Services — Penetration Testing

Penetration testing that goes beyond the scan.

Certified engineers manually attack your systems the way a real adversary would — then hand you a report your auditors, insurers, and board can act on. Testing typically starts within 1.5 weeks of engagement.

The difference

Where the scan stops, our testers start

Anyone can run a scanner and forward the PDF. A scan lists what might be wrong; a penetration test proves what an attacker can actually reach — by chaining findings together the way a real intrusion does.

What an automated scan returns
Known CVEs and missing patches
Open ports and exposed services
Weak TLS and configuration flags
A long list, unranked by real risk
Manual exploitationOSINT, hand reconnaissance, and certified engineers attempting real compromise
What our testers prove
Chained exploits that reach live data
Business-logic flaws no tool detects
Privilege escalation and lateral movement
Ranked findings with working evidence

Every finding is re-verified before it reaches your report — no false positives to chase down.

What we test

Penetration testing services for every attack surface

Eight testing disciplines, staffed today — scoped individually or combined into one engagement.

Network

Network penetration testing

Internal and external network infrastructure attacked with the same techniques a real adversary uses — from the open internet and from inside the perimeter.

Web

Web application penetration testing

Business logic, authentication, and injection flaws in your web apps that scanners can't see — found by hand and proven with evidence.

External

External penetration testing

Your internet-facing systems tested from an attacker's view of your perimeter — before someone else tests them for free.

Internal

Internal penetration testing

An assumed-breach scenario: what a malicious insider, or an attacker who's already in, could reach from inside your network and VPCs.

API

API penetration testing

Every facet of your APIs — auth, authorization, rate limits, data exposure — tested by engineers who build software, not just scan it.

Mobile

Mobile app penetration testing

Custom-built iOS and Android applications, tested for the storage, transport, and platform flaws unique to mobile.

Wireless

Wireless penetration testing

Weaknesses in your wireless networks discovered before they expose data beyond the physical perimeter.

IoT / SCADA

IoT & SCADA penetration testing

Embedded devices and industrial control systems, tested with the specialised techniques OT environments demand.

Ongoing

Vulnerability management

Between tests, continuous scanning, prioritisation, and patching guidance keep exposure down — delivered with our managed SOC.

Compliance-driven testing

The pen test your auditor is asking for

Most testing today has a deadline attached. We scope and report against the framework you're measured on, so the finding closes the first time.

HIPAA

HIPAA penetration testing

Testing and encryption validation scoped to ePHI systems for medical and dental practices — reported in the language OCR auditors expect. See identity security for healthcare.

SOC 2

SOC 2 penetration testing

The test your auditor expects to see during your observation window — mapped to the Trust Services Criteria and paired with our SOC 2 readiness assessment.

PCI-DSS

PCI penetration testing

Segmentation and application testing aligned to PCI-DSS requirements for anyone storing, processing, or transmitting card data — common across finance and retail.

Beyond the pen test

Red teaming & social engineering

Red team

Full red team assessment

A no-holds-barred simulated attack with the goal of an actual breach — reconnaissance, exploitation, lateral movement, and exfiltration — while your defenders detect and respond. The truest measure of how your security program performs under fire.

Human layer

Social engineering & attack simulation

Phishing and manipulation campaigns that test your people, and breach-and-attack simulation that continuously exercises your controls. Pairs naturally with security awareness training to turn results into behaviour change.

How we deliver

Signed to report in 3–5 weeks

Six stages on a timeline we commit to up front — and testing usually begins within 1.5 weeks of engagement. All times are business days.

1–3 days
1

Kickoff & scoping

Scope, rules of engagement, and timing confirmed.

2–5 days
2

Authorization

Signed authorization, access, and test accounts. No test starts without it.

3–10 days
3

Active testing

Manual, expert-driven exploitation — 2–4 weeks for larger scopes.

1–3 days
4

Validation

Every finding re-verified before it reaches the report.

3–5 days
5

Report

Delivered 1–2 weeks after testing ends, depending on scope.

