Service

Penetration testing

An authorised attack on your own systems, run by a person rather than a scanner, ending in a report your developers can act on. Focused tests start at €900; full-scope engagements run into the low thousands.

Get a fixed quote

What the work covers

Manual testing, not a scan with a logo on it

A scanner finds known CVEs and misconfigurations. It does not chain three low-severity findings into a critical path, and it does not understand your business logic — that a user can reach another tenant's invoice by changing a number in a URL. That gap is the whole point of paying a human.

Scope you choose

Web application, external infrastructure, cloud configuration, or email and DNS. Most SMEs start with the web app because that is where the customer data is, then widen once they have seen a report.

A report both audiences can use

An executive summary in plain language — what was found, what it would cost you, what to fix first — and technical findings with exact reproduction steps, CVSS scores and evidence. Findings ranked Critical, High, Medium, Low.

Retest included

Once you have fixed the findings we test them again and reissue the report. A pentest you cannot show a client afterwards has only done half its job.

What it costs

Ranges, not quotes. The number moves with scope, and you get a fixed figure in writing after the scoping call — before anyone commits.

Focused

from €900

3–5 days

  • One web application or external range
  • OWASP Top 10 plus business logic
  • Ranked findings with reproduction steps
  • Retest of fixed findings

Standard

€2,500 – €5,000

1–2 weeks

  • Web application and external infrastructure
  • Authenticated testing across user roles
  • Cloud configuration review
  • Executive summary and remediation roadmap

Full scope

from €6,000

2–4 weeks

  • Web, infrastructure, cloud, email and DNS
  • API and mobile client testing
  • Phishing simulation on request
  • Debrief call with your engineering team

How it runs

  1. 01

    Scoping and authorisation

    We agree exactly what is in scope, what is off limits and when testing happens, in writing. Testing without written authorisation is a crime rather than a service, so this step is not optional.

  2. 02

    Reconnaissance and mapping

    Attack surface, technologies, entry points. Frequently the most uncomfortable finding of the engagement is something nobody knew was exposed.

  3. 03

    Exploitation

    Confirming what is actually reachable rather than what a tool flagged as theoretically possible. Anything critical is reported the day it is found, not held for the report.

  4. 04

    Report and retest

    Full report, walkthrough call, and a retest once you have deployed the fixes.

Frequently asked questions

How much does a penetration test cost for a small business?

A focused test of one web application or external range starts around €900. A standard engagement covering the application and infrastructure runs €2,500 to €5,000, and full scope with cloud, email and APIs starts around €6,000. Cost scales with the number of systems and the depth of testing, not with the size of your company.

How is a pentest different from a vulnerability scan?

A scan is automated and checks for known issues. A pentest is a person trying to break in: chaining low-severity findings into a real attack path, testing business logic no scanner understands, and confirming what an actual breach would look like. Scans are useful and cheap; they are not the same product.

Will testing take my site down?

Testing is scheduled and conducted to avoid disruption, and anything genuinely destructive is agreed in advance or excluded. If you have a staging environment that mirrors production, that is often the better target.

How often should we test?

Annually as a floor, plus a targeted test after any significant change to your attack surface — a new product feature, a cloud migration, a new API integration, an acquisition. Testing once and filing the report is how organisations end up secure as of eighteen months ago.

Do we get something we can show clients or insurers?

Yes. The report and the post-remediation retest are what procurement teams, enterprise customers and cyber insurers ask for. Passing a retest is the part that carries weight, which is why it is included rather than sold separately.

Related reading

Tell us what you are building

A short call, a written scope and a fixed range. If it turns out you do not need what we sell, we will say so.

Start the conversation