weaknesses in networks, servers and systems.

Finds weaknesses in networks, servers and systems, from outdated services to missing network segmentation. Also shows how far an attacker could move through your network after the first foothold.

2

How someone gets in

The way inside runs through people and doors, not through a bug in the code.

Social Engineering

Checks how alert your staff are to phishing and manipulation.

Checks how alert your staff are to phishing, vishing and other manipulation attempts. Results are reported by department or group only, never by name.

Physical Pentest

Tests whether unauthorised people can get into your sites.

Tests whether unauthorised people can get into your sites: factory gates, lobbies, supplier entrances. The report shows concrete gaps instead of general advice.

3

What becomes possible inside

After the first foothold, what counts is how far privileges, networks and data can be extended.

Active Directory Pentest

Analyses your Windows domain for misconfigurations.

Analyses your Windows domain for misconfigurations an attacker would use to escalate privileges after the first foothold.

OT Pentest

Checks SCADA, PLCs and industrial plants without downtime.

Checks SCADA systems, PLCs and industrial plants without stopping production, in close coordination with the operations team and without any aggressive scanning.

AI Pentest

Tests the security of your AI systems and models.

Tests the security of your AI systems and models, from prompt injection to data leaking through the answers themselves.

Across all three layers

Red Teaming

Chained, realistic attack simulation across several vectors.

Chained, realistic attack simulation across several vectors: technology, people and physical access combined rather than one at a time. Shows how far a real attacker gets before anyone notices.

When none of the modules quite fits

Custom Security audits tailored to your requirements.Security audits tailored to your requirements, for the cases where none of the standard modules is quite the right fit.

How it works

01

Scoping

Together we define the goal, scope and depth of the test.

02

Testing

Our pentesters simulate real attacks, manually and with a clear target.

03

Report

A clear report with concrete recommendations.

Which module fits you?

  • You want to know how far an attacker really gets before anyone notices.Red Teaming
  • You want to check whether strangers can walk into your buildings unnoticed.Physical Pentest
  • You want to know whether staff fall for phishing emails or phone calls.Social Engineering
  • You want to secure your Windows domain and internal systems.Active Directory Pentest
  • You run SCADA, PLCs or other production systems.OT Pentest
  • You use your own AI models or LLM applications.AI Pentest
  • You want to find weaknesses in networks, servers or internal systems.Infrastructure Pentest
  • You want your web applications or APIs tested before go-live.Web-App Pentest
  • You want to know what attackers can find out about you before the first attack.Reconnaissance
  • None of the standard modules quite fits your case.Custom

Frequently asked questions

How does the initial call work?

30 minutes, free and without obligation. We clarify your goal, the scope and which module fits, and then you receive a fixed-price offer.

How often should we have a test done?

At least once a year, plus an additional test after major changes to infrastructure or applications. NIS2, KRITIS and DORA each set their own evidence intervals.

Do we get evidence we can show customers or auditors?

Yes. Every report is built to stand up to an audit and can be mapped to specific requirements where needed, such as NIS2, KRITIS, TISAX, DORA or ISO 27001.

Do you also test production systems?

Yes, once agreed, with an emergency contact and an immediate stop if live operations are affected. A lot can also be tested on staging systems.

Are individual employees named in social engineering tests?

No. Results stay at department or group level; names never appear in the report.

Does an OT test run against live production?

Only in close coordination with operations and without aggressive scanning. SCADA, PLCs and plants are tested in a way that keeps production running.

Book a free initial call

30 minutes, no obligation. We work out which module fits your question and what it costs.