PENETRATION TESTING

Attacks that aretraceableand documented.

Penetration tests at SEKurity are hand-driven, targeted engagements carried out by certified offensive specialists. No scanner dumps, no inflated lists without context. Every finding is reproducible, prioritised and paired with a concrete mitigation.

01 · SCOPING

Black, grey and whitebox. Discussed openly.

We choose scoping by attack reality, not marketing. Blackbox for pure perimeter validation, greybox for most projects (tested with standard user accounts) and whitebox where source-code and architecture access materially improve value. The decision is made in a technical kick-off together with your team.

02 · DELIVERABLES

A report you can defend internally.

Every engagement ends with a report: management summary, technical findings with request/response evidence, CVSS rating, reproduction steps and recommended fixes. On top of that, a technical debrief with development and operations. Retests of closed findings are available as a separately priced add-on.

03 · SERVICES

Six disciplines, one quality standard.

Web Application Tests

OWASP Top 10, authentication, access control, API and GraphQL testing.

View service

Mobile App Tests

iOS and Android, static and dynamic, MASVS/MASTG-aligned.

View service

Perimeter Tests

External attack surface, VPN appliances, mail, DNS, subdomain hygiene.

View service

Infrastructure Tests

Internal network, segmentation, lateral movement, privilege escalation.

View service

Active Directory Tests

Kerberos, ACL abuse, ADCS ESC1-11, delegation, Tier-0 containment.

View service

SAP Security Tests

NetWeaver, S/4HANA, RFC/Gateway, critical roles, transport system.

View service

Looking for a provider based in Germany? We are based in Düsseldorf and test across Germany and Europe — on site where you want us there. Cyber security Düsseldorf

04 · SECTORS

Five patterns that decide what gets tested.

We sort by what actually drives a test rather than by industry classification: which systems are exposed, who works on them, and which regulation has a say. Five patterns recur across sectors and countries often enough that we raise them during scoping as a matter of course.

  1. 01

    Production & OT

    Mechanical engineering, manufacturing, automotive suppliers. Networks grown over decades, where office IT and production were never cleanly separated: scope is decided by segmentation, remote maintenance access and what may be touched while the line is running.

  2. 02

    Regulated operators

    Municipal utilities (Stadtwerke), energy suppliers, water and wastewater, hospitals, banks and insurers. Here KRITIS, NIS-2 and DORA prescribe the depth of testing and the form of evidence — which of them applies belongs in the quote, not in the report.

  3. 03

    Public sector

    Municipalities, authorities, universities and their IT service providers. Many specialist applications from many vendors, citizen data and narrow maintenance windows: the test follows the interfaces between those applications, not the org chart.

  4. 04

    Digital products & SaaS

    Software houses and platform operators whose product is the attack surface. Tenant separation, authentication and API permissions decide the scope; the CRA adds evidence across the entire product lifecycle.

  5. 05

    Many sites & supply chain

    Retail, logistics, law firms and anyone with many locations or suppliers on the network. The shortest way in is rarely the web application here — it is an access path somebody else administers.

The list excludes no one: scope follows the attack surface, not the industry classification. If your case is not listed, we place it during the initial call.

NEXT STEP

Let's talk about the concrete goal of your next pentest.

A 30-minute call with a test lead is enough to realistically outline scope, timing and depth. No sales round, just a technical pre-alignment.