External network pentest
Internet-perimeter assessment per PTES + NIST SP 800-115: enumeration, vulnerability analysis, manual exploitation of exposed services, credential attack chains, and the breach scenario your CISO needs to see written down.
Services
Manual penetration testing by OSCP/OSCE/CREST-credentialled testers against the standards your auditors and customers actually expect: PTES methodology, OWASP ASVS L1–L3 for web, OWASP MASVS for mobile, OWASP API Security Top 10 2023, CIS Benchmarks for cloud. Every finding scored on CVSS v4.0 with business-risk context, a board-readable executive summary, JIRA-importable remediation tracker, and a free retest within 90 days. Reports designed for SOC 2 CC4/CC7 evidence, PCI DSS Req 11.4, HIPAA §164.308(a)(8), EU AI Act Article 15 and DORA TLPT. Fixed-scope, all-in USD pricing — from $700 for a basic vulnerability scan up to $4,100 for an internal or comprehensive engagement, with the line-item budget shown at the end of scoping before any testing begins.
Named OSCP/OSCE/CREST-led testers, not just scanners · GDPR-aligned · ISO 27001 ready · SOC 2 Type II in progress · HIPAA-capable · CET workday with 9 AM–1 PM ET overlap
Automated scanners catch the noise; humans catch the bugs that ship. Our engagements are manual, hypothesis-driven, and follow PTES (Penetration Testing Execution Standard) end-to-end — pre-engagement, intelligence, threat modelling, vulnerability analysis, exploitation, post-exploitation and reporting. Every finding ships with a working PoC, a CVSS v4.0 vector that includes Threat and Environmental metrics, and a remediation block your developers can ticket on Monday morning. Reports survive enterprise procurement, audit fieldwork and cyber-insurance underwriting because the methodology is documented and the testers are named.
Internet-perimeter assessment per PTES + NIST SP 800-115: enumeration, vulnerability analysis, manual exploitation of exposed services, credential attack chains, and the breach scenario your CISO needs to see written down.
OWASP ASVS L1/L2/L3 coverage: authentication, session, access control (including BOLA/IDOR), input validation, business logic abuse, file handling, API surface, and the OWASP Top 10 2021 ten chapters with active exploitation.
OWASP MASVS coverage with MASTG test cases: platform interaction, data storage, cryptography, network, authentication, code quality, resilience (root/jailbreak detection, anti-debug), and the IPA/APK static + dynamic analysis your store reviewers also do.
OWASP API Security Top 10 2023: BOLA (API1), Broken Authentication (API2), BOPLA (API3), Unrestricted Resource Consumption (API4), BFLA (API5), SSRF (API7), Security Misconfiguration (API8), Improper Inventory Management (API9). REST, GraphQL and gRPC.
AWS/GCP/Azure against CIS Benchmarks plus the provider Well-Architected Framework security pillar: IAM, encryption, logging, network exposure, secret management, container/serverless config, and the cross-account/cross-tenant boundary review.
Executive summary, methodology with PTES phases and ASVS/MASVS/API Top 10 chapters cited, findings with CVSS v4.0 vectors and PoC, attack narrative, JIRA-importable remediation tracker, and one free retest within 90 days with reissued clean letter.
Week 0: scoping call, signed Rules of Engagement (target list, allowed techniques, time windows, emergency contacts), test accounts provisioned, source-code access for grey/white-box where in scope.
Days 1–N: PTES-driven manual testing with named lead and shadow tester, daily status updates, immediate notification of any Critical finding with a working PoC, screenshot evidence captured throughout.
Within 5 business days of test end: draft report, technical debrief call with engineering, executive debrief with leadership, final report shipped as PDF + JIRA-importable CSV remediation tracker.
Within 90 days: free retest of every High and Critical finding, clean retest letter reissued for hand-off to procurement/auditor. A quarterly retainer adds rolling cadence and continuous retest between engagements.
Which test you need — and which standard it is scoped against — depends on the regulated data your product handles and the auditors your customers answer to. These are the segments we scope and test for.
Banks and payment processors must complete penetration testing as part of PCI DSS Requirement 11.4, covering the cardholder data environment (CDE). We scope tests against Req 11.4.3 and Req 11.4.5 segmentation requirements the way your QSA expects.
We simulate external and internal attacks on payment APIs, fraud detection bypass, and privilege escalation within banking systems. Reports are accepted by QSAs for PCI DSS evidence and by regulators for DORA TLPT, CBEST, and TIBER-EU frameworks. See FinTech.
