// 01 · PENETRATION TESTING
Penetration testing
A penetration test is a controlled attack on your application or network, carried out by a person, not a scanner; our glossary entry sets out what a penetration test is and what it is not. Below you’ll find how a test with us runs from scoping to retest and what goes into the report. Then pick the target by what you need checked: a single application and its API, or your whole infrastructure from the outside and the inside.
// 01
How the test runs from brief to retest
Penetration testing with us starts with scoping. On a one-hour call we agree on what is in scope (domains, IP ranges, user roles, test accounts) and, more to the point, what is not. From that comes a written brief with rules of engagement: when we test, whom to escalate to if something goes down, and whether your monitoring team should know about the test. We don’t start without a signed scope.
It takes 5 to 15 business days from the start of the test to report delivery. We don’t hold urgent findings back for the report: a Critical finding is escalated by phone immediately and a High within 24 hours, so you can react during the test instead of three weeks later.
We deliver the report within 5 business days of finishing the test and walk you through it on a call, separately with management and with your developers or administrators. One retest of fixed findings is included in the price: once you deploy the fixes, we verify every finding again and record it in the report as fixed, partially fixed, or not fixed.
The process is the same for a single application and for an entire network. What differs is the target and the technique: web application and API testing against OWASP works with roles and business logic, while internal network and perimeter tests go after configuration, privileges, and network devices.
In both cases the testers are people who also do their own research: CVE-2026-39042 in MikroTik RouterOS is a finding by our team. You can weigh a vendor’s certifications yourself. What matters is which exams rest on a real compromise and which on picking from multiple-choice answers.
Environments hosted by a cloud provider are a separate target. We test the account, the identities, and the service configuration with different techniques than your own network, under the provider’s own rules, so they are ordered separately.
Wi-Fi from around the building, Android and iOS applications, and industrial control systems (OT/ICS) also call for their own techniques, so each of them is a separate target with its own scope.
// 02
What you get in the report
The report has two parts. The first is a two-page executive summary: what we tried, how far we got, what the business risk is, and what to fix first. The second is the technical section, where each finding has a description, the impact, evidence (request, response, screenshot, or code excerpt), and the steps your people follow to reproduce it.
We rate severity with CVSS 3.1 on a scale from Critical to Low and add our own remediation priority. CVSS knows nothing about your business: a Medium on a payment gateway can be more urgent than a High on an internal wiki that twenty people can reach. Why a lower score sometimes gets fixed first is the subject of a separate article.
We write the report to hold up in front of a developer and an auditor alike. It comes in Czech or English, and when you’re handing it to a customer, an insurer, or an auditor as part of a review, we add a summary of the scope and the methodology.
// 03
Types of tests
Scope, methodology, and deliverables depend on what is being tested. Each type has its own page with the details.
// 03.1
Web application and API penetration testing
A manual test of one application or API against OWASP and WSTG, including flaws in authorization and business logic.
// 03.2
Infrastructure penetration testing
Internal and external testing of the network, servers, and Active Directory. We show the path from an ordinary workstation to Domain Admin.
// 03.3
Cloud penetration testing: what we actually test in your AWS
A test of permissions, storage, and access keys in your AWS account. We look for the path from a limited identity to your data.
// 03.4
Wi-Fi penetration testing
A test of the wireless network from within signal range: WPA2 and WPA3, guest separation, and rogue access points. We look for the path from around the building into the corporate network.
// 03.5
Mobile application penetration testing
A test of a mobile app for Android and iOS: storage, communication, authentication, and the backend from the client’s point of view. Against the OWASP MASVS methodology.
// 03.6
OT/ICS penetration testing
A test of industrial control systems, OT, ICS, and SCADA, with operational safety in mind. Mostly passive; active steps only in a maintenance window.
// 04
How we classify findings
| Severity | CVSS | Handling |
|---|---|---|
| Critical | 9.0 – 10.0 | Immediate escalation |
| High | 7.0 – 8.9 | Summary within 24 hours |
| Medium | 4.0 – 6.9 | Included in the final report |
| Low | 0.1 – 3.9 | Remediation recommendation |
// 05
Frequently asked questions
// INCLUDED WITH EVERY ENGAGEMENT
Free one-time data leak check
With every service we add a one-time leak check: we tell you whether your company email addresses and passwords sit in public leaks or on the dark web as of the day of the check. It is a snapshot of one day. If you want to know about a leak whenever one appears, you move to continuous monitoring.
How continuous leak monitoring works// NEXT STEP
The scope of a test is something we agree on, not something we estimate.
Enter your email address and we’ll get back to you. On the scoping call we set out which domains, IP ranges, and user roles are in the test and what stays out of it. How long the test takes and what it costs follow from that.