External network
Assessment of the internet-facing attack surface, for the addresses and services in scope.
We assess the paths an attacker could use to access your company’s systems and data.
We deliver executive and technical reports and remediation solutions, with free retesting included.
We agree the scope, access and authorised testing window, then use the PenTest platform for the agreed scenarios.

Assessment of the internet-facing attack surface, for the addresses and services in scope.
Testing of attack paths within the internal infrastructure, with grey-box testing included and access agreed within the authorised scope.
Executive and technical reports, with the vulnerabilities identified and remediation recommendations.
The PenTest platform used by TRU includes AI features to summarise results and present their impact on the business.
We assess attack paths in the internal and external network, within the authorised scope. Findings are documented to show the access gained and the possible impact.
AI adds context to technical findings and helps present risks and remediation priorities in language that management can follow.
Human validation completes the assessment. Once the agreed measures have been applied, the included free retest verifies that the identified issues have been remediated.
Scenarios are selected according to the infrastructure and the scope agreed for the test.
Testing credential-related weaknesses and the access they can provide.
Assessing whether additional rights can be obtained after the initial compromise.
Identifying the paths an attacker could use to reach other systems on the network.
Checking the controls that restrict communications to external destinations.
Simulating and documenting access to resources that require additional protection.
Correlating the log of testing activities with existing security alerts and controls.
IP addresses, frequency, access and authorised conditions.
Testing through the PenTest platform within the agreed time window.
Reviewing the findings and setting remediation priorities.
Pricing starts from the number of IP addresses tested and the testing frequency. The final proposal specifies the agreed scope, access and schedule.
from €31 / IP per month
Attack paths inside the internal network, with grey-box testing included, within the authorised scope.
from €313 / IP, with monthly testing
The internet-facing exposure, for the addresses and services in scope.
Prices are in euros and exclude VAT.
after the scan finishes
A summary of the findings, the risks identified and the remediation directions.
The evidence obtained during the test, vulnerability details and recommendations for the technical team.
Testing performed under CREST accreditation — Council of Registered Ethical Security Testers.
Free retesting included. We verify the outcome of the remediation measures within the agreed scope and on the agreed date.
Demonstration examples: executive summary, technical findings and remediation recommendations, for external and internal testing.

The English-language documents are demonstration examples from 2023; they show the structure of the deliverables, not the results of an identifiable client. A current project is documented for the agreed testing scope and conditions.
We establish the type of testing, the authorised scope, the number of IP addresses, the environments included and the working period. For recurring assessments, we agree the frequency and access conditions so that results can be tracked from one test to the next.
You receive reports for management and the technical team, remediation recommendations and free retesting, included. The retest schedule and the scope to be re-checked are agreed within the project.
The report helps the IT team establish what needs to be fixed and in what order. For each relevant finding, the client can assign an owner and a remediation deadline, taking into account the impact and the dependencies between systems.
Once the measures have been applied, retesting verifies the outcome within the agreed scope. This way, management can track both the risks identified and the progress of remediation.
Request a PenTest proposalTwo companies started from the impact an interruption would have on their business and chose to assess their exposure.
Internal and external PenTest, every month
Real anonymised caseAn automotive industry distributor with daily revenue of over €100,000 needed to understand which risks in its IT infrastructure could interrupt its operations. Beyond the lost revenue, management was also weighing the possibility that some customers would buy from competitors during the downtime.
The company chose internal and external PenTest every month. The assessments documented the vulnerabilities identified in executive and technical reports, together with remediation recommendations. This gave the IT team a starting point for deciding on the necessary measures.
Periodic testing makes it possible to reassess exposure as the infrastructure changes. Once remediation has been applied, the retesting included in the service verifies whether the targeted issues have been resolved.
Some measures could not be implemented immediately. The company subsequently added SOC to monitor the infrastructure during and after remediation.
Why the company also added SOCPenTest for the infrastructure included in the assessment
Real anonymised caseFor a company that sells exclusively online, a systems outage can stop orders. Management chose penetration testing to understand the security risks that could affect the availability of the business.
The role of PenTest is to identify vulnerabilities and attack paths within the agreed scope. The assessment shows where an attacker could gain access and what consequences that access could have for the systems and data tested.
The findings and recommendations in the report give the IT team the basis for remediation. Subsequent verification of the measures applied helps close the identified issues, and future tests can catch exposures that emerge as the infrastructure changes.
The company later complemented PenTest with SOC, to follow security events while its systems are in operation.
How SOC complements testing in this caseTest results become useful when the IT team turns them into measures, deadlines and checks.
The report documents vulnerabilities and attack paths. The recommendations help you order interventions according to the risks identified.
The IT team carries out remediation, and the included free retest checks the targeted issues. An applied measure also needs its outcome confirmed.
SOC can track security events in the infrastructure in scope, including when some remediation takes longer.
Testing frequency and the need for monitoring are determined by exposure and business impact. For continuity, the plan also includes backup, redundancy and recovery procedures.
The testing service is delivered by a specialised team with documented qualifications in offensive security and infrastructure.







CREST — Council of Registered Ethical Security Testers — accredits the testing service provider; the other logos represent professional qualifications in the team’s portfolio. The report documents the test performed under this accreditation.
Internal and external testing provides technical evidence for assessing vulnerabilities and the effectiveness of controls within the tested scope. The report, recommendations and retesting can be integrated into the risk treatment plan and the NIS2 programme documentation.
The service’s contribution is determined within the organisation’s security programme. Compliance also includes governance, procedures and reporting obligations, depending on applicability.
The platform includes AI features to summarise results and explain them to management. The assessment documents attack paths within the agreed scope, and human validation completes the process. The technical report and recommendations enable the IT team to plan remediation.
External testing assesses the network’s exposure from the internet. Internal testing assesses risks from inside the network, including the possibilities of accessing other systems and escalating privileges, within the authorised scope.
The type of test, the number of IP addresses, the target environments, the frequency and the preferred period. We clarify the required access and the authorised conditions before testing.
We deliver executive and technical reports for testing performed under CREST accreditation. If you need a separate certificate or a specific format requested by an auditor or business partner, we check the requirement before the project starts.
Within 48 hours after the scan finishes. This timeframe covers writing and delivering the reports, after testing has ended.
Yes. The technical report contains the findings and remediation recommendations. The executive summary helps management understand the risks and priorities, and the IT team can turn the recommendations into an action plan.
The client’s internal IT team or IT service provider. On request, TRU can organise the necessary services through its partners, with the activities set out in the project proposal.
No. Retesting after remediation is included and free. We agree the schedule and the scope to be re-checked within the project.
Infrastructure, applications and configurations change. Recurring assessments help the company identify new exposures and track the remediation of known issues. The frequency is set according to the company’s context and risks.
The proposal starts from the number of internal and external IP addresses and the testing frequency. Internal testing starts from €31 per IP address per month, and external testing from €313 per IP address, with monthly testing. Internal testing includes grey-box testing: an assessment with a level of access and information agreed before the project. Retesting after remediation is included and free; the total and the terms are specified in the proposal.
You can include this solution in the offering for your clients.
Tell us what you want to protect. Together, we will agree the starting point.
How to prioritise vulnerabilities after a pentest, reduce exposure until remediation and complement retesting with 24/7/365 SOC monitoring.
Read the article (in Romanian)