Penetration testing

Penetration testing services: find the gaps before attackers do

We specialise in professional penetration testing and IT security audits. We identify vulnerabilities in your infrastructure, applications and networks before cybercriminals exploit them. Every pentest is performed manually by OSCP- and OSWE-certified testers, and you receive a report with proof of exploitation and CVSS scores.

  • 1000+Pentests completed
  • 24hFirst vulnerabilities in the platform
  • 30 daysRetest included after the report
  • OSCPOSWE · OSEP · OSCE³ – our testers’ certifications
vipentest · pentest session (sample)LIVE
  1. 443/tcp https · 8443/tcp https-alt · 22/tcp ssh
  2. /admin 302 · /api/v2 200 · /backup.zip 200
  • CriticalIDOR: other customers’ invoices via /api/invoices/{id}
  • HighNo login rate limiting on /login
  • MediumIncomplete CSP and HSTS headers
  • LowServer version disclosed in headers
OWASP WSTG coverage87%
  • 14findings
  • 3critical and high
  • 24hto first alert
Certifications

Our certifications

Tests are performed by penetration testers holding Offensive Security and eLearnSecurity certifications: OSCP, OSWE, OSEP, OSED, OSCE³, OSWP, eWPTX, eCPPT, KLCP, alongside ISO 27001 auditors.

OSCP – Offensive Security Certified Professional OSCE³ – Offensive Security Certified Expert 3 KLCP – Kali Linux Certified Professional OSWE – Offensive Security Web Expert Certified Red Team Operator OSEP – Offensive Security Experienced Penetration Tester OSWP – Offensive Security Wireless Professional OSED – Offensive Security Exploit Developer ISO 27001 Auditor eWPTX – eLearnSecurity Web Application Penetration Tester eXtreme eCPPTv2 – eLearnSecurity Certified Professional Penetration Tester CISSP – Certified Information Systems Security Professional
Definition

What is penetration testing?

Penetration testing (pentest) is a controlled simulation of hacker attacks aimed at identifying weaknesses in IT system security. We act as ethical hackers: using the same techniques as cybercriminals, but in a legal and controlled manner, delivering a detailed report with remediation recommendations.

Below you will find the types of tests we run, the black, grey and white box methods, the step-by-step process, indicative pricing and what the report contains. If you are planning your first pentest, start with the scope and pricing sections and then book a free scoping call.

  • 83%of companies experienced a cyberattack in 2024
  • USD 4.45Maverage cost of a data breach
  • Vulnerability detection before an attack
  • Compliance with GDPR, PCI DSS, ISO 27001
  • Detailed report with recommendations
  • Protection of reputation and client data
Scope

Types of penetration testing: web, API, mobile, desktop, infrastructure, cloud, Wi-Fi, AI/LLM

We offer comprehensive penetration testing services tailored to your IT infrastructure. Each type of test has its own methodology, scope and price range.

WEB / API

Web application penetration testing

We offer professional web application testing using Black Box and Grey Box methods. Our approach enables a comprehensive security assessment of applications, both from the perspective of an external attacker and a partially informed internal user. Tests are conducted in accordance with the Penetration Testing Execution Standard (PTES) methodology.

The result of the tests is a detailed electronic report that includes:

  • Description of discovered security vulnerabilities
  • Evidence confirming their existence
  • Guidance on remediating identified issues
  • Analysis of potential consequences of exploiting discovered vulnerabilities

During testing, we use a methodology based on best practices described in the OWASP Testing Guide, as well as the OWASP Top 10, OWASP Web Security Testing Guide and ASVS methodologies.

API penetration testing

We perform API penetration testing using Black Box and Grey Box models, focusing on the security of communication between system components, data integrity, and the proper implementation of authentication and authorisation mechanisms.

