Skip to content
defend.gl

Penetration Testing as a Service

Penetration testing

A penetration test simulates a real attack on your systems, so you know your actual risk — not just the theoretical one. We test broadly and deeply, and deliver the results as a report that both leadership and technical teams can use.

Why pentest

A real test of your defences

Automated scans find the obvious flaws, but often miss the connections that only an experienced tester spots by thinking like an attacker. Without a test, you don't know whether your defences actually hold.

Test types

Types of tests we perform

01

External infrastructure

Testing everything that faces the internet — servers, firewalls, network equipment and open ports — for the weaknesses an attacker can find from the outside.

02

Web applications

Thorough testing of your websites and web apps for OWASP Top 10 vulnerabilities, flaws in authentication and authorization, and weaknesses in business logic.

03

APIs

Testing REST and GraphQL APIs for access control, rate limiting, data leakage and injection vulnerabilities.

04

Login & access control

Attacks on the front door: login flows, sessions, forgotten-password features, and attempts to bypass two-factor authentication and access restrictions.

05

Exposed services & cloud

Remote access such as VPN and RDP, mail servers, cloud services, storage and forgotten subdomains — the entry points that are often left open without anyone noticing.

Method

The method behind it

We don't improvise along the way. Every test follows recognised standards, so findings are consistent, comparable and trustworthy.

  • OWASP Testing Guide and OWASP Top 10
  • PTES (Penetration Testing Execution Standard)
  • NIST SP 800-115

The process

How a test unfolds

  1. Scope and planning

    We define the scope of the test, identify critical systems, and agree the timeline and rules of engagement.

  2. Reconnaissance

    Mapping your attack surface — the domains, services and systems included in the test.

  3. Active testing

    Manual and tool-assisted testing, where we attempt to exploit the vulnerabilities found, just as a real attacker would.

  4. Reporting

    You receive a report with prioritised findings and concrete recommendations, walked through in a meeting with your team.

  5. Retest

    Once the findings have been remediated, we verify that the fixes work.

Deliverable

The report — something you can actually use

What the report contains

A report with an executive summary for leadership, prioritised technical findings with supporting evidence, and concrete recommendations for remediation — plus a review meeting where we walk your team through the findings.

Retest

A follow-up retest is included, so you get confirmation that the reported vulnerabilities have actually been closed.

Compliance

Supports your compliance requirements

A penetration test gives you the technical documentation you need to show that the requirements in these frameworks are handled in practice — not just on paper. If you need help with the requirements themselves, you can combine the test with our compliance advisory.

NIS2 DORA ISO 27001 GDPR (Article 32)

FAQ

Questions about penetration testing

It depends on the scope, but most tests are completed in one to three weeks from scoping to report.

The price depends on scope and complexity. Contact us for a quote tailored to your systems.

Yes. Once you have remediated the reported vulnerabilities, we carry out a retest to verify that the fixes work.

Yes, our reports are structured so they can feed directly into your documentation for NIS2, DORA and similar requirements.

Get a quote for a penetration test

Contact us for a no-obligation quote tailored to your systems.