Offensive Security

    Penetration Testing

    Penetration testing is a controlled, authorized simulation of a real cyberattack on your IT systems, performed by certified ethical hackers to identify exploitable vulnerabilities before real attackers do.

    In-depth and realistic. Our pentesters use AI where it speeds things up, but rely on human judgment where context and insight truly matter. With clear findings you can effectively remediate.

    What is a pentest?

    A pentest is a controlled attack test carried out by ethical hackers. They examine whether weaknesses in your systems, applications, cloud, network or identities can really be exploited.

    You get no scanner dump, but proven risks, priorities in order and a retest after remediation.

    Which pentests are there?

    Network Pentest

    We test external and internal networks for misconfigurations, lateral movement, and privilege escalation so real attack paths cannot cause business impact.

    More information

    Web App Pentest

    We test websites, online platforms, and web applications for logic and authentication flaws to prevent abuse, data leaks, and disruption of your digital services.

    More information

    Mobile App Pentest

    We analyse iOS and Android apps, API integrations, and data storage to prevent sensitive data from being abused on real devices.

    More information

    Cloud Pentest

    We test AWS, Azure, and Google Cloud environments for misconfigurations, exposed storage, overprivileged IAM roles, and privilege escalation paths that lead to data breaches.

    More information

    API Pentest

    We test REST and GraphQL APIs for broken authentication, authorization flaws, injection vulnerabilities, and business logic issues across all your endpoints.

    More information

    AI Systems Pentest

    We penetration test AI systems, LLMs, and chatbots for prompt injection, data leakage, and failing guardrails to prevent unintended behaviour and reputational damage.

    More Information

    WiFi and Wireless Pentest

    We penetration test your wireless infrastructure for rogue access points, evil twin attacks, WPA2/WPA3 weaknesses, and RADIUS vulnerabilities to prevent unauthorised network access.

    More Information

    Physical Pentest

    We test access control, camera surveillance, and the human factor to expose unauthorised physical access to people, systems, and data.

    More Information

    Audit-Ready Pentest

    We perform penetration tests aligned with NIS2, GDPR, ISO 27001, and DORA, ensuring audit requirements are met without false security.

    More Information

    PTaaS

    With PTaaS, you test on demand or through a subscription and track risks and remediation in real time, ensuring new releases do not create blind spots.

    More Information

    Pentest Retest

    We confirm that your fixes actually hold. A certified ethical hacker retests the original vulnerabilities and delivers written validation per finding.

    More information

    Rapid Response Pentest

    When a standard planning cycle is not an option. We typically start a targeted security test within 48 to 72 hours of agreement, fully human-validated.

    More information

    Scan, AI pentest or pentest by ethical hackers?

    All three have their place. This is where they differ.

    Automated scan

    Finds known vulnerabilities quickly and across the whole environment. A solid baseline for regular checks, but it reports possibilities and does not prove impact.

    AI pentesting tool

    Fast, repeatable and strong on known patterns within a fixed scope. Coverage and depth differ per tool, and final responsibility for the result stays with you.

    Pentest by ethical hackers

    Ethical hackers validate every finding, chain attack paths across web, API, cloud and people, and put their name under the report. Retest included, so you know it is fixed.

    How a pentest works

    01

    Intake and scope

    A short conversation about your systems and goal, then a fixed proposal.

    02

    Test

    AI-assisted recon, manual testing and validation of every finding.

    03

    Report

    Priorities in order and a debrief.

    04

    Retest

    Verification that the fix really closes the risk.

    What do you get after the pentest?

    Executive summary - Risk overview and priorities for leadership
    Technical report - Detailed findings with evidence for your IT team
    Remediation plan - Concrete steps to fix issues, prioritized by urgency
    Retest included - We verify your fixes work
    Compliance mapping: NIS2, GDPR, ISO 27001 and other standards
    Raw data - All tool outputs and test results
    sample_report.pdf
    12
    Critical
    24
    High
    47
    Medium

    Frequently asked questions

    The duration depends on scope: a web application test takes 3-5 days, while a full network test requires 1-2 weeks. We'll discuss the exact timeline during the intake meeting.

    We test within agreed windows and with techniques that will not take your systems down. Anything that carries a risk of disruption is discussed upfront and only carried out once you approve it. For critical systems we test with extra caution.

    We follow the Penetration Testing Execution Standard (PTES) and OWASP guidelines. Our pentesters are OSCP and CEH-certified.

    We treat it strictly confidential. We only document what's necessary for the report and delete all data afterwards. This is covered in our NDA.

    Yes. Automated tools and AI pentesting tools cover breadth and frequency well. Ethical hackers add depth, context, attack chains and signed reports, and also test people and processes. Most mature security programs combine both.

    AI speeds up reconnaissance and is improving quickly. An ethical hacker adds depth, context and attack chains, also tests people and processes, and stands behind the report. At Sectricity every finding is validated manually. Many teams combine an AI tool for regular coverage with a pentest for depth.

    Professional external pentests usually start around €2,500 for a limited scope, always including the retest. Authenticated testing, multiple user roles, APIs and payment flows increase the scope and therefore the price; complex enterprise environments can exceed €20,000. We always establish the exact price in a free scoping call before we quote. Our pentest cost guide explains the factors and the questions to ask any provider.

    At least annually, plus after significant changes such as new applications, migrations, or acquisitions. Frameworks like ISO 27001 and NIS2 expect demonstrable testing of your security measures, and cyber insurers increasingly require evidence. Fast-changing environments benefit from on-demand testing through RedSOC.

    A vulnerability scan automatically detects known issues. A pentest is human-led: our ethical hackers actively exploit vulnerabilities, chain them into realistic attack paths, and manually validate every finding. Mature programmes use both.

    Yes. Every Sectricity pentest includes the retest: one retest per finding, with written confirmation per finding of open or closed. Verifying that fixes actually work is part of delivering real security, and it gives your auditors and insurers the evidence they need.

    Check your security

    Free scan that maps your vulnerabilities.