We apply the PTES methodology and best practices from the OWASP API Security Top 10, OWASP ASVS and Web Security Testing Guide. Upon completion of testing, you will receive a comprehensive technical and business report containing:

  • Description of all discovered vulnerabilities
  • Evidence confirming their occurrence (requests, responses, screenshots)
  • Analysis of impact on data confidentiality, integrity and availability
  • Technical and organisational recommendations to enhance API security
  • Remediation action priorities based on business impact
OWASP Top 10REST APIGraphQLOAuth 2.0PTESASVS

Mobile applications

Mobile application penetration testing involves controlled, ethical attack simulations on applications installed on Android and iOS devices, aimed at discovering real security vulnerabilities before cybercriminals do.

iOS penetration testing

We perform iOS application penetration testing using Black Box, Grey Box and White Box models. We analyse data storage methods on the device, API server communication security, certificate integrity, and protection mechanisms against application modification or reverse engineering (tampering). We also test application resistance to jailbreak detection bypass, unauthorised access to Keychain keys, and incorrect implementations of cryptographic mechanisms.

Android penetration testing

We conduct Android mobile application testing using Black Box, Grey Box and White Box models, focusing on code security analysis, environment configuration, and application resistance to attacks in real-world scenarios. We examine, among others: data storage security in device memory, API server communication, protection against decompilation and APK file modification, correct cert pinning implementation, and resistance to hooking techniques (e.g. Frida, Xposed).

We conduct tests in accordance with recognised standards:

  • OWASP Top 10 Mobile Risks
  • OWASP Mobile Application Security Testing Guide (MASTG)
  • OWASP Mobile Application Security Verification Standard (MASVS)
iOSAndroidOWASP MASTGMASVSFridaReverse Engineering

Thick client (desktop)

Our tests include both manual and automated verification of various vulnerability classes in desktop applications. Applications undergo both static and dynamic analysis.

Testing methods

  • Fuzzing and dynamic testing
  • Network component and API analysis
  • Injections
  • Cryptography security verification
  • Testing components stored on the operating system
  • Analysis of logs and data stored by the application
  • Process and memory monitoring
  • Registry key review
  • Reverse engineering and static analysis

Analysed areas

  • Application architecture
  • Data storage and cryptography usage
  • Authentication and session management mechanisms
  • Application network communication
  • Application interaction with the operating system
  • Protections against reverse engineering
OWASP ASVSOWASP Testing GuideReverse EngineeringFuzzing

IT infrastructure

During infrastructure tests, we conduct comprehensive analyses of all devices in the subnet to identify vulnerabilities and configuration errors that could enable taking control of tested hosts. One of the goals of these tests is to determine the visibility of hosts and services that could be targeted by attackers both physically present on the network and attacking remotely.

Infrastructure tests aim to verify the security of services and systems accessible to both Internet (external) and LAN (internal) network users. We apply an approach based on industry best practices such as OSSTMM and PTES.

Steps performed during testing

  • Identification of exposed TCP and UDP services
  • Identification of weaknesses in discovered services
  • Attempts to exploit identified vulnerabilities
  • Verification of identified vulnerabilities
Active DirectoryWindows ServerLinuxNetworkOSSTMMPTES

Cloud (AWS/Azure/GCP)

Cloud penetration testing involves detailed analysis of configurations, security policies and access rules, using specialised tools and techniques to identify weaknesses in cloud infrastructure.

VIPentest applies individually tailored testing methodologies to effectively analyse and secure cloud environments, taking into account their unique architecture and threat models. Our cloud environment penetration tests cover Azure, AWS and GCP platforms, providing a comprehensive security assessment of your cloud infrastructure.

AWSAzureGCPKubernetesIAMCompliance

WiFi networks

During our wireless network penetration tests, we determine the security types (Open, WEP, WPA, WPA2, WPA3 Personal or Enterprise) and authentication mechanisms used by your organisation.

Attack techniques used

  • Encryption attacks: including dictionary and brute-force attacks, exploiting WEP weaknesses, improper WPA2 configuration and weak passwords
  • Machine-in-the-Middle attacks: including Rogue Access Points and Evil Twins
  • Denial of Service (DoS) attacks: disrupting wireless communication, such as flooding
WPA2/WPA3802.1XRogue APEvil TwinDoS

AI / LLM Security

Specialised security testing of applications utilising artificial intelligence and large language models (LLM). We verify the resilience of AI systems against real attack vectors, including input manipulation, data leaks and security mechanism bypasses.

