From €2,000 · Fixed quote

Penetration testing in Cádiz

An authorised security test that attempts to exploit real vulnerabilities the way an attacker would, following open methodologies: OWASP WSTG, PTES and NIST SP 800-115.

Get my free audit

What's included?

  • Reconnaissance and enumeration of the entire agreed attack surface.
  • Controlled exploitation of vulnerabilities, always with written authorisation.
  • Technical report with CVSS severity and responsible proof of concept (PoC).
  • Executive report for management, in business language.
  • Prioritised remediation plan and a verification re-test after the fixes.

Who is it for?

For businesses with a web application, API, network or critical infrastructure that need real evidence of their security level or to prepare for a certification (ENS, ISO 27001, NIS2).

How we run a pentest

  1. 01

    Discovery

    Passive and active reconnaissance of the agreed surface: services, versions and entry points.

  2. 02

    Analysis

    Identification of vulnerabilities and manual validation, discarding false positives.

  3. 03

    Exploitation

    Controlled exploitation attempts to measure real impact without disrupting the service.

  4. 04

    Post-exploitation

    Assessment of real reach: privilege escalation and lateral movement within the agreed limits.

  5. 05

    Report and re-test

    Technical and executive delivery, remediation plan and a verification re-test after the fixes.

Testing modes

  • Black box: simulates an external attacker with no prior information.
  • Grey box: with credentials or partial documentation; the most realistic scenario.
  • White box: with access to code and architecture for maximum coverage.

What we can test

  • Web applications and APIs, following OWASP WSTG.
  • External and internal networks, segmentation and exposed services.
  • Active Directory and privilege-escalation paths.
  • Cloud environments (Azure, AWS, GCP) and identities.
  • Mobile and desktop applications.

Deliverables

  • Technical report with CVSS severity, evidence and proof of concept (PoC).
  • Executive report for management in business language.
  • Remediation plan prioritised by risk and effort.
  • Verification re-test after the fixes are applied.

We answer your questions before we start

Will you take down my production?

No. We work in agreed windows with safe techniques. Destructive tests are documented as risk, not executed against production.

How long does a pentest take?

A medium web application takes 1 to 2 weeks. An infrastructure with an internal network and Active Directory, 2 to 4 weeks. We fix it in the scope before starting.

Is it valid as evidence for a certification?

Yes: the report is technical evidence for ENS, ISO 27001, NIS2 or PCI DSS. That said, we don't issue certificates; that is up to an accredited body.

When was your last pentest?

Start with the free OSINT audit and we'll scope the pentest with a fixed quote.

Get my free audit