Penetration testing and assessments
We test your systems the way an attacker would: by hand, by certified testers, documented so it can be followed, and with a clear rating of your risk.
The attack, before it happens
A penetration test is a deliberate attempt to get into your systems before somebody else does. Our pentesters work by hand, find weaknesses an automated scanner misses, and establish how far an attacker could actually move on the day.
Every finding is documented with reproduction steps and rated against the BSI scheme, so that you know which risk is real and what to do first. Certified testers carry out the work, suited to applications, networks, cloud environments and industrial systems.
NIS2 requires regular technical testing. Where that is the trigger, we align the scope and the evidence with the requirement, so that the report works as proof.
How much we know beforehand changes the result
Black, grey or white box is not a matter of taste but the decision whether a test should be realistic or thorough. We recommend the approach in the first conversation and explain why.
Black box
The tester has no access to internal information and sees the system as an external attacker would.
Strengths: a realistic scenario, no prior knowledge distorting the picture, weaknesses at the surface show up quickly.
Limits: part of the time goes into reconnaissance, deeper faults often stay undiscovered, and it suits complex internal systems poorly.
Typical targets: web applications, network infrastructure, the external perimeter.
Grey box
A middle route: the tester receives part of the information, for instance the credentials of an ordinary user or an architecture sketch, but not everything.
Strengths: depth and realism together, cheaper than white box, faster than black box.
Limits: less deep than white box, less realistic than black box.
Typical targets: web applications with backend access, internal networks with external interfaces, systems with internal and external components.
White box
The tester receives full access: source code, databases, network architecture, configurations.
Strengths: the analysis goes deep, deeply buried faults get found, and the time goes into testing rather than reconnaissance.
Limits: more effort, requires expertise in the technology in use, and a lot of prior knowledge can obscure the obvious attack routes.
Typical targets: internal systems, complex applications, testing with a compliance purpose.
The right test for each attack surface.
From a single system to a full attack simulation. Commissioned individually, or several together when the whole picture counts.
- External penetration test The perimeter and the services exposed to the network.
- Internal penetration test Active Directory, lateral movement, privileges.
- Cloud environments AWS, Azure and Google Cloud, plus Microsoft 365 and Entra ID.
- Wireless networks Wireless networks, segmentation and guest separation.
- OSINT analysis Open sources, evaluated passively, with source and date.
From release to retest.
We work to the OWASP ASVS and Top 10, PTES, OSSTMM and the BSI practical guide for IS penetration tests. Every report goes through a second-pair-of-eyes review.
Kick-off and scoping
Fixing objectives, scope and test windows together, and obtaining the releases.
Testing
Manual testing along recognised standards. Critical finds we report immediately.
Report
A management summary and technical findings with a finding ID and a risk rating.
Closing meeting
On request, going through the results with your teams and prioritising the measures.
Retest
On request, examining the fixed weaknesses again and confirming the state.
A report your team can work from.
Every finding comes placed: with risk, effort and the route to a fix.
Management summary
The position on one page, readable for management and the board.
Technical findings
Every finding with a unique finding ID, evidence and reproduction steps.
Risk rating to BSI
A traceable rating of every find against a recognised scheme.
Prioritised recommendations
Concrete recommendations in the order in which they take effect.
Closing meeting
On request, a joint walk-through of the results with your teams.
Retest
On request, a re-examination of the fixed weaknesses, with confirmation of the state.
How you recognise a test of ours
Vendor-independent
We do not trade in security products. Our assessment is tied to no manufacturer and follows your risk alone.
Tested by hand
Every finding comes from the analysis of a certified tester. A scanner delivers the surface; the chaining comes about afterwards, by hand. Every finding is evidenced with reproduction steps.
Second pair of eyes
Every report is reviewed. We bring experience from critical infrastructure sectors such as rail, energy and finance.
Completed projects in detail.
An extract from our work. Reference details are named once released, and in person.
Certifications and memberships.
Our testers hold recognised offensive certifications. As members of the relevant professional networks we stay current on the threat picture.