The HIPAA Security Rule (45 CFR §164.312) mandates regular technical security evaluations including penetration testing of systems storing electronic protected health information (ePHI). Our testers specialize in EMR/EHR system vulnerabilities, HL7 FHIR API security, and FDA-regulated medical device firmware assessments.
Web application testing runs to OWASP ASVS L3 for high-assurance healthcare data, with findings traceable to the Security Rule safeguards your OCR auditor cites. See HealthTech.
E-commerce platforms face constant targeting through SQL injection, broken authentication, and insecure payment integrations. We test full checkout flows, third-party payment gateway integrations, session management, and cart manipulation attacks aligned with OWASP Top 10 for web applications.
Checkout flows are tested end-to-end including price manipulation, coupon abuse, and race-condition vulnerabilities in inventory reservations. PCI DSS Req 11.4 testing covers the cardholder data environment for platforms processing card payments directly.
SOC 2 Type II auditors expect documented penetration testing as evidence of security controls for CC4.1 monitoring and CC7.1 vulnerability identification. We test multi-tenant isolation boundaries, privilege escalation between customer accounts, API authorization flaws, and admin panel exposure in SaaS environments.
Our multi-tenant testing methodology specifically targets BOLA/IDOR vulnerabilities that allow one tenant to access another tenant's data. Reports are accepted by every major SOC 2 audit firm. See SaaS Development.
Government contractors and agencies must comply with NIST SP 800-53 security controls, which include penetration testing requirements for moderate and high-impact systems. We test for supply chain attack vectors, insider threat scenarios, and compliance with FISMA assessment standards.
Our public sector testers are familiar with FedRAMP authorization requirements, CMMC Level 2/3 assessment preparation, and the DoD Cybersecurity Maturity Model. Engagements follow PTES methodology with NIST SP 800-115 documentation standards that federal auditors recognize.
Industrial control systems (ICS) and SCADA networks present unique attack surfaces where a successful breach can cause physical damage, production downtime, or safety incidents. Our OT security testers follow ICS-CERT advisories and ISA/IEC 62443 standards to evaluate PLC communication security, HMI vulnerabilities, and IT/OT network segmentation.
We test IT/OT boundary controls, historian server access, remote access paths into the SCADA environment, and engineering workstation security. Deliverables include a segmentation verification report satisfying IEC 62443 zone and conduit documentation requirements.
Fixed-scope, all-in USD pricing. You see the line-item budget at the end of scoping and sign off before any testing begins — no recruitment markup, no tool surcharges, and a free retest within 90 days on every tier.
Basic vulnerability scan
from $700
2–3 days · automated scan + triage
Automated vulnerability scan with manual triage: false positives filtered, CVSS v4.0 severity and a prioritised fix list.
App / site pentest
from $1,400
1–2 weeks · single web app or site
Single web application or site, OWASP ASVS L2 by default, authenticated multi-role and business-logic testing, report and retest.
External infra pentest
from $2,300
1–2 weeks · internet perimeter
External-perimeter infrastructure pentest per PTES + NIST SP 800-115: enumeration, exposed-service exploitation, credential chains and breach scenario.
Internal / comprehensive
from $4,100
2–4 weeks · multi-surface / red-team
Internal network or comprehensive red-team-style engagement: multi-surface web/API/mobile/cloud, tenant-isolation and lateral-movement testing, attack narrative.
Threat-Led Penetration Testing (DORA TLPT, CBEST, TIBER-EU) and larger red team engagements quoted separately on a custom-scope basis. NDA and signed Rules of Engagement before any testing begins.

Annual pentest evidence packaged for CC4.1 monitoring and CC7.1 vulnerability identification — report accepted by every major audit firm.
Read more →
Annual external/internal pentest per Req 11.4.3 and segmentation testing per Req 11.4.5 — scoped and reported the way your QSA expects.
Read more →
§164.308(a)(8) technical evaluation evidence, with findings traceable to Security Rule safeguards and OCR-defensible remediation tracking.
Read more →GDPR-aligned · ISO 27001 ready · SOC 2 Type II in progress · HIPAA-capable · OSCP/CREST-led
Every engagement is led by a named OSCP/OSCE/CREST-credentialled tester. Automated scanners run in support to maximise coverage, but the findings that matter come from manual hypothesis testing and chained exploitation.
PTES-cited methodology, OWASP standard chapters, CVSS v4.0 vectors, named testers and credentials, retest letter format that maps to SOC 2 / PCI / HIPAA evidence requirements. No back-and-forth with the audit firm.
