Penetration Testing
Penetration testing is a vital part of modern security. It uncovers system vulnerabilities and helps you identify and manage risks before they become problems.
Penetration Testing
Penetration testing (also known as security testing) is a controlled and systematic way to assess the security of an application or system. We simulate the tactics of a real attacker to identify hidden vulnerabilities in your systems, applications, and network environments.
As a result, you'll receive a clear report of the findings, a risk severity classification, and practical recommendations for fixing the vulnerabilities.
What do we test?
Common targets of penetration testing include:
Internal network (LAN) and external network (WAN)
Segmentation, exposed services, and access rights from inside and outside the network.
Individual systems or larger environments
From a single server to an extensive system environment.
Web applications
Access control, sessions, input validation, and known injection vulnerabilities.
Mobile applications
iOS and Android: data storage, interfaces, and traffic protection.
Cloud service environments
Configurations and access rights in AWS, Azure, and GCP environments.
Other interfaces
APIs and integrations between systems.
IoT and embedded devices
Firmware, connection security, and the device’s own services.
Physical controls
Access control and physical access to devices and premises.
Three Pricing Tiers
Project price depends on the scope of testing. The exact scope and price are always confirmed in a scoping call before an offer is sent.
Small
€4,500 (excl. VAT)
A small web application or a limited network, 3–5 testing days
Medium
€7,500 (excl. VAT)
Two testing areas or a larger environment, 5–8 testing days
Large
€12,000+ (excl. VAT)
Comprehensive testing across multiple areas or a demanding special target, 10+ testing days
Invoicing is done monthly based on the work carried out.
Need more regular testing?
A single test shows the state of your system at the time of testing. New features and integrations constantly change the situation, so regular testing keeps your security posture up to date and reviews changes shortly after they go live.
Four Steps
1
Scoping
1–2 h
- Defining the targets and scope
- Choosing the testing environment: production, staging, or development
- Agreeing on the schedule
- Written authorization before starting
- Rules of engagement, contacts, and communication channels
2
Testing
3–15 days depending on scope
- Active penetration testing within the agreed scope
- Critical findings are reported immediately upon discovery
- Ongoing communication with the client about project progress
3
Reporting
3 business days after testing
- A complete report of findings
- CVSS-based severity classification
- Each finding includes a reproducible description and a concrete remediation suggestion
4
Review
- The report is reviewed together and approved by the client
- Retesting of findings is included in the service when agreed in advance.
Who Is Penetration Testing for?
Penetration testing is essential for any organization that wants to protect valuable data and ensure operational continuity. It is especially important if you:
Handle customer or personal data
- Customer databases
- Payment information
Offer digital services
- E-commerce
- SaaS platforms
- Integrations
Need to meet legal and regulatory requirements
- GDPR
- ISO 27001
- NIS2
Operate in critical sectors
- Healthcare
- Finance
- Technology
Whether you're a small or medium-sized business or a growing tech company, penetration testing helps protect your operations and strengthen stakeholder trust.
Why Invest in Penetration Testing?
Penetration testing is an investment that protects your company's reputation, customer trust, and business continuity. You'll receive a clear report of findings, risk severity classifications, and practical recommendations for fixing vulnerabilities.
Benefits for Your Business:
Identify and fix risks early to prevent costly data breaches and business disruptions.
Meet legal requirements and show that you comply with GDPR, ISO 27001, and other standards.
Build trust and show customers and partners that you take security seriously.
Open Source Intelligence (OSINT) and Attack Surface Mapping
We offer companies a comprehensive OSINT and attack surface mapping service to identify and manage risks related to publicly available information.
We gather data from open sources about the company, its personnel, and systems, and identify which externally visible assets may expose the organization to potential attacks.
The service provides a clear overall picture of external threats and delivers concrete recommendations for reducing risks. We help protect your business, enhance cybersecurity, and strengthen risk management.
What's included in the service?
- Kick-off meeting (1 hour)
- Data collection, analysis, and compilation from public sources
- Report
- Final meeting (1 hour)
Customer Benefits
- Identification of cybersecurity risks from external sources
- Proactive threat prevention
- Analysis and recommendations from an external, independent experts
Frequently Asked Questions
What does penetration testing mean?
A technical activity where security professionals map out weaknesses and vulnerabilities in a system, aiming to prevent security breaches. Also known as pen testing or security auditing.
Why use an outside expert for testing?
An external party brings an independent perspective and challenges existing technical solutions in a way that is hard to achieve from within an organization. A third-party report also carries more weight in discussions about security investments with senior management.
What testing approaches are there?
Three main types: black-box (the tester has no prior knowledge of the system, mimicking an external attacker), grey-box (partial knowledge of the structure, the most common choice, balancing coverage and efficiency), and white-box (full access to source code and architecture, the most thorough, but slowest).
What can be tested?
Almost anything: web applications, mobile applications, internal networks (LAN), external networks (WAN), cloud environments, IoT and embedded devices, API interfaces, and physical controls.
Does testing have to happen in production?
Not necessarily. A staging environment is recommended, especially for network testing. Production testing is possible but requires clear written approval and is agreed separately due to the risks involved.
How much of our own resources does testing require?
Very little. We need a test environment or access to production, user accounts with different roles, a short walkthrough of normal system usage, and API documentation if applicable. Testing then proceeds independently.
How long does testing take?
A few days for small, limited targets, typically 5–15 days. Larger scopes take longer. An exact estimate is given during the scoping call.
What happens if a critical vulnerability is found during testing?
It is reported to you immediately, we don’t wait for the final report.
Is retesting done after fixes?
Retesting of findings is included in the service when agreed in advance.
Customer stories
“We wanted to verify the security level of Infomaatti's mobile reporting application through a penetration test carried out by an external expert. The application is a core part of our customers' daily operations, so investing in security throughout our development work is extremely important to us.”
Henri Hakasalo
CEO, Infomaatti Oy
“We had Braveson Oy carry out a security test on our Eventos 3 event management system. The testing was carried out professionally, and the collaboration with Braveson's experts went excellently from start to finish.”
Pekka Neuvonen
CEO, Prospectum Oy
“Braveson carried out a security test on our Piiri application, and we are very satisfied with the testing project. Braveson's team handled the project from start to finish professionally, working independently and on the agreed schedule. Ensuring the security of our customers' data in the Piiri application is of paramount importance to us, which is why we wanted to verify it with outside professionals. We can warmly recommend Braveson's services to any organization that takes security seriously.”
Hanne Haapakoski
CEO, Piiri Kit Oy
“Braveson carried out a security test for JAY Solutions on an AI-powered wealth management service under development. The project proceeded smoothly, communication was clear, and the collaboration was effortless. The testing findings and improvement suggestions were practical and easy to apply in further development. Braveson had a strong understanding of the risks associated with the technology being tested, which allowed the testing to be focused effectively on the areas most critical to the service. We recommend Braveson for similar security testing projects.”
Erno Pellinen
CISO, JAY Solutions Oy
Didn't find the right service?
Do you need customized security testing? We offer thorough, technology-neutral security testing to help you understand and improve your security. Each project is tailored to your environment and risks. We find vulnerabilities, assess threats, and give clear recommendations to strengthen your defenses and support compliance.
Get in touch and let's design a testing that fits your organization perfectly!
Contact us