Tested areas

  • Prompt Injection (direct & indirect): injecting malicious instructions into the model
  • Jailbreaking: bypassing LLM restrictions and security policies
  • Training data leaks (PII leakage): extracting confidential information from the model
  • Output manipulation: forcing incorrect or harmful responses
  • RAG Poisoning: attacks on Retrieval-Augmented Generation systems
  • Insecure Plugin/Tool Use: abusing tools connected to the LLM
  • Model Denial of Service: exhausting resources and blocking availability

We conduct tests in accordance with the OWASP Top 10 for LLM Applications and our own methodologies developed on the basis of the latest research in adversarial AI.

Prompt InjectionJailbreakRAG SecurityOWASP LLM Top 10Adversarial AI

People and processes: social engineering, red team

A pentest checks the technology. To assess the resilience of the whole organisation, we complement it with social engineering testing (phishing campaigns, vishing, smishing) and a red team assessment that tests detection and response, in which we simulate a multi-week attack and check whether your team and SOC detect and stop it.

A phishing campaign for up to 500 people takes 2–4 weeks, and a full TLPT cycle with Threat Intelligence takes 8–16 weeks. We combine the results of social engineering tests with those of technical tests so that management sees the full risk picture: technology, people and processes.

  • Phishing simulations and other attacks on employees
  • Red team operations mapped to MITRE ATT&CK
  • TLPT for the financial sector (DORA / TIBER-EU)
PhishingRed TeamMITRE ATT&CKTLPT
Methodology

Testing methods: black box, grey box and white box

Choose an approach tailored to your needs and level of access to system information. Black box, grey box and white box penetration tests differ in how much the tester knows at the start.

Black Box

Simulation of an external hacker attack. The tester has no knowledge of the tested system: they start from scratch, just like a real attacker.

Hacker’s perspective

Grey Box

Optimal balance of time and effectiveness. The tester has partial knowledge of the system, e.g. API documentation or a test account.

Recommended

White Box

The most thorough analysis. The tester has full access to source code, architecture documentation and system configuration.

Code review
Methodologies

Methodology: OWASP, PTES, OSSTMM, NIST and MASVS

We conduct our penetration tests in accordance with international IT security standards and methodologies.

OWASP

Open Web Application Security Project: the web application and API security standard (Web Security Testing Guide, Top 10, ASVS).

OSSTMM

Open Source Security Testing Methodology Manual: a security testing methodology for infrastructure and networks.

NIST CSF

National Institute of Standards and Technology: the Cybersecurity Framework for managing cyber risk.

MASTG / MASVS

OWASP Mobile Application Security: the testing standard for iOS and Android mobile applications.

OWASP LLM Top 10

Security standard for AI applications and large language models: prompt injection, data leaks, RAG poisoning.

Regulations

Penetration testing for NIS2, DORA, ISO 27001, PCI DSS, HIPAA and GDPR

We help meet the requirements of key IT industry regulations and standards. The test report includes a description of scope and methodology written for your auditor or regulator.

HIPAA

Protection of medical data and patient health information.

DORA

Digital Operational Resilience Act: digital resilience of the EU financial sector, including TLPT.

NIS2

EU Directive on network and information systems: cybersecurity of essential and important entities.

PCI-DSS

Payment Card Industry Data Security Standard: payment data security.

ISO 27001

International standard for information security management (ISMS).

NIST

National Institute of Standards cybersecurity and risk management framework.

GDPR

General Data Protection Regulation: compliance with EU data protection laws.

KNF / UKNF

Polish Financial Supervision Authority recommendations on IT security.

Process

Penetration testing process step by step

Every test follows the same process, whether it covers a single application or your entire infrastructure. You know what is happening at each stage and how long it will take.

  1. 01
    30–60 min, free of charge

    Scoping call

    We agree what is to be tested, in which model (black, grey or white box), in which environment and when. After the call you receive a quote with a specific number of days and a fixed price, not a “from”.

    ScopingQuote
  2. 02
    1–2 days

    Formalities

    Contract and NDA signed electronically, plus the rules of engagement: time window, your point of contact, and the escalation path if we find a critical vulnerability.

