ZW-Labs · Penetration testing
Every way in.
We try it first.
Hands-on testing of the systems your business runs on. Every finding comes with evidence and a specific fix, and we retest once you've fixed it.
From the internet we find what's exposed. From inside we show how far one compromised laptop gets.
What we look at
- Exposed services and remote-access gateways
- Segmentation between networks
- Active Directory attack paths
- Credential exposure and lateral movement
- Wireless, on request
A backup service account's password is crackable offline
Mapped to
- PTES
- NIST SP 800-115
- SOC 2
- PCI DSS
How it runs
Scope, test, report, retest.
Nothing is touched until scope and written authorisation are agreed.
Before we start
Scope
We agree targets, test accounts, timing and rules of engagement. You sign a written authorisation.
During the test
Test
Hands-on testing. Anything critical comes to you the day we find it, not in the final report.
When testing ends
Report
An executive summary for leadership, and every finding with evidence, severity and a specific fix.
When you're ready
Retest
We verify each fix and reissue the report showing what's closed — ready for auditors and customers.
Questions
Before you book.
How long does a test take?Open +
It depends on scope. A focused web or API test is usually one to two weeks of testing. You get a timeline with the proposal, before anything is agreed.
What do you need from us?Open +
What's in scope, test accounts where relevant, a testing window, and a signed authorisation. We send a short scoping questionnaire to make it quick.
Will it affect production?Open +
We agree the environment and any excluded actions first. A staging copy of production is preferred; where we must test production, destructive checks are excluded or scheduled with you.
Can the report support SOC 2, ISO 27001, PCI DSS or HIPAA?Open +
Yes — it's structured to serve as independent testing evidence. Certifying compliance is your auditor's job; we give them what they need from a test.
Tell us what needs testing — or watching.
Get a quote →