The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
Proposal
Our professionals take the attacker's seat and test your environment the way a real attack would: chaining flaws, working around defences and going as far as they can. At the end you hold proof of what an attacker could achieve, and the route to close each gap.
No price appears on this page. Scope does: what we do, how we run it, who runs it and what is not included. The people who read your request are the ones who will look after you, and they come back with the proposal and with time to talk it through.
A specialist genuinely tries to break in, and proves what can be done.
We put a specialist in the attacker's role to test your environment the way a real attack would: chaining flaws, bypassing defenses, and going as far as the scenario allows. The goal is not to deliver a list of tool alerts. It is to prove what an attacker could actually do in your case and show the path to close each gap.
Two factors define the depth of the work. The first is how much information we have at the start: starting from zero simulates the external attacker who only found you on the internet, starting with user access deepens the application testing, and having documentation and source code in hand yields more findings per hour of work. The second is the rigor of the engagement, which separates a single pass from a cycle with multiple professionals working in parallel, cross review, and retesting.
Before any testing, we lock down scope, execution windows, and written authorization. From you, we need formal approval and the access the chosen approach requires. At the end, you receive the technical report with every flaw and how to reproduce it. The full methodology also includes the executive report, the prioritized remediation plan, retesting after fixes, and the presentation to leadership.
Planning and authorisation
We agree the scope in writing and set the windows, the emergency contacts and the formal authorisations. No test starts without that.
Reconnaissance
We map what exists, what is exposed and where an attacker would start. Services, domains and entry points are charted before we touch anything, because a well-understood target yields more than a tool switched on blindly.
Exploitation
We genuinely try to exploit, chaining flaws the way a real attack would, until we prove how far it is possible to get.
Cross review
A second professional repeats the main tests, at a different hour. It is the stage that most often catches what the first one walked past.
Retest
Once your team has fixed things, we come back and confirm item by item that the gap closed.
Presentation
A meeting with leadership translating the technical result into business risk and investment decisions. We arrive with the answers to the questions the board always asks: what to attack first, how much effort it takes and what happens if nothing is done.
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.