    NDARules of Engagement
  3. 03
    1 day

    Reconnaissance and threat modelling

    We map the application or network, identify technologies, user roles and entry points. We establish what the worst-case scenario would be for your business and start there.

    OSINTThreat modelling
  4. 04
    3–10 days

    Manual testing

    An OSCP- or OSWE-certified pentester manually verifies every vulnerability class from OWASP, PTES and OSSTMM. Scanners are only a supporting tool. You see each vulnerability in the vulnerability management platform on the day it is found; critical ones we also report by phone.

    OWASPPTESOSSTMM
  5. 05
    2–3 days

    Report

    An executive summary for management, a list of vulnerabilities with CVSS scores, step-by-step proof of exploitation and recommendations in order of implementation. We walk your team through it in a debriefing meeting.

    CVSS 3.1Executive summary
  6. 06
    included, within 30 days of the report

    Retest

    Once you have deployed the fixes, you mark them in the platform with one click, we verify that the vulnerabilities are really gone and issue a final report with a certificate for your client, auditor or regulator.

    RetestCertificate
Pricing

Penetration testing cost: what drives the price

The price depends on three factors: the size of the scope (number of features, endpoints or hosts), the number of user roles that must be tested separately, and the testing model. White box with access to source code is more thorough but takes more time. Below are indicative net price ranges; you receive an exact price after a 30-minute scoping call.

ScopeVariantNet priceDuration
Web application or APIunauthenticated (black box)from PLN 6,0003–4 days
Web application or API2–3 roles, admin panelPLN 14,000–22,0007–10 days
Web application or API4+ roles, many modules, integrations (white box)from PLN 22,000from 10 days
Mobile applicationone platform, 1 role, backend in scopePLN 9,999–14,0005–7 days
Mobile application (iOS + Android)both platforms, 1 rolePLN 14,000–20,0007–10 days
Mobile application (iOS + Android)multiple roles, payments or medical datafrom PLN 18,000from 10 days
External infrastructureup to 25 IP addressesfrom PLN 6,0003–5 days
Internal infrastructure + Active Directoryup to 250 hosts, 1 domainPLN 15,000–30,0007–12 days
Internal infrastructure + Active Directoryover 250 hosts, multiple domains or sitesfrom PLN 30,000from 12 days
Social engineeringphishing campaign, up to 500 peoplePLN 9,999–16,0002–4 weeks
TLPT (DORA / TIBER-EU)full cycle with Threat Intelligencefrom PLN 172,0008–16 weeks

The ranges apply to typical scopes. The price grows with size: the number of screens and endpoints, roles, hosts, domains and environments. Large applications, multiple environments or distributed networks are quoted individually after a scoping call. All prices are net amounts in PLN.

Included in the price: the report in two versions (executive and technical), a debriefing meeting, a retest within 30 days and a certificate after the retest, and access to the vulnerability management platform. Quoted separately: testing in production outside business hours, more than one environment, and on-site work at your premises.

Report

What you get in the report

A VIPentest penetration test report has two parts, because two different audiences read it: management and the technical team.

Executive summary

2–3 pages: overall security level, number of vulnerabilities by severity, the three most important business risks and the recommended order of action. No jargon, ready to show to the board or a client.

Technical section

Every vulnerability with a CVSS 3.1 score, impact description, proof of exploitation (screenshots, requests, code), exact location and a remediation recommendation referencing OWASP and CWE.

Scope and methodology description

What was tested, in which model, with which tools, what was excluded and why. This is the part your ISO 27001, NIS2 or DORA auditor needs.

Retest report and certificate

A table: vulnerability, status after the fix, verification date. Plus a certificate of testing you can share with business partners. Access to the vulnerability management platform remains after the project ends.

Platform

Visibility from day one: the vulnerability management platform

Most companies learn the results of a test from a PDF after it is over. With us, every client gets access to the VIPentest vulnerability management platform for the duration of the test and beyond.

01

Live test progress

You see what stage the team is at, what has been tested, what remains and whether we are on schedule.

