Pentest & attack simulation Penetration testing (pentest): simulate a real cyberattack on your systems

Our experts carry out penetration tests on your applications, infrastructure and networks to identify genuinely exploitable vulnerabilities before an attacker discovers them. Each pentest is performed within a previously authorised scope and results in a technical report, a risk rating and a remediation plan.

Structured methodology
Report you can use in your ISMS
Compatible with an ISO 27001 programme

What you get

At the end of the pentest

A detailed test report with proof of exploitation, severity levels and remediation recommendations — plus a technical and executive debrief session.

3–10 days
100% confidential
0 prod impact

93% of businesses have at least one critical vulnerability detectable in an external pentest

What is a pentest or penetration test?

A pentest is an authorised offensive security test. The aim is to work in a way close to that of an attacker, to check whether vulnerabilities on an application, a network or an infrastructure can actually be exploited.

Where a vulnerability scan mainly detects potential weaknesses, a penetration test seeks to assess their exploitability and real impact.

Identify

Entry points.

Test

Exploitable vulnerabilities.

Measure

Potential impact.

Remediate

Priority flaws.

Is a vulnerability scan enough to replace a pentest?

Automated scan

  • broad detection
  • automation
  • identification of potential weaknesses
  • little contextualisation

Pentest

  • human analysis
  • validation
  • business context
  • exploitation scenarios
  • real-impact assessment

The scan shows where to look. The pentest seeks to determine what is genuinely exploitable.

Pentest or bug bounty: what is the difference?

Pentest

  • limited duration
  • precise scope
  • identified team
  • structured methodology
  • complete report

Bug bounty

  • vulnerability research by several researchers under programme rules
  • generally ongoing
  • payment tied to validated flaws

The two approaches can be complementary, but they do not meet exactly the same need.

Cybersecurity audit or pentest: which service should you choose?

Comparison between a cybersecurity audit and a pentest
Cybersecurity audit Pentest
Global view of the IT system Targeted offensive test
Architecture & configuration Vulnerability exploitability
Processes & governance Attack simulation
Broad scope Precisely defined scope
Global roadmap Offensive technical report
OSCP, CEH, CISA certified pentesters Report with proof of exploitation Zero impact on production

+80 pentests completed

93% critical flaws detected

4.9/5 client satisfaction

Penetration tests we perform

External pentest, internal pentest, web pentest and social engineering testing — every attack vector is covered, from the network to applications.

External pentest: test your internet-exposed surface

An external pentest assesses your internet-facing surface: what an attacker can reach without prior access to your internal network.

  • exposed services
  • remote access
  • VPN
  • reachable infrastructure
  • public interfaces

Internal pentest: simulate an attacker already on your network

This internal intrusion simulation assesses what an attacker could achieve after initial access to an internal network.

  • segmentation
  • privileges
  • accounts
  • resource access
  • possible movement between environments

Web & application pentest: test your applications and interfaces

A web pentest and web application pentest cover your applications and interfaces: authentication, session management, authorisations, user inputs, application logic and APIs.

Tests are built around the main families of application risks recognised by OWASP.

Phishing & social engineering test

This phishing pentest (social engineering test) measures the organisation's resistance to a controlled manipulation or phishing campaign.

  • authorised campaign
  • defined population
  • indicators
  • debrief
  • awareness recommendations

Black box, grey box or white box: which pentest approach should you choose?

Black box

The tester has very little initial information and is closer to an external attacker scenario.

Grey box

Some information or access is provided in order to go deeper into the test.

White box

The tester has more complete technical information to analyse the scope in depth.

The test mode is chosen according to the objective, the budget, the depth required and the constraints of the environment.

A pentest performed only within an authorised, controlled framework

Written authorisation

The scope is contracted before testing begins.

Precise scope

Domains, IPs, applications, environments and exclusions.

Intervention window

Hours and constraints are defined.

Rules of engagement

Permitted actions, prohibited actions and emergency procedures are agreed.

No test is started without explicit validation of the scope and intervention rules.

How does a penetration test unfold?

Every pentest follows a structured method — from scoping to retest — so the engagement stays authorised, readable and actionable.

Hover or select a step to see the details.

  1. Scoping

    Scope, objectives, rules, exclusions.

  2. Reconnaissance

    Identification of the elements in scope.

  3. Analysis

    Search for and rating of vulnerabilities.

