Skip to main content

Penetration testing and assessments

We test your systems the way an attacker would: by hand, by certified testers, documented so it can be followed, and with a clear rating of your risk.

Der Bericht als Arbeitsgrundlage Ein Befund mit Schwere, Reproduktionsschritten, Risikobewertung und bestandenem Nachtest, daneben die Verteilung aller Befunde. CRITICAL FINDING 004 1 2 3 REPRODUCTION RISK RETEST PASSED CRITICAL HIGH MEDIUM LOW REPORT · FOUR-EYES REVIEW
Trusted by
What a pentest is

The attack, before it happens

A penetration test is a deliberate attempt to get into your systems before somebody else does. Our pentesters work by hand, find weaknesses an automated scanner misses, and establish how far an attacker could actually move on the day.

Every finding is documented with reproduction steps and rated against the BSI scheme, so that you know which risk is real and what to do first. Certified testers carry out the work, suited to applications, networks, cloud environments and industrial systems.

NIS2 requires regular technical testing. Where that is the trigger, we align the scope and the evidence with the requirement, so that the report works as proof.

Approach

How much we know beforehand changes the result

Black, grey or white box is not a matter of taste but the decision whether a test should be realistic or thorough. We recommend the approach in the first conversation and explain why.

Black box

The tester has no access to internal information and sees the system as an external attacker would.

Strengths: a realistic scenario, no prior knowledge distorting the picture, weaknesses at the surface show up quickly.

Limits: part of the time goes into reconnaissance, deeper faults often stay undiscovered, and it suits complex internal systems poorly.

Typical targets: web applications, network infrastructure, the external perimeter.

Grey box

A middle route: the tester receives part of the information, for instance the credentials of an ordinary user or an architecture sketch, but not everything.

Strengths: depth and realism together, cheaper than white box, faster than black box.

Limits: less deep than white box, less realistic than black box.

Typical targets: web applications with backend access, internal networks with external interfaces, systems with internal and external components.

White box

The tester receives full access: source code, databases, network architecture, configurations.

Strengths: the analysis goes deep, deeply buried faults get found, and the time goes into testing rather than reconnaissance.

Limits: more effort, requires expertise in the technology in use, and a lot of prior knowledge can obscure the obvious attack routes.

Typical targets: internal systems, complex applications, testing with a compliance purpose.

Approach

From release to retest.

We work to the OWASP ASVS and Top 10, PTES, OSSTMM and the BSI practical guide for IS penetration tests. Every report goes through a second-pair-of-eyes review.

1

Kick-off and scoping

Fixing objectives, scope and test windows together, and obtaining the releases.

2

Testing

Manual testing along recognised standards. Critical finds we report immediately.

3

Report

A management summary and technical findings with a finding ID and a risk rating.

4

Closing meeting

On request, going through the results with your teams and prioritising the measures.

5

Retest

On request, examining the fixed weaknesses again and confirming the state.

What you receive

A report your team can work from.

Every finding comes placed: with risk, effort and the route to a fix.

Management summary

The position on one page, readable for management and the board.

Technical findings

Every finding with a unique finding ID, evidence and reproduction steps.

Risk rating to BSI

A traceable rating of every find against a recognised scheme.

Prioritised recommendations

Concrete recommendations in the order in which they take effect.

Closing meeting

On request, a joint walk-through of the results with your teams.

Retest

On request, a re-examination of the fixed weaknesses, with confirmation of the state.

Why Yekta IT

How you recognise a test of ours

Vendor-independent

We do not trade in security products. Our assessment is tied to no manufacturer and follows your risk alone.

Tested by hand

Every finding comes from the analysis of a certified tester. A scanner delivers the surface; the chaining comes about afterwards, by hand. Every finding is evidenced with reproduction steps.

Second pair of eyes

Every report is reviewed. We bring experience from critical infrastructure sectors such as rail, energy and finance.

Credentials

Certifications and memberships.

Our testers hold recognised offensive certifications. As members of the relevant professional networks we stay current on the threat picture.

Certifications held in the team
Memberships
eco – Verband der Internetwirtschaft
networker NRW
Cost

Roughly what a pentest costs.

The effort depends on a few factors. Set your case and you get a non-binding guide figure. The exact scope we fix together in the kick-off.

What should be tested?
Scope
Approach
Include a retest?
Guide figure
Effort
person-days

Investment
Day rate € · plus VAT

A guide figure, not a quote. The final effort comes out of the scoping we do together in the kick-off.

