secureskies
Cyber Security/Evaluate/Penetration Testing

The route in,
evidenced.

A scanner lists vulnerabilities. A penetration test chains them into a route to the objective and proves what lies open at the end: domain admin, customer data, production control. We test externally, internally, against web applications and in the cloud — by hand, documented, with a retest after you remediate.

FormatTest plus retestblack/grey/white box
ScopeExternal · internal · webAWS · Azure · M365
ReferenceNIS2 Art. 21ISO 27001 A.8.8
OutcomeReport with attack pathplus retest confirmation
01 · Service

What is included.

Not just finding issues — showing what an attacker can do with them.

External test

Internet-facing systems, VPN, mail and web portals; reconnaissance as an attacker with no inside knowledge.

Internal test

From the position of a compromised client or employee: Active Directory, network segmentation, servers.

Application and cloud

Web applications against OWASP; AWS, Azure and Microsoft 365 configuration from an attacker’s view.

Report and retest

Every finding with evidence, exploitability, business impact and remediation; a retest once you have fixed them.

02 · Process

Five steps,
one deliverable.

01

Scoping

Objectives, rules of engagement, time windows, emergency contacts; written authorisation.

02

Reconnaissance

Map the attack surface.

03

Exploitation

Chain weaknesses, reach the objectives, evidence every step.

04

Report

Technical and for management; closing debrief.

05

Retest

Verify remediated findings and issue the confirmation.

03 · Who it fits

When this service
applies.

Companies with an annual testing obligation from a customer, insurer or regulator
Before go-live of new applications or cloud landing zones
After a merger or acquisition, as a baseline
More services · Evaluate

How far would an attacker get in your environment —
as far as domain admin?