Solutions /SECURITY TESTING · PenTest

Penetration testing
for internal and external networks.

We assess the paths an attacker could use to access your company’s systems and data.

Request a PenTest proposal See a sample report

Test what
has to hold up.

We deliver executive and technical reports and remediation solutions, with free retesting included.

We agree the scope, access and authorised testing window, then use the PenTest platform for the agreed scenarios.

Illustration from the TRU presentation on vulnerabilities and the protection of IT systems
01

External network

Assessment of the internet-facing attack surface, for the addresses and services in scope.

02

Internal network

Testing of attack paths within the internal infrastructure, with grey-box testing included and access agreed within the authorised scope.

03

Reports under CREST accreditation

Executive and technical reports, with the vulnerabilities identified and remediation recommendations.

HOW WE USE AI

Clear reports.
Human validation.

The PenTest platform used by TRU includes AI features to summarise results and present their impact on the business.

01

Network testing

We assess attack paths in the internal and external network, within the authorised scope. Findings are documented to show the access gained and the possible impact.

02

AI-assisted reporting

AI adds context to technical findings and helps present risks and remediation priorities in language that management can follow.

03

Validation and retesting

Human validation completes the assessment. Once the agreed measures have been applied, the included free retest verifies that the identified issues have been remediated.

WHAT WE ASSESS

Attack paths.
Possible impact.

Scenarios are selected according to the infrastructure and the scope agreed for the test.

  • Authentication

    Testing credential-related weaknesses and the access they can provide.

  • Privilege escalation

    Assessing whether additional rights can be obtained after the initial compromise.

  • Lateral movement

    Identifying the paths an attacker could use to reach other systems on the network.

  • Outbound traffic

    Checking the controls that restrict communications to external destinations.

  • Access to sensitive data

    Simulating and documenting access to resources that require additional protection.

  • Monitoring visibility

    Correlating the log of testing activities with existing security alerts and controls.

HOW WE WORK

From context
to a concrete plan.

  1. 01

    We define the scope

    IP addresses, frequency, access and authorised conditions.

  2. 02

    We run the test

    Testing through the PenTest platform within the agreed time window.

  3. 03

    We analyse the results

    Reviewing the findings and setting remediation priorities.

PENTEST PRICING

Starting prices.
Clear timelines.

Pricing starts from the number of IP addresses tested and the testing frequency. The final proposal specifies the agreed scope, access and schedule.

INTERNAL PENTEST

from €31 / IP per month

Attack paths inside the internal network, with grey-box testing included, within the authorised scope.

EXTERNAL PENTEST

from €313 / IP, with monthly testing

The internet-facing exposure, for the addresses and services in scope.

  • Reports in 48 hoursThe executive report and the technical report, delivered within 48 hours after the scan finishes.
  • Reports under CREST accreditationDocumented findings and remediation recommendations for the IT team.
  • Free retestWe re-check the remediation measures within the agreed scope and on the agreed date.

Prices are in euros and exclude VAT.

REPORTS AVAILABLE IN48hours

after the scan finishes

DELIVERABLES FOR TWO PERSPECTIVES

Clarity for management.
Detail for the IT team.

Executive report

A summary of the findings, the risks identified and the remediation directions.

Technical report

The evidence obtained during the test, vulnerability details and recommendations for the technical team.

Testing performed under CREST accreditation — Council of Registered Ethical Security Testers.

Free retesting included. We verify the outcome of the remediation measures within the agreed scope and on the agreed date.

DELIVERABLES YOU CAN REVIEW

Browse the PenTest reports.

Demonstration examples: executive summary, technical findings and remediation recommendations, for external and internal testing.

Executive report

Executive report — page 1
Open the PDF ↗
Report preview

The English-language documents are demonstration examples from 2023; they show the structure of the deliverables, not the results of an identifiable client. A current project is documented for the agreed testing scope and conditions.

TESTING AND REMEDIATION

From the tested scope to the measures applied.

What we clarify before testing

We establish the type of testing, the authorised scope, the number of IP addresses, the environments included and the working period. For recurring assessments, we agree the frequency and access conditions so that results can be tracked from one test to the next.

You receive reports for management and the technical team, remediation recommendations and free retesting, included. The retest schedule and the scope to be re-checked are agreed within the project.

How to turn the report into a remediation plan

The report helps the IT team establish what needs to be fixed and in what order. For each relevant finding, the client can assign an owner and a remediation deadline, taking into account the impact and the dependencies between systems.

Once the measures have been applied, retesting verifies the outcome within the agreed scope. This way, management can track both the risks identified and the progress of remediation.

Request a PenTest proposal
FROM OUR PROJECTS

Why they chose
penetration testing.

Two companies started from the impact an interruption would have on their business and chose to assess their exposure.

Automotive industry distributor

Monthly testing for business continuity

Internal and external PenTest, every month

Real anonymised case

An automotive industry distributor with daily revenue of over €100,000 needed to understand which risks in its IT infrastructure could interrupt its operations. Beyond the lost revenue, management was also weighing the possibility that some customers would buy from competitors during the downtime.

The company chose internal and external PenTest every month. The assessments documented the vulnerabilities identified in executive and technical reports, together with remediation recommendations. This gave the IT team a starting point for deciding on the necessary measures.

Periodic testing makes it possible to reassess exposure as the infrastructure changes. Once remediation has been applied, the retesting included in the service verifies whether the targeted issues have been resolved.