What drives the price

Scope

How many systems, roles and functions get tested. The largest lever on the effort.

Depth

From a broad overview to deep testing of individual functions.

Approach

Black, grey or white box. With prior knowledge the testing is more targeted; without it, more reconnaissance is needed.

Retest

The re-examination after the fixes. Recommended, to confirm the state bindingly.

Complexity

An off-the-shelf CMS is tested faster than a bespoke application grown over years with interfaces into several systems.

Additional services

A second presentation of the results for further stakeholders, support during the fixes, or training afterwards.

FAQ

Common questions before commissioning.

A clearly bounded test usually takes a few days; larger environments take correspondingly longer. We name the duration bindingly after the scoping. A guide figure can be estimated in the calculator above.

We test under control and agree critical steps beforehand. Tests can run in an agreed window or against a staging environment. During active testing we stay reachable throughout the test window.

Before testing starts there is a written engagement with a release for the defined targets. If systems are hosted by a third party, for instance a cloud provider, we obtain the necessary consent together.

Black box tests without prior knowledge and reflects the outside view. Grey box is the most common case: with a test account the testing is more targeted and more efficient. White box, with documentation and possibly code, reaches the greatest depth. We recommend the approach that fits your objective.

At least once a year is usual, and after larger changes to the application or the infrastructure. For heavily exposed systems a shorter interval can make sense.

A contact, the defined test objectives, and depending on the approach either credentials or documentation. The exact need we fix in the kick-off, so that the test starts cleanly.

A penetration test is a controlled attack on your systems. We look for weaknesses the way an attacker would, and evidence what can be reached with them. At the end there is a list of findings with severity, reproduction steps and a proposed fix. A vulnerability scan delivers a list of possible problems; a penetration test shows which of them are actually exploitable in your environment.

A test shows which services are reachable, which of them are vulnerable, and what attack chain comes out of that. What you then switch off, harden or patch shrinks the surface. A retest afterwards evidences that the findings are closed.

That depends on the target. For web applications and APIs an intercepting proxy with manual analysis; for networks port and vulnerability scanners to record the surface; for Active Directory tools that analyse permission paths; for firmware disassemblers and emulation. Part of the work runs through our own scripts, because no standard tool knows a proprietary protocol. Which tools ran in your test is stated in the report.

  1. Preliminary conversation. On request we advise beforehand which test fits your question.
  2. Kick-off. Scope, time window, contacts and the escalation path get recorded.
  3. Testing to recognised standards.
  4. Rating of the weaknesses found by severity.
  5. Final report with recommendations.
  6. Presentation of the results, optional.
  7. Support during the fixes and a retest of the closed gaps, both optional.

During the testing phase you receive regular status reports and can ask questions or adjust the scope at any time. Critical findings we report immediately rather than in the report, so that you can act while the testing is still running.

Article 32 of the GDPR requires the effectiveness of technical and organisational measures to be reviewed regularly. A penetration test is such a review and documents it in a way that can be followed. It does not replace data protection advice, but it supplies the technical evidence a supervisory authority or an auditor wants to see.

Our testers hold, among others, Offensive Security Certified Professional (OSCP), Offensive Security Web Expert (OSWE) and Offensive Security Experienced Penetration Tester (OSEP). Those are practical examinations, not multiple choice tests. The company itself is not certified to ISO 27001; we work to the requirements of the standard. Who tests on your project, and what certifications that person holds, is named in the proposal.

The price follows the effort. These factors set it:

  • Scope: a single web application costs less than the whole IT infrastructure.
  • Complexity: a standard CMS such as WordPress is tested faster than a bespoke e-commerce platform.
  • Kind of test: white box costs more than black box, because reviewing source code takes time and particular knowledge.
  • Qualification of the testers.
  • Duration: five days against several weeks.
  • Additional services: presenting the results more than once for different stakeholders, training for staff, support during the fixes, a retest.

Worked examples are in our article on the course and cost of a penetration test, which is in German.

Every finding in the report comes with a concrete proposed fix. Beyond that we support the implementation if you want: from individual questions from your developers through to reworking the security architecture. Afterwards the retest establishes whether the gaps are closed.

The report has two parts: a summary for management and a technical part for implementation. Every finding carries an ID, a description, the steps to reproduce it, a rating of its severity and a proposed fix. On request we present the results remotely or on site.

