Penetration testing for businesses
We try to get into your network the way an attacker would, only with your permission and without any damage. You will find out where they would really get in and what to do about it.

EXCELLENT Based on 627 reviews Posted on Google Matus LelkoTrustindex verifies that the original source of the review is Google. Veľmi ústretový personál, rýchle a úspešné prevedenie opravy tlačiarne. Môžem len vrelo odporúčaťPosted on Google MilanTrustindex verifies that the original source of the review is Google. Profesionálny prístup na riešenie uvedených problémov.Posted on Google Ľubomír GaraiTrustindex verifies that the original source of the review is Google. PRÍJEMNÝ PRACOVNÍCI, RÝCHLE A PROFESIONÁLNE OPRAVY.Posted on Google Ľuboš DudíkTrustindex verifies that the original source of the review is Google. Super firma, vždy keď som sa na nich s niečím obrátil, môj problém rýchlo vyriešili. Odporúčam 👍Posted on Google Eva SommierTrustindex verifies that the original source of the review is Google. S firmou IT pomoc som bola maximálne spokojná. Pomohli mi s kompletným nastavením internetového riešenia, routera aj preinštalovaním počítača. Oceňujem najmä vysoko odborný a profesionálny prístup, rýchlu komunikáciu a promptné dodanie služby. Pán Klozik je naozaj expert vo svojom odbore – všetko mi zrozumiteľne vysvetlil, navrhol najlepšie riešenie a celá realizácia prebehla bez problémov. Veľká spokojnosť z mojej strany a určite využijem Vaše služby aj v budúcnosti. Určite odporúčam.Posted on Google Jozef ČmeloTrustindex verifies that the original source of the review is Google. Som veľmi spokojný so službami firmy IT pomoc. Kedykoľvek som opakovane potreboval urgentne pomoc, vždy boli ochotní a pomohli. Vážim si okamžitú pomoc a ochotu pri vyriešení problémov s tlačiarňou, s internetovým spojením a podobne.Posted on Google Darina MalackáTrustindex verifies that the original source of the review is Google. Oceňujem ústretový prístup zamestnancov pobočky v BA, ktorí do 2 dní vyriešili náš problém s poškodením tlačiarne. Ďakujem vámVerified by TrustindexTrustindex verified badge is the Universal Symbol of Trust. Only the greatest companies can get the verified badge who has a review score above 4.5, based on customer reviews over the past 12 months. Read more
What a penetration test is
A penetration test is a controlled attempt to break into your systems using the same techniques real attackers use, but with your written consent and without causing any damage. Unlike an automated scan, we also verify whether a weakness found can genuinely be exploited. The output is a list of confirmed vulnerabilities ranked by severity and a concrete remediation plan. It is also one of the ways to demonstrate that your measures work under NIS2 and ISO 27001.
The penetration tests we run
Six perspectives on your security. We always agree the scope up front, based on what you actually need.
External penetration test

The attacker's view from the internet. We check everything you have exposed to the outside world: firewall, VPN, mail and web servers, plus remote access. Related: network and firewall protection →
Internal penetration test

A simulation of an attacker who is already inside the network, or of a disgruntled employee. It shows how far someone can move across the network and whether your segmentation actually holds.
Web application and API test

Your company website, e-shop, customer portal or the interfaces between systems. We look for flaws in login, permissions and input handling that could expose other people's data.
Wi-Fi network security test

We verify the strength of your encryption, the separation of the guest network from the corporate one, and whether Wi-Fi can be used to reach internal systems. More about network protection →
Social engineering and phishing

We test the weakest link, which is people. A controlled phishing campaign shows how many employees click and who enters a password. Results are anonymous. Training follows on →
Physical security test

Can someone reach the server room, a free network socket or an unlocked computer? We check your access controls and how staff respond to an unfamiliar face.
Black box, grey box, white box
They differ in how much information about your environment we receive at the start. We will recommend what makes the most sense in your situation.
Black box
No knowledgeWe start with what anyone on the internet can find out about you, which is usually just your company name and domain. This most closely mirrors a real attack from outside.
When: when you want to know how you stand against an opportunistic attacker.Grey box
Partial knowledgeWe get a basic overview of the environment and a standard user account. Less time goes into reconnaissance and more into the testing itself, so we usually find more.
When: the best value for money, which is why we choose it most often.White box
Full knowledgeWe have the documentation, network diagrams and administrator access, and sometimes the source code. The deepest and most complete view, revealing even flaws hidden in the configuration.
When: for critical systems and ahead of certification.How a penetration test works
We will not take your operations down We plan tests so they do not disrupt how your business runs. Riskier steps are done by agreement outside working hours, and we stay reachable throughout the test so anything can be stopped immediately. Get a testWhat you get at the end
The final report is written so that both management and technical staff can follow it. No raw scanner output.
Penetration test, IT audit or vulnerability scan?
Three different things that often get mixed up. They work best together, but they answer a different question.
| Vulnerability scan | IT audit | Penetration test | |
|---|---|---|---|
| Answers the question | Which known weaknesses do we have? | Do we have things set up correctly? | Can someone really get in? |
| How it works | Automatically, by a tool | Review of settings and documentation | Manually, by a person, with verification |
| False alarms | Frequent, they need checking | Rare | Ruled out, findings are confirmed |
| How often | Continuously, even monthly | After major changes | Typically once a year |
| Where to find it | Monitoring and oversight | Complete IT audit | This page |
If you are not yet sure what exactly you need, get in touch. We will advise based on the state your IT is in.

