A clear testing mandate
Systems, objectives, timing and permitted methods are agreed in writing before testing begins. Testing only covers systems you are authorised to have tested.
01 / PENETRATION TESTING
A penetration test explores how weaknesses could be used in an attack. We agree the objectives and boundaries, test selected attack paths and explain what the findings mean for your business.
Request a quoteFor businesses that want to investigate risk in selected systems, before a major launch or as part of planned security work.
01 / SCOPE AND DELIVERABLES
Systems, objectives, timing and permitted methods are agreed in writing before testing begins. Testing only covers systems you are authorised to have tested.
Selected weaknesses are examined together to assess whether they could allow unauthorised access or other consequences. Depth and methods follow the agreed scope.
Reporting explains what was tested, which findings were confirmed and what they could mean for information and operations. The level of documentation is agreed in advance.
Priorities and recommended actions make the results useful for IT and management. Retesting after remediation can be agreed separately.
Scope, deliverables and pricing are tailored to the engagement. A penetration test is a snapshot within defined boundaries and cannot reveal every possible attack path.
HOW WE GET STARTED
We agree which systems, attack scenarios and testing methods the engagement will cover.
Testing follows the mandate, with agreed contact points and stop conditions.
Findings inform practical actions. Follow-up and any retesting are agreed together.
02 / REGULATIONS AND DOCUMENTATION
Our assessment of how the service can support your work. Applicable requirements depend on your organisation and how the service is used.
Test findings can help assess whether technical security measures adequately protect personal data.
GDPR, including Article 32An agreed penetration test may form part of a risk-based testing programme. This service is not offered as DORA TLPT.
DORA: testing and trainingFindings and follow-up can inform the organisation’s risk treatment and improvement work.
ISO on the standardThe service is not a certification or a guarantee of full compliance. The regulatory information is general guidance, not legal advice. Sources checked on 18 September 2026.
A vulnerability assessment provides a broader view of technical weaknesses and may include controlled testing of selected findings. A penetration test puts greater emphasis on specific attack paths, connections and consequences. The agreed scope determines the depth.
This is assessed for each engagement. The testing window, system load, contingency arrangements and limits on active testing must be agreed, particularly for systems essential to operations.
An ordinary penetration test is not a threat-led penetration test under DORA’s specific TLPT framework. TLPT applies to designated entities and has separate requirements for testing and testers.
NEXT STEP / A NO-OBLIGATION CONVERSATION
What would you like to test, and what do you want to learn? Do not include passwords or sensitive system details here.
We agree needs, scope and pricing before starting.
An enquiry carries no obligation to purchase.