Home / Services

Penetration Testing

Technical diagram of the penetration testing process: scope definition, manual testing, evidence collection and findings ranked by risk

What is a Penetration Test (Pentest)?

A Penetration Test, or Pentest, is an assessment carried out by information security professionals, also known as pentesters or ethical hackers, in which an authorised simulated attack is performed against the networks, systems and applications of the contracting company.

Pentest Approaches

Every organisation has different goals, requirements and scenarios when hiring a Penetration Test. For that reason there are different approaches, varying according to how much information is shared with the specialists before the assessment begins.

Black Box Pentest

In a Black Box Pentest our specialists start the assessment without any privileged information about the environment. The goal is to reproduce the scenario of an external attacker who tries to identify, exploit and compromise systems using only publicly available information.

This approach shows which vulnerabilities could be exploited by an attacker with no prior access to the company infrastructure, realistically simulating attacks launched from the Internet.

Grey Box Pentest

In a Grey Box Pentest part of the information is provided by the company, such as access credentials, limited documentation or details about specific systems.

This approach reduces the time spent on reconnaissance and allows the effort to be concentrated on identifying the most relevant vulnerabilities, providing broader test coverage and more efficient results. For that reason it is the approach most often recommended by MTR Cyber Sec for Web applications, APIs, mobile applications, Cloud environments and most corporate projects.

White Box Pentest

In a White Box Pentest the specialists have extensive knowledge of the environment before the assessment begins. Depending on the scope, architecture diagrams, technical documentation, privileged credentials and even application source code may be made available.

This approach provides an extremely deep analysis of the attack surface and is suited to detailed security reviews, validations during software development and projects that require the highest possible level of technical coverage.

Whichever approach is chosen, the goal remains the same: identifying vulnerabilities before they can be exploited by an attacker. The most suitable methodology is defined considering the goals of the assessment, the project scope and how much information the company is able to share.

Why hire this service?

A Penetration Test helps companies identify vulnerabilities so they can be fixed before attackers exploit them and cause serious damage to the organisation. A cyber attack can lead to the following impacts:

  • Financial loss;
  • Lawsuits and fines;
  • Service disruption;
  • Data theft and leakage;
  • Scams and fraud;
  • Ransomware;
  • Loss of credibility;
  • Reputational damage.

How much does a Pentest cost?

The cost of a Pentest varies according to the scope of the assessment. There is no single price for this service, because every environment has its own characteristics, technologies and goals.

Before preparing the commercial proposal we carry out an initial survey of the information needed to understand the environment and define a scope that matches the needs of the company.

Type of assessment

The first factor considered is the type of environment to be assessed. The scope may involve Web applications, APIs, mobile applications (Android and iOS), internal and external infrastructure or cloud environments such as Amazon Web Services (AWS), Microsoft Azure and Google Cloud Platform (GCP).

Each technology has its own characteristics and requires specific methodologies to ensure a proper technical assessment.

Size of the environment

The number of applications, APIs, servers, devices, features and access profiles directly influences the effort required to run the tests.

Larger projects usually require more assessment time to ensure adequate coverage of the environment.

Complexity of the environment

Beyond the number of assets, the complexity of the environment also influences the scope. Applications with multiple user profiles, different access levels, integrations between systems and critical features usually require a more detailed analysis.

For that reason each project is analysed individually to define a scope that matches the characteristics and the goals of the company.

Approach used

The approach chosen for the assessment also influences project planning. Tests carried out as Black Box, Grey Box or White Box have different goals and may require different levels of preparation and execution.

The approach is defined together with the client, considering the goals of the assessment and the scenario to be reproduced.

How to request a quote

To prepare a suitable proposal, our team first collects the main information about the environment, such as the type of application or infrastructure, the number of assets involved, the goals of the assessment, the desired approach and the expected timeframe.

After that survey we prepare a technical and commercial proposal with no obligation, matching the scope and the needs of the company.

Get in touch with our team to request an initial review of your environment and receive a technical and commercial proposal with no obligation, matching the scope and the needs of your company.

Professional Report with Results

At the end of the assessment we deliver a technical report and an executive report containing everything the company needs to understand the risks identified and prioritise remediation.

The report includes:

  • All vulnerabilities identified;
  • Severity rating (Critical, High, Medium, Low or Informational);
  • Technical evidence of each vulnerability found;
  • Description of the business impact;
  • Clear remediation recommendations;
  • References to security best practices.

Penetration Test Attestation Letter

Alongside the technical report we provide a Penetration Test Attestation Letter, a formal document certifying that the security assessment was carried out following industry best practices.

This document attests that:

  • the Pentest was carried out by qualified specialists;
  • the tests followed internationally recognised methodologies;
  • the results presented reflect the vulnerabilities identified during the assessment.

The Attestation Letter can be used as evidence in compliance processes, security audits, vendor approval and with business partners or clients that request proof the Pentest was performed.

Who else hires a Pentest?

Companies across many industries use Penetration Testing to reduce risk, strengthen the security of their environments and meet regulatory requirements.

The main sectors include:

  • Banks and Fintechs: high financial volume and requirements related to BACEN, PCI DSS and data protection laws.
  • Hospitals, Clinics and Healthcare Companies: protection of sensitive patient data and high exposure to attacks.
  • Technology and Software Companies: systems used by clients and partners, where security is part of the product itself.
  • E-commerce and Marketplaces: storage of customer data and payment information, making them frequent fraud targets.
  • Public Sector and Government: protection of critical infrastructure and strategic data.
  • Educational Institutions: large volumes of student, staff and researcher data.
  • Logistics, Transport and Industry 4.0: growing use of automation, connected systems and IoT devices.
  • Companies seeking certifications: organisations working towards compliance with standards such as ISO 27001, SOC 2, PCI DSS and other security requirements.
  • Law and Accounting Firms: handling of highly confidential client and partner information.

Where does your company fit?

If your company handles sensitive data, digital infrastructure, Web applications, APIs, mobile applications, Cloud environments or any Internet-facing service, a Pentest is one of the most effective ways to identify vulnerabilities before they can be exploited by criminals.

Regardless of company size or industry, investing in periodic security assessments helps reduce risk, strengthen asset protection and increase the confidence of clients, partners and suppliers.

Get in touch with our team to request an initial review of your environment and receive a technical and commercial proposal with no obligation, matching the scope and the needs of your company.