02

Vulnerabilities during the test, not after

Every finding appears in the platform on the day it is discovered, with a CVSS score, evidence and a recommendation. Your development team can start fixing before the test is over.

03

Fix reporting and retest

Once a fix is deployed, you mark the vulnerability as remediated, we verify it and close it. The history of every vulnerability is preserved.

04

Report and certificate in one place

You download them from the platform as soon as they are ready. Access does not expire when the project ends.

Preparation

How to prepare your company for a penetration test

Good preparation shortens the test by a day or two and increases its value. Before we start, we need six things from you.

01

Purpose of the test

A regulatory requirement, a client’s demand, a new release or a general security assessment. The purpose determines the model and scope.

02

List of what we are testing

Addresses, application names, repositories (for white box), IP ranges.

03

Environment

Test, pre-production or production. Production requires a time window and the owner’s consent.

04

Test accounts

One for each user role, with data that can be safely modified.

05

Provider consents

If the application is hosted in the cloud or with a hosting provider, some of them require advance notice of the test.

06

Point of contact and escalation path

Who picks up the phone when we find a critical vulnerability at 11 pm.

Who it is for

Who penetration testing services are for

Penetration tests are ordered by organisations that process customer data, are subject to regulation, or need to show a business partner proof of security. Most often we work with:

Software houses and SaaS

The end client requires a test report before go-live or in the contract. We test the web application, API and mobile apps before release, and the retest confirms the fixes. See penetration testing for software houses.

E-commerce and fintech

Payments, card data and user accounts: a scope aligned with PCI DSS and KNF recommendations. We check the basket, payments, customer panel and integrations with payment providers. See penetration testing for banking and fintech.

Banks and insurers

Financial entities covered by DORA and KNF supervision: regular tests of critical systems, and for the largest institutions TLPT in line with TIBER-EU.

Healthcare

Systems holding patient medical data: HIPAA and GDPR requirements, tests of applications, patient portals and the facility’s infrastructure.

Essential and important entities under NIS2

Energy, transport, manufacturing, public administration and their suppliers: infrastructure and application tests as part of the risk management required by NIS2.

Companies facing an audit or a client questionnaire

ISO 27001 certification, an internal audit or a security questionnaire from a business partner: the test report and certificate close the “penetration testing” item without further questions. If the questionnaire also asks about hardening, we complement the pentest with a security configuration audit against CIS benchmarks or a compliance audit for NIS2, DORA and ISO 27001.

FAQ

Frequently asked questions about penetration testing

Find answers to the most common questions about penetration testing.

How long does a penetration test take?

The duration of penetration testing depends on the scope and complexity of the tested system. A typical web application pentest takes 3 to 10 business days, depending on the number of roles and modules. An external infrastructure test takes 3–5 days, an internal network with Active Directory 7–12 days, and a comprehensive IT infrastructure security audit may require 2 to 4 weeks. Add 2–3 days for the report. After an initial analysis, we prepare a detailed schedule tailored to your needs.

Can penetration testing disrupt system operations?

Professional penetration tests are conducted in a controlled and safe manner. Before starting pentests, we sign an agreement defining the scope of activities, time windows and security procedures. We do not run denial-of-service attacks without explicit consent, and we agree risky operations with your point of contact as we go. We can perform tests on a staging environment or during low-traffic hours, minimising the risk of impact on production, and in production we work on test accounts and data that can be modified.

What will I receive after the tests are completed?

You will receive a detailed report containing: an executive summary for management, a full list of discovered vulnerabilities with risk assessment according to CVSS 3.1, a technical description of each vulnerability with exploitation evidence (Proof of Concept), prioritised remediation recommendations, and support throughout the remediation process. After the retest we add a final report and a certificate of testing, and you download both from the vulnerability management platform.

How often should penetration tests be conducted?

We recommend conducting penetration tests at least once a year and after every significant change in IT infrastructure or application update. Regulated industries (finance, healthcare, e-commerce) often require more frequent audits: PCI DSS requires pentests quarterly or after every significant change, and DORA and KNF recommendations assume regular testing of critical systems. A retest within 30 days of the report confirms that the fixes actually worked.