Findings are written for the developer who has to fix them: minimal repro, root-cause analysis, code-level guidance, JIRA-importable. Engineering teams close findings instead of arguing with the report.
For continuous assurance, a quarterly retainer pairs you with a relationship lead who learns your stack across the year — each quarter's test builds on prior findings rather than restarting from scratch.
Our iOS and Android apps had diverged over years of separate development. YuSMP rebuilt a single unified solution with live camera feeds, smart-home device control, and role-based multi-user access. Zero critical defects in the first six months post-launch.
Privacy apps live and die by trust. YuSMP built a no-logs WireGuard implementation with a server latency map, one-tap connect, and kill switch — every feature we had promised users. Apple review approved on the first submission.
Every engagement follows PTES end-to-end. The scope of knowledge given to testers determines how deeply we can probe business logic, authorization, and trust boundaries.
No prior knowledge of the target system. Our testers approach the target as a real external attacker, discovering exposed assets, mapping attack surface, and attempting to breach systems using public information only.
Deliverables include a full attack narrative, exploited vulnerabilities with CVSS v4.0 scores, and remediation recommendations with priority rankings. Best suited for external perimeter and internet-facing web application tests.
Partial knowledge such as user credentials or API documentation. This approach simulates an insider threat or a breach where initial access has already occurred, allowing testers to go deeper into authorization flaws, business logic vulnerabilities, and lateral movement paths.
Deliverables include an authenticated attack chain, privilege escalation findings, and a remediation roadmap with developer-friendly fix guidance. Recommended for SaaS multi-tenant testing, authenticated web app assessments, and API security reviews.
Full knowledge including source code, architecture diagrams, and credentials. Our testers review code for security anti-patterns, misconfigured infrastructure-as-code, and logic vulnerabilities that only become visible with full context.
Deliverables include code-level vulnerability references, SAST/DAST correlation analysis, and a prioritized secure development action plan. Best suited for pre-launch audits, security design reviews, and compliance-driven assessments requiring maximum coverage.
It depends on your attack surface. External network pentest (PTES methodology, NIST SP 800-115) covers internet-exposed infrastructure — DNS, mail, perimeter services, exposed admin interfaces. Web app pentest covers your application logic and is scoped against OWASP ASVS (Application Security Verification Standard) L1 for opportunistic threats, L2 for most SaaS applications handling sensitive data, L3 for high-assurance (healthcare, fintech, defence). Mobile pentest follows OWASP MASVS (Mobile ASVS) covering platform (iOS/Android) controls, network, cryptography, auth and code quality. API pentest follows the OWASP API Security Top 10 2023 (BOLA, broken auth, BOPLA, unrestricted resource consumption, etc.) and tests authn/authz at the request level. Cloud config audit reviews AWS/GCP/Azure against CIS Benchmarks plus provider-specific Well-Architected Framework security pillar. Most SaaS need web app + API + cloud config annually; mobile if you ship a mobile app.
Our lead testers hold a combination of OSCP (Offensive Security Certified Professional — practical 24-hour exam), OSCE/OSEP (more advanced exploitation), CREST CRT/CCT (UK industry-recognised, accepted by HMG and Bank of England CBEST), and where relevant CISSP for the senior advisor role. Why it matters: an OSCP-holder has demonstrably exploited multi-host environments under time pressure; an automated scanner has not. Enterprise procurement, Bank of England CBEST, EU TIBER-EU, and most cyber-insurance underwriters now ask for named credentialed testers on the engagement, not just a firm's marketing claim of 'certified professionals'.
Every finding is scored on CVSS v4.0 (the current FIRST-published vector that includes Threat and Environmental metrics, plus the Safety/Automated/Recovery extensions). We also assign a contextual business risk rating because CVSS alone misses tenant isolation and data-classification context. The report contains: an executive summary readable by the board, a methodology section citing PTES phases and the ASVS/MASVS/API Top 10 chapters tested, a findings section with reproduction steps, CVSS vector, business impact, and prioritised remediation, an attack narrative reconstructing the path an attacker would take, and an appendix of testing evidence. We also deliver a remediation tracker as JIRA-importable CSV.
Yes — every engagement includes one free retest within 90 days of the report. We re-execute the proof-of-concept for every High and Critical finding, verify the fix, and reissue a clean retest letter you can hand to enterprise procurement or an auditor. Out-of-scope retests (more than 90 days, or expanded scope) are quoted at 30% of the original engagement. For continuous assurance, a quarterly retainer keeps testing on a rolling cadence with continuous retest between engagements.
