ZW-Labs · Penetration testing

Every way in.
We try it first.

Hands-on testing of the systems your business runs on. Every finding comes with evidence and a specific fix, and we retest once you've fixed it.

Most cloud breaches start with a setting, not an exploit. We find the ones that actually lead somewhere.

What we look at

  • Over-privileged roles and trust policies
  • Public storage, snapshots and shared links
  • Exposed services and network paths
  • Kubernetes and container configuration
  • Secrets in pipelines and instance metadata
Example findingcritical

A CI role can assume the production admin role

Mapped to

  • CIS Benchmarks
  • SOC 2
  • ISO 27001
  • HIPAA
Quote for cloud →

How it runs

Scope, test, report, retest.

Nothing is touched until scope and written authorisation are agreed.

  1. Before we start

    Scope

    We agree targets, test accounts, timing and rules of engagement. You sign a written authorisation.

  2. During the test

    Test

    Hands-on testing. Anything critical comes to you the day we find it, not in the final report.

  3. When testing ends

    Report

    An executive summary for leadership, and every finding with evidence, severity and a specific fix.

  4. When you're ready

    Retest

    We verify each fix and reissue the report showing what's closed — ready for auditors and customers.

Questions

Before you book.

How long does a test take?Open +

It depends on scope. A focused web or API test is usually one to two weeks of testing. You get a timeline with the proposal, before anything is agreed.

What do you need from us?Open +

What's in scope, test accounts where relevant, a testing window, and a signed authorisation. We send a short scoping questionnaire to make it quick.

Will it affect production?Open +

We agree the environment and any excluded actions first. A staging copy of production is preferred; where we must test production, destructive checks are excluded or scheduled with you.

Can the report support SOC 2, ISO 27001, PCI DSS or HIPAA?Open +

Yes — it's structured to serve as independent testing evidence. Certifying compliance is your auditor's job; we give them what they need from a test.

Tell us what needs testing — or watching.

Get a quote →