30–60 min
6

Debrief

A readout call for leadership and engineers.

Deliverables

What you get at the end

A 25–50 page report with two audiences in mind: an executive summary your leadership can read without a translator, and technical findings your engineers can act on — severity-rated, with reproduction steps, screenshot evidence, and specific remediation guidance for every finding.

Then a debrief call within a week of delivery, walking both audiences through what matters most. Reports are delivered one to two weeks after testing ends, depending on scope.

Executive summarySeverity-rated findingsReproduction stepsEvidence & screenshotsRemediation guidanceDebrief call
After the fix

Retesting — and second opinions

Verify

Retest your fixes

Findings aren't closed until they're proven closed. We retest remediated findings and confirm the holes are actually gone — available as a follow-up engagement, often packaged with the original test at a lower cost.

Second opinion

Check another firm's work

Some clients come to us purely to retest a previous vendor's engagement — because a report full of green checkmarks is only reassuring if the testing behind it was real. If your last test felt too easy, that's worth a second look.

Why us

Why teams choose AppliedIAM for penetration testing

100% manual testing, not scanner reports

The scan is the starting point. Our testers combine its output with OSINT and manual reconnaissance, then attempt real exploitation — no tool-only PDFs with a logo on top.

Certified offensive engineers

Our testers hold OSCP, CRTE, GPEN, and CISSP, with OSCE/OSEP at senior level — the hands-on delivery certifications, not the checkbox ones.

Testing starts in ~1.5 weeks

Most firms quote two to four weeks before testing begins. We average a week and a half — which matters when an auditor has given you a date.

We help you fix what we find

Testing that ends at a PDF leaves you holding the risk. Our delivery teams can remediate findings with you — from access control to hardening.

Identity attackers, identity defenders

Most real intrusions run through stolen credentials and standing privilege. We attack that path in testing because we secure it every day in our privileged access management work.

Compliance-mapped reporting

Findings mapped to the framework you answer to — HIPAA, SOC 2, PCI-DSS, NIST — so reports close audit items instead of raising new questions.

OSCPOSCE / OSEPCRTEGPENCISSP

Testing aligned to: HIPAA · SOC 2 · PCI-DSS · NIST · GDPR

FAQ

Common questions about penetration testing

How much does a penetration test cost?
It depends on scope. A single small web application sits at the low end of the market; large multi-week engagements covering external, internal, and cloud environments run substantially higher. The biggest cost drivers are the number of systems and applications in scope, credentialed testing across multiple user roles, and compliance-driven depth for frameworks like PCI-DSS or HIPAA. We scope precisely before quoting, so you pay for the testing you need.
How long does a penetration test take?
Active testing runs 3–10 business days for a single application or network segment, and 2–4 weeks for larger scopes. End to end — from signed authorization to a delivered report — a mid-size engagement is typically 3–5 weeks, and we can usually begin testing within about a week and a half of engagement.
What's the difference between a penetration test and a vulnerability scan?
A vulnerability scan is automated: a tool lists known weaknesses. A penetration test is a certified engineer actually attempting to exploit them — chaining findings together, moving through your environment the way a real attacker would, and proving what is genuinely reachable. Auditors and frameworks like PCI-DSS and SOC 2 generally expect a manual penetration test, not just a scan.
How often should we run a penetration test?
At least annually, and after any significant change — a new application, a major infrastructure migration, or a merger. Compliance frameworks commonly require annual testing plus retesting after remediation. Many of our clients pair an annual full test with a smaller retest to verify fixes.
Will testing disrupt our production systems?
Testing is governed by written rules of engagement agreed before we start: exclusions, blackout windows, and a technical contact reachable during testing hours for stop-testing emergencies. Destructive techniques are never used against production without explicit sign-off. Disruption is rare and the safeguards exist precisely so it stays that way.
Compliance deadline?

See what an attacker would find — before one does.

Tell us your scope and the framework you're testing against. We'll come back with a precise quote and a start date — typically within 1.5 weeks.