Section 203 of the German Criminal Code binds certain professions to secrecy about what has been entrusted to them. They include, among others:

  • Lawyers and notaries with access to client files.
  • Doctors, dentists, psychiatrists and nursing professions with access to patient data.
  • Private health, accident and life insurers and billing agencies that work with diagnoses and findings.
  • Journalists protecting their sources.
  • Pharmacists with health and medication data.
  • Tax advisers and auditors with access to business figures.

Today that data sits in practice management systems, legal software and specialist applications. A penetration test establishes whether unauthorised access to it is possible, and documents the test. That counts towards supervisory authorities, towards an insurer if something goes wrong, and on the question of whether a data breach was avoidable.

Six points to judge it by:

  • Qualification. Practical certifications such as OSCP, and for advanced testing OSEP or OSWE. CEH and CISSP evidence knowledge, not testing practice.
  • References. In this business client names usually stay confidential. A provider can still name sectors and test scopes.
  • Breadth. Web applications, APIs, mobile apps, networks, cloud, and the black, grey and white box approaches.
  • Communication. Status reports during the test, immediate notice of critical findings, and a team you can reach.
  • Fixing. A report that only lists gaps helps little. Every finding needs a proposal, and support during implementation on request.
  • The report. Reproduction steps, severity, recommendation. Without reproduction steps your team cannot follow a finding.

Yes. We test across Germany, remotely and on site. From Berlin the enquiries are mostly about web applications, APIs and cloud environments. The testing effort does not change with the location; only travel is planned in.

Yes. In Hamburg the enquiries come mostly from retail, logistics and maritime operations. For those environments we test not only the office IT but the systems that control the flow of goods, and the interfaces to partners and service providers.

All of them. Web applications and APIs, mobile apps, internal and external infrastructure, cloud environments, wireless networks, physical security, social engineering and OT environments. The location does not restrict what we offer.

For companies and institutions in Cologne we test as we do anywhere else.

For small and mid-sized companies based in North Rhine-Westphalia the state covers half: the MID-Digitale Sicherheit programme funds a current-state analysis, penetration tests and fixing the findings at 50 per cent, with a grant between 4,000 and 15,000 euros. Since January 2026 it is approved through the NRW.BANK, and the programme runs until the end of 2029. We have supported several companies through the application.

Financial service providers are watched particularly closely, because their data is valuable to attackers and because the regulator requires regular testing. Since January 2025, DORA has required threat-led penetration testing for a subset of institutions and has replaced the BAIT for those affected. Penetration tests are one of the methods by which that evidence is produced. We test in Frankfurt on site and remotely.

Dortmund is where we are based. We work here for large groups as well as smaller companies, and we can be on site the same day.

For small and mid-sized companies based in North Rhine-Westphalia the state covers half: the MID-Digitale Sicherheit programme funds a current-state analysis, penetration tests and fixing the findings at 50 per cent, with a grant between 4,000 and 15,000 euros. Since January 2026 it is approved through the NRW.BANK, and the programme runs until the end of 2029. We have supported several companies through the application.

The criteria are the same as everywhere: practical certifications, a report with reproduction steps, and support during the fixes. For companies and institutions in Düsseldorf we test on site and remotely.

For small and mid-sized companies based in North Rhine-Westphalia the state covers half: the MID-Digitale Sicherheit programme funds a current-state analysis, penetration tests and fixing the findings at 50 per cent, with a grant between 4,000 and 15,000 euros. Since January 2026 it is approved through the NRW.BANK, and the programme runs until the end of 2029. We have supported several companies through the application.

Yes, we test in Leipzig too. The effort follows the scope of the systems, not the location. Being on site is only necessary when internal networks, wireless or physical access are being tested.

Many enquiries from Stuttgart come from the automotive industry and its supply chain. We bring vehicle experience to those: CAN, the UDS diagnostic protocol to ISO 14229, control units, and the requirements of UN R155. More on our page for automotive and mobility.

We test regularly for companies and institutions in Essen, often on site the same day.

For small and mid-sized companies based in North Rhine-Westphalia the state covers half: the MID-Digitale Sicherheit programme funds a current-state analysis, penetration tests and fixing the findings at 50 per cent, with a grant between 4,000 and 15,000 euros. Since January 2026 it is approved through the NRW.BANK, and the programme runs until the end of 2029. We have supported several companies through the application.

Next step

Talk to us.

A first conversation usually takes 30 minutes. We look at where you stand and tell you frankly whether we are the right partner.

Telephone
0231 39814905
Mon–Fri · 9am–5pm CET
Email
info@yekta-it.de
PGP key available
Location
Dortmund
Ruhrallee 9 · 44139