SOC 2 expects a regular pentest as evidence for CC4.1 monitoring and CC7.1 vulnerability identification; our reports are accepted by every major audit firm. PCI DSS v4.0.1 Req 11.4.3 requires annual external/internal penetration testing plus after any significant change; Req 11.4.5 requires segmentation testing (annual merchants, every 6 months service providers). HIPAA does not name 'penetration test' explicitly but §164.308(a)(8) requires periodic technical evaluation — pentests are the de-facto evidence. EU AI Act Article 15 requires accuracy, robustness and cybersecurity testing; DORA (Regulation (EU) 2022/2554) imposes Threat-Led Penetration Testing (TLPT) on significant financial entities from January 2025. We map every finding to the relevant control so the report does double duty in audits.
Fixed-scope, all-in USD pricing across four tiers. A basic vulnerability scan runs from $700 (2–3 days): automated scanning with manual triage and a prioritised fix list. An app or site pentest is from $1,400 (1–2 weeks): a single web application or site, OWASP ASVS L2 by default with authenticated multi-role and business-logic testing. An external infrastructure pentest is from $2,300 (1–2 weeks): the internet-facing perimeter per PTES + NIST SP 800-115. An internal network or comprehensive engagement is from $4,100 (2–4 weeks): multi-surface web/API/mobile/cloud with tenant-isolation and lateral-movement testing. What moves the number is scope size, surface count and required assurance level. You see the line-item budget at the end of scoping and sign off before any testing begins — no recruitment markup, no tool surcharges, and a free retest within 90 days is included on every tier.
Every pentest report includes: an executive summary readable by non-technical leadership, a methodology section citing PTES phases and the specific OWASP/NIST standards tested, a findings section with reproduction steps, CVSS v4.0 vector, business impact, and prioritised remediation guidance, an attack narrative that reconstructs the path a real attacker would take, and a JIRA-importable CSV remediation tracker. For High and Critical findings, we include a working proof-of-concept that your engineering team can reproduce in a safe environment to validate the fix.
We use CVSS v4.0, the current FIRST-published scoring standard that includes Base, Threat, and Environmental metrics plus Safety, Automatable, and Recovery extensions. Every finding receives a CVSS v4.0 vector string alongside a contextual business risk rating, because CVSS alone can misrepresent severity when tenant isolation or data classification context matters. For example, a medium CVSS score on a BOLA/IDOR vulnerability affecting multi-tenant SaaS may carry Critical business risk if it exposes all customer data.
Yes — every engagement includes one free retest within 90 days of the final report. We re-execute the proof-of-concept for every High and Critical finding after your team has applied fixes, verify the remediation is effective, and reissue a clean retest letter that enterprise procurement or an auditor can accept as evidence of resolution. Out-of-scope retests (beyond 90 days or expanded scope) are quoted at 30% of the original engagement fee.
The answer depends on your compliance obligations and change velocity. PCI DSS Req 11.4.3 requires annual external and internal penetration testing, plus after any significant infrastructure or application change. SOC 2 auditors expect at least annual testing for CC4.1/CC7.1 evidence. HIPAA §164.308(a)(8) requires periodic technical evaluations with no defined interval — annual is the de-facto standard. Beyond compliance, fast-moving SaaS teams typically benefit from quarterly or semi-annual testing to catch vulnerabilities introduced by new features before they reach enterprise customers.
Automated scanners (ZAP, Nuclei, Burp Scanner) excel at coverage — they can enumerate thousands of parameters, test known vulnerability patterns at scale, and surface configuration issues quickly. But they systematically miss business logic flaws, authentication state confusion, BOLA/IDOR at an application level, and chained vulnerabilities that require contextual reasoning across multiple requests. In our engagements, automated tools run in support of manual testing to maximize coverage, but the findings that matter come from hypothesis-driven manual testing.
A vulnerability scan enumerates known CVEs and misconfigurations against a signature database — fast, broad, but shallow. It reports potential vulnerabilities, many of which are false positives or unexploitable in your specific configuration. A penetration test takes exploitable findings further: the tester chains them together, escalates privileges, demonstrates lateral movement, and produces a breach scenario that shows your CISO and board what an attacker could actually achieve. Scans are inputs to our triage process; manual exploitation is the output that matters for compliance evidence.
Practical guides on application security, compliance audits, and data protection.




Share a few details and a senior consultant will reply within one business day.