// 01 · PENETRATION TESTING

Penetration testing

A penetration test is a controlled attack on your application or network, carried out by a person, not a scanner; our glossary entry sets out what a penetration test is and what it is not. Below you’ll find how a test with us runs from scoping to retest and what goes into the report. Then pick the target by what you need checked: a single application and its API, or your whole infrastructure from the outside and the inside.

// 01

How the test runs from brief to retest

Penetration testing with us starts with scoping. On a one-hour call we agree on what is in scope (domains, IP ranges, user roles, test accounts) and, more to the point, what is not. From that comes a written brief with rules of engagement: when we test, whom to escalate to if something goes down, and whether your monitoring team should know about the test. We don’t start without a signed scope.

It takes 5 to 15 business days from the start of the test to report delivery. We don’t hold urgent findings back for the report: a Critical finding is escalated by phone immediately and a High within 24 hours, so you can react during the test instead of three weeks later.

We deliver the report within 5 business days of finishing the test and walk you through it on a call, separately with management and with your developers or administrators. One retest of fixed findings is included in the price: once you deploy the fixes, we verify every finding again and record it in the report as fixed, partially fixed, or not fixed.

The process is the same for a single application and for an entire network. What differs is the target and the technique: web application and API testing against OWASP works with roles and business logic, while internal network and perimeter tests go after configuration, privileges, and network devices.

In both cases the testers are people who also do their own research: CVE-2026-39042 in MikroTik RouterOS is a finding by our team. You can weigh a vendor’s certifications yourself. What matters is which exams rest on a real compromise and which on picking from multiple-choice answers.

Environments hosted by a cloud provider are a separate target. We test the account, the identities, and the service configuration with different techniques than your own network, under the provider’s own rules, so they are ordered separately.

Wi-Fi from around the building, Android and iOS applications, and industrial control systems (OT/ICS) also call for their own techniques, so each of them is a separate target with its own scope.

// 02

What you get in the report

The report has two parts. The first is a two-page executive summary: what we tried, how far we got, what the business risk is, and what to fix first. The second is the technical section, where each finding has a description, the impact, evidence (request, response, screenshot, or code excerpt), and the steps your people follow to reproduce it.

We rate severity with CVSS 3.1 on a scale from Critical to Low and add our own remediation priority. CVSS knows nothing about your business: a Medium on a payment gateway can be more urgent than a High on an internal wiki that twenty people can reach. Why a lower score sometimes gets fixed first is the subject of a separate article.

We write the report to hold up in front of a developer and an auditor alike. It comes in Czech or English, and when you’re handing it to a customer, an insurer, or an auditor as part of a review, we add a summary of the scope and the methodology.

// 03

Types of tests

Scope, methodology, and deliverables depend on what is being tested. Each type has its own page with the details.

// 04

How we classify findings

Vulnerability severity classification
SeverityCVSS
Critical9.0 – 10.0
High7.0 – 8.9
Medium4.0 – 6.9
Low0.1 – 3.9

// 05

Frequently asked questions

From the start of the test to report delivery, 5 to 15 business days. Of that, 2 to 3 days go to writing the report and the rest to the testing itself. The scoping call happens before the start and doesn’t count toward that time, and the retest after your fixes is scheduled separately. We can usually hold a start date within two weeks of the order.

A vulnerability scan is an automated check against a database of known flaws; a penetration test is manual work. The tester also backs up each finding with an exploitation attempt, so you know if it’s a real risk or just a tool’s alert. Flaws in authorization, business logic, and chains of smaller weaknesses are things a scanner won’t find on its own, and our comparison of penetration tests and vulnerability scans goes through them with examples.

Repeat a pentest once a year as a baseline, and after every major change: a new application version with a different data model, a cloud migration, a new supplier integration, or a security incident. Change and risk set the interval, not the calendar. In the higher obligations regime under Act No. 264/2025 Coll., on Cybersecurity (the Czech Cybersecurity Act), Decree No. 409/2025 Coll. (in Czech) requires a penetration test at least once every two years (Section 24(5)). Our NIS2 page covers which regime applies to whom and the scanning deadlines.

Under normal circumstances, no. Techniques that can bring a service down (flooding attempts, mass password guessing, exploits that risk crashing a process) we only run with your explicit approval and in an agreed window. Before a risky step, we call. Where a write could damage production data, we verify by reading only and finish the rest in a test environment.

The effort of the engagement, which comes down to four variables: how many applications and user roles, how many IP addresses and domains, how deep the test goes (perimeter only, or the internal network too), and how many environments are tested separately. Cloud accounts are a separate item: a different target, not a depth of network testing. The breakdown and the effort ranges for each service are on the pricing page. After scoping you get a fixed proposal for a specific scope, not an open-ended hourly rate.

// INCLUDED WITH EVERY ENGAGEMENT

Free one-time data leak check

With every service we add a one-time leak check: we tell you whether your company email addresses and passwords sit in public leaks or on the dark web as of the day of the check. It is a snapshot of one day. If you want to know about a leak whenever one appears, you move to continuous monitoring.

How continuous leak monitoring works

// NEXT STEP

The scope of a test is something we agree on, not something we estimate.

Enter your email address and we’ll get back to you. On the scoping call we set out which domains, IP ranges, and user roles are in the test and what stays out of it. How long the test takes and what it costs follow from that.

When you submit this form, we process your contact details so we can respond to your inquiry. How we handle them is described in our Privacy policy.

Want to tell us right away what you need tested? Open the form on the contact page