Services · Cybersecurity · Penetration testing

Penetration testing & vulnerability assessment

Find your gaps before someone else does. You get a tested, evidenced view of what an attacker can actually reach in your environment, ranked by what it would cost your business, with fixes your team can start on this quarter.

01 — Who this is for

Four reasons teams come to us first.

nexaya engineers reviewing a cybersecurity engagement
01

Preparing for a certification

ISO 27001 or SOC 2 both require evidence of testing — not just a policy that says you do it.

02

A client or regulator asked

Some contracts and audits require a penetration test report on file, not just a vulnerability scan.

03

You shipped something new

A new platform went live and nobody outside the build team has tried to break it.

04

It's been over a year

In practice, that means you have not been tested. Threats and your environment have both moved on.

02 — What we do

Six angles. One coordinated test.

  • 01External testing. Everything an attacker can see from the internet: perimeter, exposed services, forgotten subdomains, and credentials of yours already circulating in breach data.
  • 02Internal testing. What happens after one laptop is compromised — lateral movement, privilege escalation, and how far a foothold travels before something stops it.
  • 03Web & API testing. Against the OWASP Top 10 and the OWASP API Security Top 10, including business logic flaws that scanners never find.
  • 04Mobile application testing. Android and iOS, including how the app stores data and talks to your backend.
  • 05Cloud configuration review. Identity, storage exposure, network segmentation, and logging across AWS, Azure, and Google Cloud.
  • 06Social engineering, on request. Phishing and pretexting, scoped and authorised in writing before anything is sent.
03 — What you receive

A report built to be checked, not taken on faith.

  • 01An executive summary your board can read in five minutes, written in business risk rather than CVE numbers.
  • 02A technical report with reproduction steps, evidence, and CVSS scoring for every finding.
  • 03A remediation roadmap ordered by exploitability and business impact, with effort estimates so your team can plan sprints against it.
  • 04A free retest of every critical and high finding, at no extra cost, within 90 days.
  • 05An attestation letter you can send to clients, auditors, and regulators.
04 — Standards we test against

One test, several obligations satisfied.

OWASP Top 10 OWASP ASVS PTES NIST SP 800-115 MITRE ATT&CK

Findings are mapped to ISO 27001 Annex A controls and, where relevant, to the national requirements that apply in your market — so one test feeds several compliance obligations instead of one.

05 — Timeline & engagement

How long it takes, by scope.

ScopeTypical durationReport delivered
External perimeter 5 working days Within 5 working days of test close
Web application or API 5 – 10 working days Within 5 working days
Internal network 10 – 15 working days Within 7 working days
Full-scope programme 15 – 25 working days Within 10 working days

Testing windows are agreed around your operating hours. Where infrastructure will not tolerate load, we say so at scoping and adjust the method rather than risk your production environment.

06 — Frequently asked questions

Straight answers, before you ask.

What's the difference between a vulnerability assessment and a penetration test?

A vulnerability assessment scans for known weaknesses. A penetration test has an engineer actively try to exploit them, the way a real attacker would. Ours combines both in one engagement.

How long does a penetration test take?

An external perimeter test typically takes 5 working days. A full-scope programme — external, internal, web/API, and cloud — runs 15 to 25 working days, depending on scope.

Do you test production environments?

Yes, on request, with testing windows agreed around your operating hours. Where infrastructure will not tolerate load, we say so at scoping and adjust the method rather than risk your production environment.

What do we receive at the end of the test?

An executive summary for your board, a technical report with reproduction steps and CVSS scoring, a prioritised remediation roadmap, a free retest of every critical and high finding within 90 days, and an attestation letter for clients, auditors, and regulators.

Which standards do you test against?

OWASP Top 10, OWASP ASVS, PTES, NIST SP 800-115, and MITRE ATT&CK — with every finding mapped to ISO 27001 Annex A and the national framework that applies in your market.

Book this test

See what an attacker can reach.

Same NDA, same named engineer, same report format described above — scoped to penetration testing and vulnerability assessment. No cost, no obligation.

Talk to the engineer who would run this test →

Penetration testing & vulnerability assessment.

Mutual NDA signed first. Findings stay yours.

One business day. From a named engineer, not a salesperson.

Request received.

A named engineer will reply within one business day to scope the NDA and the test window.