ZW-Labs · Penetration testing

Every way in.
We try it first.

Hands-on testing of the systems your business runs on. Every finding comes with evidence and a specific fix, and we retest once you've fixed it.

From the internet we find what's exposed. From inside we show how far one compromised laptop gets.

What we look at

  • Exposed services and remote-access gateways
  • Segmentation between networks
  • Active Directory attack paths
  • Credential exposure and lateral movement
  • Wireless, on request
Example findinghigh

A backup service account's password is crackable offline

Mapped to

  • PTES
  • NIST SP 800-115
  • SOC 2
  • PCI DSS
Quote for networks →

How it runs

Scope, test, report, retest.

Nothing is touched until scope and written authorisation are agreed.

  1. Before we start

    Scope

    We agree targets, test accounts, timing and rules of engagement. You sign a written authorisation.

  2. During the test

    Test

    Hands-on testing. Anything critical comes to you the day we find it, not in the final report.

  3. When testing ends

    Report

    An executive summary for leadership, and every finding with evidence, severity and a specific fix.

  4. When you're ready

    Retest

    We verify each fix and reissue the report showing what's closed — ready for auditors and customers.

Questions

Before you book.

How long does a test take?Open +

It depends on scope. A focused web or API test is usually one to two weeks of testing. You get a timeline with the proposal, before anything is agreed.

What do you need from us?Open +

What's in scope, test accounts where relevant, a testing window, and a signed authorisation. We send a short scoping questionnaire to make it quick.

Will it affect production?Open +

We agree the environment and any excluded actions first. A staging copy of production is preferred; where we must test production, destructive checks are excluded or scheduled with you.

Can the report support SOC 2, ISO 27001, PCI DSS or HIPAA?Open +

Yes — it's structured to serve as independent testing evidence. Certifying compliance is your auditor's job; we give them what they need from a test.

Tell us what needs testing — or watching.

Get a quote →