Web Application Tests
OWASP Top 10, authentication, access control, API and GraphQL testing.
View servicePENETRATION TESTING
Penetration tests at SEKurity are hand-driven, targeted engagements carried out by certified offensive specialists. No scanner dumps, no inflated lists without context. Every finding is reproducible, prioritised and paired with a concrete mitigation.
01 · SCOPING
We choose scoping by attack reality, not marketing. Blackbox for pure perimeter validation, greybox for most projects (tested with standard user accounts) and whitebox where source-code and architecture access materially improve value. The decision is made in a technical kick-off together with your team.
02 · DELIVERABLES
Every engagement ends with a report: management summary, technical findings with request/response evidence, CVSS rating, reproduction steps and recommended fixes. On top of that, a technical debrief with development and operations. Retests of closed findings are available as a separately priced add-on.
03 · SERVICES
OWASP Top 10, authentication, access control, API and GraphQL testing.
View serviceiOS and Android, static and dynamic, MASVS/MASTG-aligned.
View serviceExternal attack surface, VPN appliances, mail, DNS, subdomain hygiene.
View serviceInternal network, segmentation, lateral movement, privilege escalation.
View serviceKerberos, ACL abuse, ADCS ESC1-11, delegation, Tier-0 containment.
View serviceNetWeaver, S/4HANA, RFC/Gateway, critical roles, transport system.
View serviceLooking for a provider based in Germany? We are based in Düsseldorf and test across Germany and Europe — on site where you want us there. Cyber security Düsseldorf
04 · SECTORS
We sort by what actually drives a test rather than by industry classification: which systems are exposed, who works on them, and which regulation has a say. Five patterns recur across sectors and countries often enough that we raise them during scoping as a matter of course.
Mechanical engineering, manufacturing, automotive suppliers. Networks grown over decades, where office IT and production were never cleanly separated: scope is decided by segmentation, remote maintenance access and what may be touched while the line is running.
Municipal utilities (Stadtwerke), energy suppliers, water and wastewater, hospitals, banks and insurers. Here KRITIS, NIS-2 and DORA prescribe the depth of testing and the form of evidence — which of them applies belongs in the quote, not in the report.
Municipalities, authorities, universities and their IT service providers. Many specialist applications from many vendors, citizen data and narrow maintenance windows: the test follows the interfaces between those applications, not the org chart.
Software houses and platform operators whose product is the attack surface. Tenant separation, authentication and API permissions decide the scope; the CRA adds evidence across the entire product lifecycle.
Retail, logistics, law firms and anyone with many locations or suppliers on the network. The shortest way in is rarely the web application here — it is an access path somebody else administers.
The list excludes no one: scope follows the attack surface, not the industry classification. If your case is not listed, we place it during the initial call.
NEXT STEP
A 30-minute call with a test lead is enough to realistically outline scope, timing and depth. No sales round, just a technical pre-alignment.