  4. Controlled tests

    Validation of their exploitability within the agreed limits.

  5. Impact assessment

    Technical and business rating.

  6. Cleanup & close-out

    Return of the environment to the agreed state.

  7. Report

    Findings, evidence, severity and recommendations.

  8. Debrief

    Presentation to the teams.

  9. Retest

    Verification of fixes if planned. See the retest.

01 Scoping

Scope, objectives, rules, exclusions.

How are identified flaws classified?

Critical

Critical

Exploitation likely to generate a major impact.

High

High

Significant risk requiring priority remediation.

Medium

Medium

A real weakness whose context reduces the impact or ease of exploitation.

Low

Low

Recommended improvement or hardening.

The final level is not based on a technical score alone: we also take exposure and business impact into account.

What does your pentest report contain?

A deliverable readable by leadership and actionable by IT: summary, vulnerability sheets and remediation roadmap.

Pentest report — anonymised example

Vulnerability sheet

Asset: Client application

Asset
Client application
Severity
High
Description
Insufficient access control on a feature.
Potential impact
Access to information normally restricted.
Recommendation
Review authorisation rules and add the necessary server-side controls.

Fictitious, anonymised example intended to illustrate the structure of the deliverable. It does not describe any exploitation technique.

Which pentest fits your need?

Your pentest

Recommended type Application pentest
Scope 2–5 targets
Estimated duration 4–6 days
  • Application100 %
  • Infrastructure40 %
  • Social engineering0 %
Retest

Deliverables

  • executive report
  • technical report
  • vulnerability severity
  • recommendations
  • debrief meeting
  • retest included

Indicative package

Application pentest

Get a scoping session

Indicative estimate. The final quote depends on the technical scope and rules of engagement.

Who should run a pentest?

Pentesting is no longer reserved for large enterprises. Any connected system is a potential target — better to test it before an attacker does.

E-commerce & SaaS

Your web applications and APIs are exposed 24/7 — an OWASP application pentest identifies flaws before your users or malicious bots do.

New applications

A new application, API or portal: an application pentest secures the product itself, not only the infrastructure around it.

SMEs handling sensitive data

Medical, financial or personal data — a pentest shows clients and partners that this data is actively protected.

ISO 27001 programme

A pentest can support risk management, technical controls and preparation for an ISO 27001 programme. It is not an ISO certification.

Client requirements

Very common in B2B: a client, buyer or partner asks for a pentest report to validate your security level.

Before go-live

New application, API, portal or infrastructure: the pentest is the last check before opening the service.

After a major change

Migration, rebuild, cloud, architecture change: a pentest checks that the new attack surface has not introduced flaws.

After remediation: we verify that vulnerabilities are actually closed

  1. Pentest
  2. Report
  3. Fixes
  4. Retest
  5. Validation

The retest targets previously identified vulnerabilities to verify that the implemented fixes are effective.

Optional

Application pentest

The retest is not included in the indicative price. You can add it at scoping — it is then billed separately.

Optional

Infrastructure pentest

Same approach as application testing : the retest is optional and billed separately, based on the findings to recheck.

Included

Full pentest

The retest is included in the engagement, together with 3-month remediation follow-up.

How much does a professional pentest cost?

The price of a penetration test depends primarily on the scope to be tested, not solely on the size of the company.

Application pentest

€2,900 – 5,500 excl. VAT

1 to 3 web applications / APIs

  • OWASP Top 10 testing
  • SQL injection, XSS, CSRF, IDOR
  • Authentication and access control testing
  • Report with proof of exploitation
  • Technical debrief (1h)

Retest Optional — billed separately

Request a quote

Full pentest (app + infra)

€6,500 – 12,000 excl. VAT

Full IT, sensitive sector

  • 360° pentest (app + infra + IT)
  • Social engineering (simulated phishing)
  • Realistic attack scenarios (APT)
  • Executive + technical report
  • Retest included
  • 3-month remediation follow-up included

Retest Included

Request a quote

Indicative pricing — a tailored quote is provided within 24 hours based on your exact scope. The retest is included in the full pentest; on the application and infrastructure offers, it is optional and billed separately.

What does the price of a pentest depend on?

The price of a penetration test is calculated from the actual scope — not a single flat fee. Cost depends in particular on these elements, confirmed during the first discussion.