Some measures could not be implemented immediately. The company subsequently added SOC to monitor the infrastructure during and after remediation.

Why the company also added SOC
Online retail company

Assessing the exposure of an online-only business

PenTest for the infrastructure included in the assessment

Real anonymised case

For a company that sells exclusively online, a systems outage can stop orders. Management chose penetration testing to understand the security risks that could affect the availability of the business.

The role of PenTest is to identify vulnerabilities and attack paths within the agreed scope. The assessment shows where an attacker could gain access and what consequences that access could have for the systems and data tested.

The findings and recommendations in the report give the IT team the basis for remediation. Subsequent verification of the measures applied helps close the identified issues, and future tests can catch exposures that emerge as the infrastructure changes.

The company later complemented PenTest with SOC, to follow security events while its systems are in operation.

How SOC complements testing in this case
AFTER THE ASSESSMENT

From the report
to the remediation plan.

Test results become useful when the IT team turns them into measures, deadlines and checks.

You set the priorities.

The report documents vulnerabilities and attack paths. The recommendations help you order interventions according to the risks identified.

You apply and verify the measures.

The IT team carries out remediation, and the included free retest checks the targeted issues. An applied measure also needs its outcome confirmed.

You add monitoring.

SOC can track security events in the infrastructure in scope, including when some remediation takes longer.

Testing frequency and the need for monitoring are determined by exposure and business impact. For continuity, the plan also includes backup, redundancy and recovery procedures.

THE EXPERTISE BEHIND THE TESTING

Accreditation and professional qualifications.

The testing service is delivered by a specialised team with documented qualifications in offensive security and infrastructure.

OSCP · OSCE · OSEP · OSWP
OSCP · OSCE · OSEP · OSWPOffSec qualifications for penetration testing and offensive assessment.
eCPPT · eJPT · eMAPT
eCPPT · eJPT · eMAPTProfessional qualifications of the testing specialists.
CEH
CEHCertified Ethical Hacker, part of the team’s qualifications portfolio.
ARTE
ARTEQualification in vulnerability assessment and exploitation.
Security+ · Network+
Security+ · Network+Security and networking qualifications.
CCENT · CCNA
CCENT · CCNANetworking qualifications listed in the team’s documentation.
CREST · Pen Test
CREST · Pen TestThe provider’s accreditation for penetration testing services.

CREST — Council of Registered Ethical Security Testers — accredits the testing service provider; the other logos represent professional qualifications in the team’s portfolio. The report documents the test performed under this accreditation.

MEASURES FOR NIS2

Verify your security measures.

Internal and external testing provides technical evidence for assessing vulnerabilities and the effectiveness of controls within the tested scope. The report, recommendations and retesting can be integrated into the risk treatment plan and the NIS2 programme documentation.

The service’s contribution is determined within the organisation’s security programme. Compliance also includes governance, procedures and reporting obligations, depending on applicability.

FREQUENTLY ASKED QUESTIONS

The details that
matter when you choose.

What role do AI and human validation play in the PenTest service?

The platform includes AI features to summarise results and explain them to management. The assessment documents attack paths within the agreed scope, and human validation completes the process. The technical report and recommendations enable the IT team to plan remediation.

What is the difference between internal and external testing?

External testing assesses the network’s exposure from the internet. Internal testing assesses risks from inside the network, including the possibilities of accessing other systems and escalating privileges, within the authorised scope.

What information is needed for a proposal?

The type of test, the number of IP addresses, the target environments, the frequency and the preferred period. We clarify the required access and the authorised conditions before testing.

Do you deliver reports and documentation for CREST requirements?

We deliver executive and technical reports for testing performed under CREST accreditation. If you need a separate certificate or a specific format requested by an auditor or business partner, we check the requirement before the project starts.

How soon will I receive the reports?

Within 48 hours after the scan finishes. This timeframe covers writing and delivering the reports, after testing has ended.

Does the report also explain how to remediate the vulnerabilities?

Yes. The technical report contains the findings and remediation recommendations. The executive summary helps management understand the risks and priorities, and the IT team can turn the recommendations into an action plan.

Who implements the remediation measures?

The client’s internal IT team or IT service provider. On request, TRU can organise the necessary services through its partners, with the activities set out in the project proposal.

Is retesting charged separately?

No. Retesting after remediation is included and free. We agree the schedule and the scope to be re-checked within the project.

Why would periodic testing be necessary?

Infrastructure, applications and configurations change. Recurring assessments help the company identify new exposures and track the remediation of known issues. The frequency is set according to the company’s context and risks.

How much does a PenTest cost and what does internal testing include?

The proposal starts from the number of internal and external IP addresses and the testing frequency. Internal testing starts from €31 per IP address per month, and external testing from €313 per IP address, with monthly testing. Internal testing includes grey-box testing: an assessment with a level of access and information agreed before the project. Retesting after remediation is included and free; the total and the terms are specified in the proposal.

Do you provide IT services?

You can include this solution in the offering for your clients.

Partner programme
NEXT STEP

Security starts with a conversation.

Tell us what you want to protect. Together, we will agree the starting point.

Request a PenTest proposal
PRACTICAL GUIDE

What to do after a pentest if you cannot remediate all vulnerabilities immediately

How to prioritise vulnerabilities after a pentest, reduce exposure until remediation and complement retesting with 24/7/365 SOC monitoring.

Read the article (in Romanian)