What to know before a pentest
Guides written by the team that does the testing: how to prepare, what it costs, what regulations require and what each vulnerability category means.
Preparation, cost, choice
How to prepare for a pentest
Scope, environment, test accounts and rules of engagement, settled before testing starts.
What a pentest costs
What drives the price: scope, type of test, level of access — and how to compare two quotes fairly.
Pentest or vulnerability scan?
What an automated scanner finds, what only a person finds and when you need each.
What we look for and what regulations require
OWASP Top 10 guide
The ten OWASP categories explained with real examples: what they mean, what they look like and how to fix them.
Moldova’s cybersecurity law
The Republic of Moldova’s cybersecurity law: who it applies to and which measures it requires.
NIS2 and GDPR
How to demonstrate NIS2 (Art. 21) and GDPR compliance through penetration testing.
DORA and TLPT
The testing programme DORA requires of financial entities, including TLPT.
ISO 27001 and SOC 2
What ISO/IEC 27001:2022 and SOC 2 require for technical testing and which evidence the auditor accepts.
PCI DSS 4.0
The scanning (11.3) and penetration tests (11.4) PCI DSS 4.0 requires, and how segmentation is tested.
A question the guides do not answer?
Write to us; an engineer who does the testing replies within one business day.