Number of applications

Number of user roles

Number of APIs

Number of IPs / servers

Infrastructure complexity

External or internal pentest

Black / grey / white box

Production or test environment

Desired depth

Social engineering

Need for a retest

Specific client or framework requirements

How long does a pentest take?

Small scope

A few days.

Standard application or infrastructure

About one to two weeks, depending on preparation and depth.

Complex scope

Specific scheduling.

Scoping and access to environments strongly determine the timeline.

Your questions about pentesting

Our offensive security experts respond within 24 hours to all your questions.

Contact us
What is a pentest?

A pentest is an offensive security test performed within an authorised framework. It follows an attacker-like logic to check whether vulnerabilities on an application, network or infrastructure can actually be exploited. See the definition.

What does pentest mean?

Pentest is short for penetration testing. It is the same service. See the definition.

What is the difference between a pentest and a penetration test?

There is no fundamental difference: pentest is the English abbreviation of penetration testing. Both names refer to the same engagement. See the definition.

What is the difference between a cybersecurity audit and a pentest?

A cybersecurity audit gives a global view of the IT landscape: architecture, configuration, processes and governance. A pentest is a targeted offensive test, on a defined scope, to assess whether vulnerabilities are exploitable. An audit may come before a pentest; they are not the same service. See the comparison.

What is the difference between a vulnerability scan and a pentest?

A scan mainly detects potential weaknesses, often automatically. A pentest seeks to determine what is actually exploitable and what the impact would be. A scan is not a substitute for a pentest. See the comparison.

What is an external pentest?

An external pentest assesses your Internet-facing surface: what an attacker can reach without prior access to your internal network, including exposed services, remote access, VPN and public interfaces. See external pentest.

What is an internal pentest?

An internal pentest simulates an attacker already present on the network. It assesses segmentation, privileges, accounts and possible movement between environments. See internal pentest.

What is a web pentest?

A web pentest, or web application pentest, covers your applications and interfaces: authentication, sessions, authorisation, user input, application logic and APIs. Testing is built around the main application risk families recognised by OWASP. See web pentest.

What is a black box pentest?

In a black box pentest, the tester has very little initial information. The approach is close to an external attacker scenario. See test approaches.

What is the difference between black box, grey box and white box?

Black box: little initial information. Grey box: some information or access is provided to go deeper. White box: the tester has more complete technical information. The mode is chosen according to the objective, budget and desired depth. See test approaches.

Can you run a pentest on a production environment?

This is decided according to the scope and rules of engagement. Neither a systematic yes nor a systematic no: scoping sets the environment, the testing window and authorised actions. No test starts without explicit validation. See the authorised framework.

How much does a pentest cost?

The price of a pentest depends primarily on the scope to be tested, not solely on the size of the company. As a guide: application pentest €2,900–5,500 excl. VAT, infrastructure pentest €3,900–7,500 excl. VAT, full pentest €6,500–12,000 excl. VAT. See pricing.

What is the price of a penetration test?

The price of a penetration test is the price of a pentest: it is the same service. It is calculated from the scope (applications, APIs, IPs, test type, retest), with indicative ranges from €2,900 to €12,000 excl. VAT depending on the pack. See the price factors.

How long does a pentest take?

There is no universal rule. A small scope takes a few days. A standard application or infrastructure takes about one to two weeks, depending on preparation and depth. A complex scope requires specific scheduling. Scoping and access to environments strongly determine the timeline. See indicative timelines.

What does a pentest report contain?

A deliverable that leadership can read and IT can act on: an executive summary, vulnerability sheets and a remediation roadmap. See the report example.

What is a retest?

A retest targets previously identified vulnerabilities to verify that the implemented fixes are effective. It is included in the full pentest; on the application and infrastructure offers, it is optional and billed separately. See the retest.

Pentest or bug bounty: what is the difference?

A pentest is a structured engagement with a defined scope, carried out by a commissioned team within a limited timeframe. A bug bounty is an ongoing programme open to a community of security researchers. Both can be complementary, but they do not meet exactly the same need. See the comparison.

Can you run a phishing test?

Only within a framework that is explicitly authorised and defined with the organisation: authorised campaign, defined population and rules of engagement. See the phishing test.

Ready to simulate a real cyberattack on your systems?

Our certified pentesters test your defences and deliver a complete report with proof of exploitation. First conversation free, confidential, no commitment.

Start my pentest
First conversation free Zero production impact Report within 5 days
Innovation hub