Frequently asked questions

Frequently asked questions about penetration testing.

Would you like to commission a penetration test? Below, you can read how we define the scope, prepare for testing and handle the results. Do you have a question about your situation? Discuss it with us.

Are there risks involved in a penetration test?

During a penetration test, we carry out activities that can affect your systems. Disruption therefore cannot be ruled out entirely. We agree the scope, testing times and permitted activities in advance to limit these risks.

You know who is carrying out the assessment, when testing takes place and which IP addresses we work from. We agree who will be available and how we report unusual events. If a test has unwanted consequences, we immediately coordinate which activities need to be adjusted or stopped.

What types of penetration tests are there?

We assess external and internal networks, web applications and APIs, among other things. For Microsoft 365, Entra ID and Azure, we offer a Cloud Security Assessment. Depending on your assessment question, we can combine different assessments. View the penetration testing options.

Black box, grey box and white box describe how much information and access our researchers receive in advance:

  • Black box: we start without detailed prior knowledge of the environment, apart from the agreed targets and conditions.
  • Grey box: we receive limited information or access, such as an account with user permissions.
  • White box: we receive extensive information and the agreed access, such as documentation, configurations or source code.

These starting points can suit different testing objectives. A white-box assessment is therefore not limited to an internal network. Together, we determine what information and access are needed to answer your assessment question.

Can I share the report with external stakeholders?

Yes. The report contains a management summary and technical findings with evidence and recommendations. This allows you to discuss the outcomes with, for example, your management, auditor or IT partner.

A penetration test report contains sensitive information about your systems and vulnerabilities. Share it only with the parties involved who need that information, and use a secure method of exchange. We can agree which sections are relevant to the recipient.

Can we split the results for different parties?

Yes, we can divide the results into report sections for different internal teams or external parties. For example, a software supplier can receive the relevant application findings and an administration provider the infrastructure findings.

We agree in advance who needs which information and how we will deliver it. When splitting the results, we take connected findings into account so that each recipient has enough context to take measures.

What is the scope of the penetration test?

The scope describes what we examine and where the boundaries of the engagement lie. Together, we determine which systems, applications, integrations or scenarios are relevant and which questions you want answered.

We document the targets, starting point, available access and operational conditions in advance. We also discuss dependencies on other parties. If an extension proves necessary during the assessment, we agree it with you first.

Can I commission a penetration test if my IT is outsourced?

Yes. Even with outsourced IT, you can have the security of your environment independently assessed. We agree with you and the IT provider involved which systems will be tested, who needs to give permission and what access is needed.

We make arrangements in advance for scheduling, contacts and handling unusual events. The findings help you and your IT partner determine which security measures need attention.

What are the next steps after the penetration test?

You receive a report with substantiated findings, risks, priorities and remediation advice. We discuss the results with you and your team. We distinguish between measures you can take in the short term and improvements that require more preparation.

The report is the final deliverable of the assessment. Our explanations and aftercare continue afterwards. Our understanding guarantee means we keep explaining the findings and advice until the IT and security leads involved understand what was found, what it means and how they can act on it.

A retest can then establish whether the agreed findings have been resolved. We agree separately which points we will examine again and when.

Would you prefer to talk it through?

Tell us what is happening. We will help you determine the next step.