Roughly what a pentest costs.
The effort depends on a few factors. Set your case and you get a non-binding guide figure. The exact scope we fix together in the kick-off.
A guide figure, not a quote. The final effort comes out of the scoping we do together in the kick-off.
Scope
How many systems, roles and functions get tested. The largest lever on the effort.
Depth
From a broad overview to deep testing of individual functions.
Approach
Black, grey or white box. With prior knowledge the testing is more targeted; without it, more reconnaissance is needed.
Retest
The re-examination after the fixes. Recommended, to confirm the state bindingly.
Complexity
An off-the-shelf CMS is tested faster than a bespoke application grown over years with interfaces into several systems.
Additional services
A second presentation of the results for further stakeholders, support during the fixes, or training afterwards.
Common questions before commissioning.
A penetration test is a controlled attack on your systems. We look for weaknesses the way an attacker would, and evidence what can be reached with them. At the end there is a list of findings with severity, reproduction steps and a proposed fix. A vulnerability scan delivers a list of possible problems; a penetration test shows which of them are actually exploitable in your environment.
A test shows which services are reachable, which of them are vulnerable, and what attack chain comes out of that. What you then switch off, harden or patch shrinks the surface. A retest afterwards evidences that the findings are closed.
That depends on the target. For web applications and APIs an intercepting proxy with manual analysis; for networks port and vulnerability scanners to record the surface; for Active Directory tools that analyse permission paths; for firmware disassemblers and emulation. Part of the work runs through our own scripts, because no standard tool knows a proprietary protocol. Which tools ran in your test is stated in the report.
- Preliminary conversation. On request we advise beforehand which test fits your question.
- Kick-off. Scope, time window, contacts and the escalation path get recorded.
- Testing to recognised standards.
- Rating of the weaknesses found by severity.
- Final report with recommendations.
- Presentation of the results, optional.
- Support during the fixes and a retest of the closed gaps, both optional.
During the testing phase you receive regular status reports and can ask questions or adjust the scope at any time. Critical findings we report immediately rather than in the report, so that you can act while the testing is still running.
Article 32 of the GDPR requires the effectiveness of technical and organisational measures to be reviewed regularly. A penetration test is such a review and documents it in a way that can be followed. It does not replace data protection advice, but it supplies the technical evidence a supervisory authority or an auditor wants to see.
Our testers hold, among others, Offensive Security Certified Professional (OSCP), Offensive Security Web Expert (OSWE) and Offensive Security Experienced Penetration Tester (OSEP). Those are practical examinations, not multiple choice tests. The company itself is not certified to ISO 27001; we work to the requirements of the standard. Who tests on your project, and what certifications that person holds, is named in the proposal.
The price follows the effort. These factors set it:
- Scope: a single web application costs less than the whole IT infrastructure.
- Complexity: a standard CMS such as WordPress is tested faster than a bespoke e-commerce platform.
- Kind of test: white box costs more than black box, because reviewing source code takes time and particular knowledge.
- Qualification of the testers.
- Duration: five days against several weeks.
- Additional services: presenting the results more than once for different stakeholders, training for staff, support during the fixes, a retest.
Worked examples are in our article on the course and cost of a penetration test, which is in German.
Every finding in the report comes with a concrete proposed fix. Beyond that we support the implementation if you want: from individual questions from your developers through to reworking the security architecture. Afterwards the retest establishes whether the gaps are closed.
The report has two parts: a summary for management and a technical part for implementation. Every finding carries an ID, a description, the steps to reproduce it, a rating of its severity and a proposed fix. On request we present the results remotely or on site.
Section 203 of the German Criminal Code binds certain professions to secrecy about what has been entrusted to them. They include, among others:
- Lawyers and notaries with access to client files.
- Doctors, dentists, psychiatrists and nursing professions with access to patient data.
- Private health, accident and life insurers and billing agencies that work with diagnoses and findings.
- Journalists protecting their sources.
- Pharmacists with health and medication data.
- Tax advisers and auditors with access to business figures.
