Pentesting & Red Teaming / CORE SERVICE

Penetration Testing

Manual penetration testing for networks, web applications, APIs, and cloud environments, with evidence, prioritized fixes, and remediation retesting.

THE WORK, IN CONTEXT

Penetration Testing, with a clear purpose.

Penetration testing, or pentesting, covers the networks, applications and APIs, cloud environments, operational technology, and connected devices your business depends on. Nine focused services sit under this core, from an external network test to a coordinated engagement that chains findings across several environments under one scope. You choose the layers that matter. Each is tested by hand, with automated tools widening coverage rather than producing the result. The same principal scopes, tests, and reports every engagement, so nothing is handed to junior staff. Every engagement follows one rhythm. We agree the objectives, systems, and rules of engagement in writing. We coordinate testing around production safety and a stop path you control. We report each finding with reproduction steps, a clear severity rating, and a fix written for the owner. Then we validate the fix at retest with evidence.

A GOOD FIT WHEN

For CISOs, engineering leaders, and compliance owners who need proof of exposure before an attacker, an auditor, or a customer finds it. Buy this ahead of a PCI DSS or FedRAMP cycle, a customer security review, or after a major release or acquisition.

THE WORK BEHIND THE SERVICE

What we do.
What you can use.

Scope the right targets

We agree the objectives, the systems and ranges in play, and the rules of engagement in writing, including allowlisting decisions, lockout thresholds, and cloud provider notification windows. You name one stop contact, and every environment gets a signed authorization before any testing starts.

Test by hand

The principal works each layer manually, from outside reconnaissance and internal identity attack paths to cloud access controls and the authorization behind your interfaces. Automated tools widen coverage and speed the routine checks, but every reported finding is confirmed by hand, with evidence captured for each one.

Report and retest

You receive an attack narrative, findings rated for severity and written with reproduction steps and a developer-ready fix, and an executive summary for leadership and customers. After you remediate, we retest the closed items and issue a shareable attestation letter.

FIND YOUR FOCUS

Specific services.
Substantive answers.

01 / Penetration Testing

External Network Penetration Testing

Testing of your internet-facing perimeter from an outsider’s position, confirming what is exposed and attempting exploitation by hand.

  • Discover internet-facing assets from public domain, certificate, and address-range records
  • Confirm listening services across the agreed ranges against your asset inventory
  • Attempt exploitation of exposed admin interfaces, remote access, and mail systems by hand

From $2,400

Scope, pricing & FAQs
02 / Penetration Testing

Internal Network Penetration Testing

Testing from the position of an insider or an attacker with a foothold, chasing paths toward high-value administrative access.

  • Map hosts, shared resources, and services reachable from the agreed foothold
  • Abuse sign-in and directory services through credential and trust attacks
  • Harvest and reuse credentials to move sideways across the estate

From $3,600

Scope, pricing & FAQs
03 / Penetration Testing

Web Application Penetration Testing

Authenticated and unauthenticated testing of your web applications and the sign-in flows behind them, from the perspective of every user role.

  • Test access controls across roles for cross-user and privilege-escalation flaws
  • Exercise authentication and session handling, including multi-factor bypass and session hijacking
  • Probe injection and input-handling flaws across the application’s inputs

From $3,600

Scope, pricing & FAQs
04 / Penetration Testing

API Penetration Testing

Testing of the interfaces behind your applications and integrations, focused on whether each role and tenant can reach only the data and actions it should.

  • Test object-level and function-level access across roles and tenants
  • Review token handling, authentication, and session flaws per endpoint
  • Probe requests that set unauthorized fields and abuse of heavy operations

From $3,000

Scope, pricing & FAQs
05 / Penetration Testing

Cloud Penetration Testing

Cloud penetration testing validates attack paths through identities, services, and infrastructure, with evidence, remediation guidance, and retesting.

  • Review identities and permissions for privilege escalation and trust between accounts
  • Check exposure of cloud storage across the environment
  • Probe the serverless and container services running your workloads

From $3,600

Scope, pricing & FAQs
06 / Penetration Testing

Operational Technology Security Testing

Testing of operational technology and industrial control environments with a plan built around safety and availability.

  • Review how the business and control networks are separated
  • Assess remote-access paths into the control environment
  • Check the exposure of communications between control devices

From $6,000

Scope, pricing & FAQs
07 / Penetration Testing

IoT & Device Security Testing

Testing of embedded devices across hardware, firmware, radio, and the cloud and mobile services behind them.

  • Probe the exposed access points on the device hardware and extract its software
  • Analyze the device software for embedded secrets and weak update mechanisms
  • Test the wireless and network connections the device relies on

From $6,000

Scope, pricing & FAQs
08 / Penetration Testing

Vendor & Third-Party Software Assessment

Technical security evaluation of software before you buy it, deploy it, or connect it to your environment.

  • Review how the vendor builds and maintains the product securely
  • Examine the product’s software components for vulnerable and end-of-life parts
  • Run application and interface testing against the product in a sandbox where permitted

From $1,800

Scope, pricing & FAQs
09 / Penetration Testing

Comprehensive Penetration Testing

Coordinated testing across multiple environments and asset types under one scope, one attack narrative, and one report.

  • Run one scoping exercise and one authorization across every environment
  • Sequence external, internal, web, interface, and cloud testing to chain findings
  • Keep a timestamped activity log so your defenders can match alerts to test activity

From $7,200

Scope, pricing & FAQs
WHAT YOU TAKE FORWARD

Built to support the next decision.

  • Attack narrative tracing how each foothold was reached and where it led
  • Findings with reproduction steps, severity ratings, evidence, and owner-ready fixes
  • Executive summary written for leadership, customers, insurers, and auditors
  • Retest evidence confirming that remediated findings are closed
  • Shareable attestation letter covering the agreed scope and dates

The selected services, deliverables, access requirements, and any follow-up validation are agreed in your engagement scope.

INFORMED BY RECOGNIZED GUIDANCE
START AT THE SOURCE

Let’s find your next move.

A focused conversation. A clear scope. A practical path to stronger security.

Let’s talk security