OF-01Manual validation
External penetration testing
What an attacker would see, and achieve, from the Internet.
We simulate real attacks from outside the organisation: networks, web applications, APIs and Internet-facing servers. We identify firewall weaknesses, misconfigurations and exploitable vulnerabilities, and validate every finding by hand with reproducible evidence and specific recommendations.
What's included
- Reconnaissance and mapping of the exposed surface
- Vulnerability analysis with manual validation
- Controlled exploitation, with no denial of service
- Review of web applications and APIs (OWASP Top 10)
- Remediation plan prioritised by risk
Deliverables
- Executive report
- Technical report
- Results presentation session
- Retest of findings
OF-02Manual validation
Internal penetration testing
What happens once the attacker is already inside.
Simulates an attack from inside the corporate network: a compromised laptop, a malicious employee or an unmanaged device. We assess servers, workstations, network devices, Active Directory and permissions, plus segmentation and privilege control, to minimise the risk of lateral movement. Delivered entirely remotely, with our probe or a machine provided by the organisation.
What's included
- Enumeration of the internal network and Active Directory
- Privilege escalation and controlled lateral movement
- Review of segmentation and access control policies
- Analysis of workstations, servers and network devices
- Recommendations to strengthen internal security
Deliverables
- Executive report
- Technical report
- Results presentation session
- Retest of findings
OF-03Manual review of critical flows
Source code review
Vulnerabilities caught before they reach production.
Security review of application and service source code, combining automated analysis with manual review of the critical parts: authentication, session management, input handling, cryptography and access control. We detect embedded secrets, vulnerable dependencies and insecure patterns, with fix examples for the development team.
What's included
- Static analysis of the code and its dependencies
- Detection of embedded secrets, keys and credentials
- Manual review of the critical flows
- A fix recommendation per finding, with examples
Deliverables
- Technical report with findings by file and line
- Session with the development team
- Retest of the fixed version
OF-04Controlled simulation
Man-in-the-middle simulation
Can someone listen to, or alter, your company's communications?
Man-in-the-middle attacks remain one of the most common threats on corporate networks. We run controlled simulations to assess how vulnerable your communications are: Wi-Fi security, authentication protocols and data encryption. The report includes concrete solutions such as VPNs, digital certificates and stronger policies.
What's included
- Audit of corporate and guest Wi-Fi networks
- Traffic interception and service spoofing tests
- Review of authentication and encryption protocols
- Mitigation measures: VPN, certificates and policies
Deliverables
- Technical report
- Mitigation guide
- Results presentation session
OF-05Training included
Phishing simulation
The human factor, measured and trained.
We design simulated phishing campaigns that replicate the techniques real cybercriminals use, and measure open, click and credential-submission rates by department. Then we provide training to improve the security culture and prevent real incidents.
What's included
- Scenarios tailored to the company
- Campaigns by email and messaging
- Metrics by department: opens, clicks and credentials
- Follow-up awareness training
Deliverables
- Results report with metrics
- Awareness session
- Training material
OF-06Continuous service in TORO
Continuous attack surface discovery
Your exposure changes every week. We keep watch.
A pentest is a photograph; the attack surface is a film. This recurring service periodically identifies every exposed resource of the organisation (domains, subdomains, IP addresses, services, certificates and applications), both those the organisation knows about and those discovered during reconnaissance. Every new asset or relevant change is analysed and reported, and the full picture can be checked at any time in TORO.
What's included
- Inventory of exposed assets and shadow IT
- Detection of new domains, services and ports
- Monitoring of certificates, technologies and vulnerable versions
- Alerts on changes and critical exposures
Deliverables
- Attack surface dashboard in TORO
- Alerts on changes
- Periodic exposure report