Pentests from the web app to the front door, tailored to your organisation.
Classic IT security measures alone often fall short. Attackers are just as happy to walk through an unlocked door, talk an inattentive employee into something or go after a networked production line. A penetration test uncovers the weaknesses you actually have, before a real attacker does.
No access yet. We test what is visible and reachable without logging in.
Shows which traces of you attackers can find online.
Shows which traces of you attackers can find on the open internet: metadata, old accounts, publicly reachable systems. Often the first step before a targeted attack.
Uncovers security flaws in your web applications (OWASP).
Uncovers security flaws in your web applications and APIs along the OWASP catalogue. Checks the authorisation logic too, not just known CVEs.
Finds weaknesses in networks, servers and systems.
Finds weaknesses in networks, servers and systems, from outdated services to missing network segmentation. Also shows how far an attacker could move through your network after the first foothold.
The way inside runs through people and doors, not through a bug in the code.
Checks how alert your staff are to phishing and manipulation.
Checks how alert your staff are to phishing, vishing and other manipulation attempts. Results are reported by department or group only, never by name.
Tests whether unauthorised people can get into your sites.
Tests whether unauthorised people can get into your sites: factory gates, lobbies, supplier entrances. The report shows concrete gaps instead of general advice.
After the first foothold, what counts is how far privileges, networks and data can be extended.
Analyses your Windows domain for misconfigurations.
Analyses your Windows domain for misconfigurations an attacker would use to escalate privileges after the first foothold.
Checks SCADA, PLCs and industrial plants without downtime.
Checks SCADA systems, PLCs and industrial plants without stopping production, in close coordination with the operations team and without any aggressive scanning.
Tests the security of your AI systems and models.
Tests the security of your AI systems and models, from prompt injection to data leaking through the answers themselves.
Chained, realistic attack simulation across several vectors.
Chained, realistic attack simulation across several vectors: technology, people and physical access combined rather than one at a time. Shows how far a real attacker gets before anyone notices.
Custom Security audits tailored to your requirements.Security audits tailored to your requirements, for the cases where none of the standard modules is quite the right fit.
Together we define the goal, scope and depth of the test.
Our pentesters simulate real attacks, manually and with a clear target.
A clear report with concrete recommendations.
30 minutes, free and without obligation. We clarify your goal, the scope and which module fits, and then you receive a fixed-price offer.
At least once a year, plus an additional test after major changes to infrastructure or applications. NIS2, KRITIS and DORA each set their own evidence intervals.
Yes. Every report is built to stand up to an audit and can be mapped to specific requirements where needed, such as NIS2, KRITIS, TISAX, DORA or ISO 27001.
Yes, once agreed, with an emergency contact and an immediate stop if live operations are affected. A lot can also be tested on staging systems.
No. Results stay at department or group level; names never appear in the report.
Only in close coordination with operations and without aggressive scanning. SCADA, PLCs and plants are tested in a way that keeps production running.
30 minutes, no obligation. We work out which module fits your question and what it costs.