Scope and test type
Black box with no prior knowledge, grey box with test accounts for each role, or white box with access to the code. For most applications we recommend grey box, as it finds the most for the same budget.
We agree the scope together. For web applications and their surroundings, these are the usual focal points.
Black box with no prior knowledge, grey box with test accounts for each role, or white box with access to the code. For most applications we recommend grey box, as it finds the most for the same budget.
Horizontal and vertical privilege escalation: can a customer see others' data, can a basic user reach admin functions, do disabled accounts still work?
Password rules, second factor, password reset, session lifetime and single sign-on via Entra ID or ID Austria where used.
Injection into database and operating system, cross-site scripting, crafted files and parameters that alter prices, quantities or customer numbers.
Whether the API itself enforces who may do what, whether it limits request rates and whether the app stores secret keys on the device.
Reachable admin consoles, outdated components, missing security headers, open cloud storage and forgotten test systems.
Every finding with a CVSS score, evidence and a suggested fix, a management summary, and confirmation once issues are resolved.
Nothing starts without signed authorisation. You receive our IP addresses beforehand so your team can recognise us in the logs.
Scope, test type, time window, emergency contacts and the owner's authorisation, plus the host's where systems are hosted externally.
Mapping the attack surface and manual probing with tools such as Burp Suite, with no denial of service and no changes to real data.
Delivered encrypted to named recipients and walked through over video with developers and management.
Checking the fixes and issuing a final confirmation for your records.
A vulnerability scan is not a penetration test. Scanners find known holes in outdated software and missing settings, which is valuable. But they have no idea that customer A must never see customer B's data. Those logic errors are what make the difference, and only someone examining the application by hand, as an attacker would, will find them.
Because attacking someone else's systems without permission is a criminal offence, however well meant. Consent must come from the real owner. If the system runs with a host or service provider, we obtain their agreement as well.
We steer clear of destructive techniques, but some residual risk comes with any test. That is why we prefer a test environment. On live systems we only work within the agreed window and with a current backup.
No. You receive a report covering scope, methodology and findings, and a confirmation after the retest. That normally satisfies customers, insurers and ISO 27001 auditors.
At least annually and after major changes, such as a new interface, a new login method or a move to the cloud. For essential and important entities under NIS2, it can be one element of the required risk management.
Like a master key. It explains how to get in. Keep the circle of recipients small and do not put it in widely shared folders until every finding has been fixed.
Describe the application, its user roles and who owns it. We will suggest scope, test type and a schedule.
Your enquiry has arrived
Our reply reaches you within one working day. Outages that leave your staff unable to work are dealt with first.
We could not find that town. Try another spelling, or choose whichever provincial capital lies closest; as everything is handled remotely, you get the same service in all nine Austrian states.