We think like an attacker, but act responsibly. During pentesting we simulate real attack scenarios to identify vulnerabilities in your IT.
This concerns not only outdated systems or open ports, but also misconfigurations, insecure passwords or access options from outside.
Penetration Testing for Your IT Infrastructure
Test IT Security Proactively
How secure is your IT really? With a professional penetration test (pentest) we uncover security gaps in your infrastructure before cybercriminals do. Whether network, web applications or Active Directory:
Our certified experts simulate real attacks and show you exactly where you stand.
Ideal for SMEs in Switzerland that want to secure their IT proactively, GDPR-compliant, transparent and clearly explained.
Ideal for SMEs in Switzerland that want to secure their IT proactively, GDPR-compliant, transparent and clearly explained.
Uncover Vulnerabilities
before attackers do
Systems
Ports
Services
Authentication
Detect vulnerabilities before others do.
Internal & external tests (Web, Network, AD)
We test your infrastructure from the inside and from the outside: Whether your systems run in the office, in the data centre or in the cloud, we tailor the test precisely to your environment.
01
External
With external penetration tests we simulate attacks from outside your network. The goal is to uncover vulnerabilities in publicly accessible systems before attackers exploit them.
Among others, we examine web servers, firewalls, cloud services as well as DNS, VPN and email configurations using automated and manual tests.
Among others, we examine web servers, firewalls, cloud services as well as DNS, VPN and email configurations using automated and manual tests.
02
Internal
Internal tests simulate attacks from within the company network, e.g. through compromised devices or unauthorised access. The focus is on Active Directory, access rights, shares and internal services.
We analyse how far an attacker can move internally and whether a privilege escalation up to domain administrator is possible.
We analyse how far an attacker can move internally and whether a privilege escalation up to domain administrator is possible.
03
Web Apps
Web applications are frequent attack targets because they are directly accessible from the internet. We analyse web apps for typical vulnerabilities such as SQL injection, XSS, insecure authentication and faulty access controls.
In addition, we identify logic errors as well as security flaws in APIs, in order to detect technical and business-logic gaps early.
In addition, we identify logic errors as well as security flaws in APIs, in order to detect technical and business-logic gaps early.
Final Report with Action Plan
On request with a presentation at your management meeting
After the test you receive a clearly understandable report with all identified vulnerabilities, prioritised by risk. Along with it we deliver a concrete action plan so you can remediate vulnerabilities in a targeted way, internally or with our support. The report is also suitable for audits, insurers or management boards.
Carried out by certified security experts
Our penetration tests are carried out exclusively by experienced Security Engineers, with certifications such as OSCP, CEH or eJPT. You receive not only technical quality, but also professional communication, confidentiality and clear advice before and after the test.
Frequently Asked Questions
All about penetration testing
01
How long does a pentest take?
Depending on the scope: 2 to 7 days. The time frame is defined together in advance.
02
Is operation disrupted in the process?
No, all tests are carried out with risk awareness and aligned with your operating hours.
03
Is the report also recognised for ISO / NIS2 audits?
Yes, the final report can be used for certifications and security attestations.