What Is a Penetration Test and When Do You Need One?
A penetration test is an authorised, controlled attack against your own systems, run to discover the routes a real adversary could use to get in. The goal is not to produce a list of weaknesses but to prove whether those weaknesses can actually be exploited and how far an attacker could travel once inside.
Typical signals that an organisation needs a penetration test:
- You process customer data, payment details or personal data in an application.
- You are going through an ISO 27001 or PCI DSS audit and a current report is requested.
- You shipped a major release, a payment integration or an infrastructure change.
- An enterprise client requires independent security testing as a contract condition.
- You have never had an independent security assessment.
Our Testing Scope
Engagements follow OWASP Top 10, OWASP MASVS, NIST SP 800-115 and PTES. We include only the areas you actually need.
Web application penetration testing
Full coverage of SQL injection, XSS, CSRF, broken access control and IDOR, insecure file upload, session management flaws and business logic errors. Authenticated and unauthenticated roles are tested separately.
Mobile application penetration testing
Static and dynamic analysis for Android and iOS: reverse engineering resistance, insecure local storage, certificate pinning, root and jailbreak detection, and inspection of the API traffic behind the app.
API and web service testing
REST, SOAP and GraphQL assessment covering broken authentication and authorisation, BOLA and IDOR, excessive data exposure, missing rate limiting and injection.
Server and infrastructure assessment
Hardening review for Linux and Windows servers, exposed port and service analysis, missing patches, weak configuration and TLS settings.
Internal network and Active Directory
Controlled testing of privilege escalation, Kerberoasting, AS-REP roasting, lateral movement and full domain compromise scenarios.
Social engineering and phishing
Controlled phishing campaigns and staff awareness measurement that turn human-factor risk into a number. Results are reported at organisation level, never per individual.
Our Testing Process
The engagement is transparent, contractual and fully authorised.
1. Scoping and agreement
Target assets, the testing window and the rules of engagement are documented in writing and an NDA is signed. Systems that are out of scope are recorded with the same clarity.
2. Reconnaissance
Passive and active discovery maps your real attack surface: domains, subdomains, exposed services, technologies in use and leaked credentials.
3. Vulnerability analysis
Automated tooling and manual review are combined. Every finding is verified by hand and false positives are removed before they reach the report.
4. Exploitation
Controlled exploitation inside the approved scope. Where access is gained, impact and propagation are documented with screenshots and request logs.
5. Reporting and retest
The report is delivered, walked through with your team, and a verification retest is repeated free of charge after remediation.
What Is Inside the Report?
The report has two layers so that management and engineers can both use the same document.
- Executive summary: the overall risk picture in non-technical language, critical finding count and priority order.
- Finding detail: CVSS v3.1 score, affected endpoint, reproduction steps and evidence for every issue.
- Remediation guidance: concrete fixes your developers can apply directly to your stack.
- Verification method: the checks your own team can run to confirm a fix worked.
- Retest results: an updated closure table showing what was fixed and what remains open.
What Drives the Price
A fixed list price would be misleading; the same phrase "website test" can describe a five-page brochure site or a dealer portal with hundreds of screens. The cost drivers are:
- Scope size: number of IPs, domains, applications and screens.
- Testing model: black box (no information), grey box (user account provided), white box (source code shared).
- Role count: every privilege level is a separate workload.
- Scheduling: tests that must run out of hours or inside a maintenance window.
- Retest and advisory: support given to your developers during remediation.
Once the scope is agreed together we quote a fixed price with no surprises.
ISO 27001 and GDPR Alignment
A penetration test is not only technical work, it is also a compliance artefact. It is the most concrete evidence that technical vulnerability management is operating under ISO 27001, and that appropriate technical measures are in place for data protection under GDPR and Turkish KVKK. Our reports are written so they can be handed to an auditor; on request we also provide a scope letter and a retest closure statement.