Today that data sits in practice management systems, legal software and specialist applications. A penetration test establishes whether unauthorised access to it is possible, and documents the test. That counts towards supervisory authorities, towards an insurer if something goes wrong, and on the question of whether a data breach was avoidable.
Six points to judge it by:
- Qualification. Practical certifications such as OSCP, and for advanced testing OSEP or OSWE. CEH and CISSP evidence knowledge, not testing practice.
- References. In this business client names usually stay confidential. A provider can still name sectors and test scopes.
- Breadth. Web applications, APIs, mobile apps, networks, cloud, and the black, grey and white box approaches.
- Communication. Status reports during the test, immediate notice of critical findings, and a team you can reach.
- Fixing. A report that only lists gaps helps little. Every finding needs a proposal, and support during implementation on request.
- The report. Reproduction steps, severity, recommendation. Without reproduction steps your team cannot follow a finding.
Yes. We test across Germany, remotely and on site. From Berlin the enquiries are mostly about web applications, APIs and cloud environments. The testing effort does not change with the location; only travel is planned in.
Yes. In Hamburg the enquiries come mostly from retail, logistics and maritime operations. For those environments we test not only the office IT but the systems that control the flow of goods, and the interfaces to partners and service providers.
All of them. Web applications and APIs, mobile apps, internal and external infrastructure, cloud environments, wireless networks, physical security, social engineering and OT environments. The location does not restrict what we offer.
For companies and institutions in Cologne we test as we do anywhere else.
For small and mid-sized companies based in North Rhine-Westphalia the state covers half: the MID-Digitale Sicherheit programme funds a current-state analysis, penetration tests and fixing the findings at 50 per cent, with a grant between 4,000 and 15,000 euros. Since January 2026 it is approved through the NRW.BANK, and the programme runs until the end of 2029. We have supported several companies through the application.
Financial service providers are watched particularly closely, because their data is valuable to attackers and because the regulator requires regular testing. Since January 2025, DORA has required threat-led penetration testing for a subset of institutions and has replaced the BAIT for those affected. Penetration tests are one of the methods by which that evidence is produced. We test in Frankfurt on site and remotely.
Dortmund is where we are based. We work here for large groups as well as smaller companies, and we can be on site the same day.
For small and mid-sized companies based in North Rhine-Westphalia the state covers half: the MID-Digitale Sicherheit programme funds a current-state analysis, penetration tests and fixing the findings at 50 per cent, with a grant between 4,000 and 15,000 euros. Since January 2026 it is approved through the NRW.BANK, and the programme runs until the end of 2029. We have supported several companies through the application.
The criteria are the same as everywhere: practical certifications, a report with reproduction steps, and support during the fixes. For companies and institutions in Düsseldorf we test on site and remotely.
For small and mid-sized companies based in North Rhine-Westphalia the state covers half: the MID-Digitale Sicherheit programme funds a current-state analysis, penetration tests and fixing the findings at 50 per cent, with a grant between 4,000 and 15,000 euros. Since January 2026 it is approved through the NRW.BANK, and the programme runs until the end of 2029. We have supported several companies through the application.
Yes, we test in Leipzig too. The effort follows the scope of the systems, not the location. Being on site is only necessary when internal networks, wireless or physical access are being tested.
Many enquiries from Stuttgart come from the automotive industry and its supply chain. We bring vehicle experience to those: CAN, the UDS diagnostic protocol to ISO 14229, control units, and the requirements of UN R155. More on our page for automotive and mobility.
We test regularly for companies and institutions in Essen, often on site the same day.
For small and mid-sized companies based in North Rhine-Westphalia the state covers half: the MID-Digitale Sicherheit programme funds a current-state analysis, penetration tests and fixing the findings at 50 per cent, with a grant between 4,000 and 15,000 euros. Since January 2026 it is approved through the NRW.BANK, and the programme runs until the end of 2029. We have supported several companies through the application.
Talk to us.
A first conversation usually takes 30 minutes. We look at where you stand and tell you frankly whether we are the right partner.