How much does penetration testing cost?

The cost of penetration testing depends on many factors: test scope, system complexity, chosen methodology (Black/Grey/White Box) and delivery timeline. A black box test of a web application or API starts from PLN 6,000 net, a grey box test with one user role costs PLN 9,999–15,000, external infrastructure of up to 25 addresses from PLN 6,000, and an internal network with Active Directory PLN 15,000–30,000. We prepare individual quotes after a free consultation and project scope analysis. Contact us to receive an offer tailored to your needs.

What is the difference between a penetration test and a vulnerability scan?

A scanner compares software versions against a database of known bugs and produces a list of “possible” issues, some of which do not exist. A penetration test is the work of a person who actually tries to exploit vulnerabilities, chains them into attack scenarios and shows the real impact on the business. A scan is one element of a test, not a substitute for it. In a pentest report every vulnerability has proof of exploitation, a CVSS score and a remediation recommendation, not just a CVE number.

Do you test the production environment or a staging copy?

Both, depending on the situation. We prefer a pre-production environment identical to production, because it allows testing without restrictions. We test production when there is no test environment or when the client wants to verify the real configuration. In that case we agree a time window, exclude load testing and work on test accounts. If the application is hosted in the cloud or with a hosting provider, some providers require advance notice of the test, which we help you arrange.

Is a retest after remediation included in the price?

Yes. One retest performed within 30 days of delivering the report is part of the service. Once you have deployed the fixes, you mark them in the vulnerability management platform with one click, and we check whether the vulnerabilities are really gone. After the retest we issue a final report with a table (vulnerability, status after the fix, verification date) and a certificate of testing for your client, auditor or regulator.

Can I follow the test while it is in progress?

Yes. You get access to the VIPentest vulnerability management platform, where you see the progress of the test and the vulnerabilities found on the day of discovery, with a CVSS score, evidence and a recommendation, and after remediation you submit them for a retest with one click. We additionally report critical vulnerabilities by phone. You download the report and certificate from the same platform, and access remains after the project ends.

Which type of penetration test should we start with?

If your company has not been tested before, we usually start with what is exposed to the internet: the web application or API in a grey box model with one user role, plus the external infrastructure. These are the scopes an attacker checks first, and their test fits within 3–7 days. The internal network with Active Directory, mobile applications and social engineering tests are added in subsequent cycles, and organisations with a working SOC consider red team operations.

Do penetration tests also cover cloud, Wi-Fi and AI systems?

Yes. Beyond web applications, mobile apps, APIs and infrastructure, we test AWS, Azure and GCP cloud environments (configuration, security policies, IAM access rules), wireless networks (WPA2/WPA3, 802.1X, Rogue AP and Evil Twin attacks) and applications built on large language models according to the OWASP Top 10 for LLM Applications: prompt injection, jailbreaking, data leaks, RAG poisoning. Each of these scopes is quoted separately after a conversation about the architecture.

Will I receive a certificate for a client or auditor after the test?

Yes. After the retest we issue a final report and a certificate of penetration testing that you can share with business partners, your ISO 27001 auditor or a regulator under NIS2, DORA or KNF recommendations. The certificate confirms that the test was performed and states its result after the retest. The scope and methodology description in the report is written so that an auditor can use it without further questions. You download the report and certificate from the vulnerability management platform.

Ready to secure your infrastructure?

Contact us and receive a free consultation. Our certified experts will help you choose the optimal scope of penetration testing for your organisation.

  1. Enquiry confirmedWe reply within 24 h on business days and ask about the scope.
  2. Scoping call under NDAWe agree on goals, environment, dates and access.
  3. Quote and test planUsually the same day after the call. No commitment.
  • Retest within 30 days included
  • Vulnerability management platform
We reply within 24 h

Write to us: free quote and scoping consultation

Briefly describe what you want to test. We reply within one business day.

    I consent to the processing of my personal data by VIPentest sp. z o.o. in order to respond to my enquiry. Details in the Privacy Policy.

    No commitment. NDA before any scoping call.

    Penetration testing · from PLN 6,000 netGet a quote