// Approach

Careful, coordinated and built on recognized standards.

A penetration test should improve your security — never put your business at risk. Here’s how we plan, perform and report every engagement.

// Methodology

Recognized frameworks. Real-world tradecraft.

Our testing is grounded in industry standards, and our techniques reflect how real attackers operate today.

PTES & NIST SP 800-115

The structure for every engagement: pre-engagement, intelligence gathering, threat modeling, exploitation, post-exploitation and reporting.

OWASP Testing Guide

The basis for web application and API testing, covering the OWASP Top 10 and far beyond it.

MITRE ATT&CK

Findings are mapped to ATT&CK techniques so your team understands each step in the context of a real attack.

// Rules of engagement

No surprises.

Before any testing begins, we agree in writing on exactly what’s in scope, what’s off-limits, when testing happens and how we’ll communicate.

  • Written authorization and a signed scope before testing
  • Agreed testing windows and emergency contacts
  • No destructive or denial-of-service techniques without explicit approval
  • Immediate notification of critical findings
  • Testing traffic from documented source IPs

// Data handling

Your data stays protected.

Penetration testers see sensitive information. We treat it with the same care we’d expect from our own vendors.

  • Access only to what’s needed to demonstrate impact
  • Evidence and reports stored and transferred encrypted
  • Reports shared only with your designated contacts
  • Client data securely destroyed at the end of the agreed retention period
  • NDAs available on request

// Engagement lifecycle

What to expect, step by step.

Scoping call

We learn about your environment, goals and constraints, then send a fixed-price proposal.

Kickoff

Rules of engagement are signed, access is set up and the testing window is confirmed.

Testing & updates

Testing proceeds as planned with regular check-ins and immediate escalation of critical issues.

Report, debrief & retest

You receive the report, we walk through it together, and we retest remediated findings.

// FAQ

Frequently asked questions

What’s the difference between a vulnerability assessment and a penetration test?

A vulnerability assessment identifies and validates known weaknesses across your environment — it’s broad. A penetration test actively exploits weaknesses and chains them together to show what an attacker could really achieve — it’s deep. Many businesses start with an assessment and add a pentest annually.

How much does a penetration test cost?

Pricing depends on scope: the number of hosts, applications, user roles and locations. After a short scoping call you receive a fixed-price proposal, so there are no surprises or hourly overruns.

How often should we test?

At least annually, and after significant changes such as a new office, a major application release, a migration or an acquisition. Many organizations add quarterly vulnerability assessments between annual pentests.

Will testing disrupt our business?

Testing is planned around your operations. We agree on timing and off-limits systems in advance, avoid destructive techniques unless explicitly approved, and stay in contact throughout.

Does a pentest help with compliance and cyber-insurance?

Yes. Penetration testing supports requirements and expectations in frameworks such as PCI DSS, the FTC Safeguards Rule (GLBA), HIPAA, SOC 2 and many cyber-insurance applications. We provide an attestation letter alongside the full report.

Do you work with our MSP or IT provider?

Absolutely. We coordinate with internal IT and managed service providers, and remediation guidance is written so they can act on it directly.

Do you test remotely or on-site?

Most testing is performed remotely. On-site work is available in Southwest Michigan and the surrounding region when the engagement calls for it.

What do you need from us to get started?

A brief scoping conversation, a point of contact, and — once the proposal is accepted — signed authorization and the access needed for the agreed scope.

// Next step

Know where you stand before someone else finds out.

Start with a no-obligation scoping call. We’ll talk through your environment, what’s driving the test and the timeline that works for you.