Penetration Testing (PenTest)

A penetration test is an authorized, controlled attack on your systems, carried out by security experts to find the weaknesses a criminal would use. It shows what an outsider, or a rogue insider, could actually reach: customer data, payment systems, administrator accounts. Learning this from a test costs far less than learning it from an incident or a regulator.

How is this different from a vulnerability scan?

A vulnerability assessment is mostly automated. Software checks your systems against a list of known weaknesses and produces a ranked list. A penetration test goes further. Experienced testers take those weaknesses, combine them and try to break in, the way a real attacker would. The result separates the problems that are genuinely dangerous from the ones that only look bad on paper.

If you want both in one engagement, see our VAPT service.

When organizations ask for one

Most clients come to us at a specific moment:

  • a new application, channel or core system is about to go live
  • a regulator, auditor or certification body wants evidence of independent testing
  • a large customer or partner has sent a security questionnaire
  • there has been an incident or a near miss, and management wants to know what else is exposed
  • the yearly testing cycle in the security policy is due

What can be tested

We agree the targets with you before any testing starts. Common choices are:

  • Internet-facing systems such as websites, portals, firewalls and API gateways (the connection points other systems use to exchange data). The question here is what an unknown outsider can achieve.
  • The internal network. We assume an attacker already has a foothold, for example through a phished laptop, and see how far they can move. This usually includes Active Directory, the system that controls staff logins and permissions.
  • Web applications and APIs, including flaws in business logic, such as one customer being able to open another customer’s records.
  • Mobile apps on iOS and Android.
  • Cloud accounts on AWS, Azure and Google Cloud, including identity settings and configuration.

What you receive

The written report has two parts. The executive summary explains in plain English what was found, what it would mean for the business and what to fix first. The technical section gives your IT team each finding with evidence, a CVSS score (the standard 0 to 10 scale for rating a weakness’s severity) and clear steps to fix it. Findings are also mapped to ISO/IEC 27001:2022, SOC 2, PCI DSS, GDPR and NIST CSF, so your compliance team can reuse the work.

The report is delivered within 10 business days of testing. Retest included: once your team has fixed the issues, we test them again and confirm which ones are closed.

Testing for banks and card payments in Asia-Pacific

Banks and payment companies across Asia-Pacific often test because PCI DSS asks for it. Under PCI DSS v4.0.1, requirements 11.4.2 and 11.4.3 call for internal and external penetration testing at least once every 12 months and after any significant upgrade or change. Requirement 11.4.4 asks that exploitable weaknesses are corrected and the test is repeated to confirm the corrections.

We plan the yearly test and the tests that follow major changes with you, so each one has a clear scope and date. Each finding in the report is mapped to the PCI DSS requirement it affects, next to ISO/IEC 27001:2022 and SOC 2. Your auditors can trace every finding from evidence to fix without your team rebuilding the work.

How the engagement runs

It starts with a free 90-minute scoping session. An NDA is available before you share details. Together we agree the targets, testing windows, anything that is off-limits and who to call if something unexpected happens. The length of the test depends on how many systems are in scope, and it is fixed in the proposal.

Testers then map what is exposed and look for weaknesses, using tools such as Burp Suite, Nessus and Nmap alongside manual work. Every finding is checked by hand before it goes into the report, which keeps false alarms out.

Where a weakness looks serious, testers try to exploit it within the agreed limits to show its real impact. On internal tests this can include trying to gain administrator rights and seeing whether your security monitoring team notices.

Notes for the technical team

Testing follows PTES (the Penetration Testing Execution Standard), NIST SP 800-115, OWASP WSTG, OWASP ASVS and OWASP MASVS. Attack paths are mapped to MITRE ATT&CK, a public catalogue of real attacker techniques, and findings also carry an OWASP Risk Rating. Snipeyes is a CREST Member and an ISO/IEC 27001:2022 certified company.

Request a penetration testing proposal. A scoped proposal follows within 24 hours, with the scope, rules and timing set out.