Continuous Security Testing
A single test shows the state of your system at the time of testing. New features and integrations constantly change the situation, so regular testing keeps your security posture up to date.
The first testing round establishes a comprehensive baseline. After that, we focus on changes and new features at the pace that suits you.
Semi-Annual Testing
Two rounds per year
€6,000 / round* (excl. VAT)
A good fit when
- your system changes at a moderate pace
- you want to keep your security posture up to date without a continuous project
- compliance requires regular testing
Quarterly Testing
Four rounds per year
€4,500 / round* (excl. VAT)
A good fit when
- you develop and release new features regularly
- integrations and APIs keep being added continuously
- you want bigger changes tested shortly after completion
Custom Testing
More frequent, agreed cycle
Request a quote
A good fit when
- you release new features weekly or in a continuous stream
- your system is business-critical
- you want changes tested shortly after release
* The exact price depends on the scope of testing.
Working Model
The same familiar experts
A dedicated team is responsible for testing. Their understanding of your environment and system logic grows with every testing round, which shows up as more efficient use of time — no time is spent relearning the basics.
Communication between testing rounds too
A shared, agreed communication channel is in place, where questions about the upcoming round can be raised between testing rounds as well.
A review after every testing round
The findings are reviewed together with the development team after the report is delivered. The review covers the content of each finding, possible ways to implement fixes, and prioritization.
Reporting of critical findings
Critical findings are reported the same day they are discovered.
Retesting of fixes
Fixed findings are retested as part of the project scope.
Report and statement
A technical report of findings and remediation recommendations is delivered after each testing round. On request, we also produce a separate statement describing the scope and methods of testing without technical detail — suitable for sharing with customers and other stakeholders.
You only pay for what you need.
Request a quoteWhat do we test?
Common targets of penetration testing include:
Internal network (LAN) and external network (WAN)
Segmentation, exposed services, and access rights from inside and outside the network.
Individual systems or larger environments
From a single server to an extensive system environment.
Web applications
Access control, sessions, input validation, and known injection vulnerabilities.
Mobile applications
iOS and Android: data storage, interfaces, and traffic protection.
Cloud service environments
Configurations and access rights in AWS, Azure, and GCP environments.
Other interfaces
APIs and integrations between systems.
IoT and embedded devices
Firmware, connection security, and the device’s own services.
Physical controls
Access control and physical access to devices and premises.
Four Steps
1
Scoping
1–2 h
- Defining the targets and scope
- Choosing the testing environment: production, staging, or development
- Agreeing on the schedule
- Written authorization before starting
- Rules of engagement, contacts, and communication channels
2
Testing
3–15 days depending on scope
- Active penetration testing within the agreed scope
- Critical findings are reported immediately upon discovery
- Ongoing communication with the client about project progress
3
Reporting
3 business days after testing
- A complete report of findings
- CVSS-based severity classification
- Each finding includes a reproducible description and a concrete remediation suggestion
4
Review
- The report is reviewed together and approved by the client
Frequently Asked Questions
How does continuous testing differ from a one-off security test?
A one-off test covers the target broadly in a single round. In the continuous model, testing is spread over time, new features are covered after each release, and fixes are verified. In a fast-moving environment, the results of a single test become outdated within a few months.
Is this the same as vulnerability scanning?
No. Scanning finds known vulnerabilities and missing patches. Testing is done manually, and it also uncovers access-control bypasses, business logic flaws, and gaps in customer data isolation that automation doesn't detect.
Can testing be done in the production environment?
Yes. In production, testing uses more cautious methods and is scheduled at agreed times. A separate test environment allows more thorough testing, but the results are only valid if that environment matches production.
How is the scope of each round defined?
The scope is always agreed before a new testing round begins. The definition takes into account changes made since the previous round, new features, and fixes to earlier findings, so each round focuses on what matters most at that time.
What is required from you before we start?
Test credentials for the different user roles, and information about the targets to be tested. The kickoff meeting defines the scope, threat models, and schedule.
How quickly can testing start?
The first testing round is carried out within 2–3 weeks of signing the agreement.
Is this service enough to demonstrate compliance?
The service produces documentation that can be used to demonstrate regular technical testing and vulnerability management. It covers one part of the requirements in NIS2, ISO/IEC 27001, and PCI DSS — not the entire scope of requirements.