What the test gives you
Penetration testing and regulation
No law mandates a penetration test as a standalone obligation. It is, however, one of the most direct ways to show that your security measures genuinely work.
We are not a law firm. Always confirm the exact scope of your company's obligations with a lawyer as well.
Why choose penetration testing from IT HELP
We are not your typical IT crowd. We look after your technology with real expertise and a human touch, and we speak a language you understand.
We run penetration tests remotely, wherever you are based, with on-site visits when they are needed. Most tests we can do remotely; for internal and physical tests we come to you in person.
Our partners

Frequently asked questions
How much does a penetration test cost?
The price depends on the scope, meaning the number of IP addresses, applications and sites, on the type of test (external, internal, web application) and on the method chosen. A smaller external test costs a fraction of what full testing of an entire environment does. Get in touch and after a short conversation about scope we will prepare a tailored, no-obligation quote.
What is the difference between a penetration test and an IT audit?
An audit checks whether you have things set up correctly, meaning configurations, licences, processes and documentation. A penetration test practically verifies whether they can actually be broken through. The audit answers “is everything in order?”, the test answers “can someone get in?”. They work best together, and we recommend starting with a complete IT audit.
Is a penetration test the same as vulnerability scanning?
No. A scan is an automated tool that compares your systems against a database of known flaws and prints a list, which usually contains plenty of false alarms. A penetration test is done by a person who verifies each finding by attempting to exploit it. That is how you know what is a genuine risk and what is only a theoretical note.
How long does a penetration test take?
It depends on the scope. A smaller external test is a matter of a few days, while full testing of a larger environment takes longer and is usually split into phases. We agree the exact timing and duration up front when defining the scope, so you know what to expect.
Could the test take our operations down?
We plan tests so they do not put your operations at risk. Riskier steps are done by agreement outside working hours and we stay reachable during the test so anything can be stopped immediately. The scope, and the systems we must not touch, are agreed in writing beforehand.
How often should penetration tests be done?
In most companies, once a year. An extra test makes sense after a major change, for example after rolling out a new application, moving to the cloud, rebuilding the network or following a security incident. Between tests we recommend ongoing vulnerability scanning and monitoring.
Does NIS2 require penetration testing?
The NIS2 Directive (EU) 2022/2555 does not explicitly list a penetration test as an obligation. It does, however, require you to adopt security measures and verify their effectiveness. A penetration test is one of the most direct ways to evidence that verification. You will find the details on our NIS2 page.
Do we need a penetration test for ISO 27001?
ISO/IEC 27001 requires technical vulnerability management and verification that measures are effective. It does not prescribe a specific form, but a penetration test report is commonly accepted evidence in both certification and surveillance audits. IT HELP itself holds ISO 27001 and ISO 9001.
What does the final report contain?
A jargon-free executive summary for management, a technical section describing every vulnerability with proof and a severity rating, and a remediation plan ranked by priority. We go through the report with you and explain what to tackle first.
We are a small company, is it worth it for us?
Yes, we adapt the scope of the test to the size of your company. Smaller companies are often targets of automated attacks that do not discriminate, and an external test of what they expose to the internet is frequently enough. If you are unsure, get in touch and we will tell you honestly whether a test makes sense for you.
What do you need from us before we start?
Above all, written authorisation to test and a non-disclosure agreement. Then a contact person, a list of the systems in scope and those we must not touch. For internal and grey box tests we also need network access or a standard user account.
Do you also look after companies outside your immediate area?
Yes. We work with clients wherever they are based. External and web tests are run remotely from anywhere, and for internal and physical tests we come to you on site.
Find out how someone would get in
Get in touch and we will agree the scope of a penetration test that makes sense for your company. The quote is free and non-binding.
“Your trust inspires us”
Your next step
Network and device protection
We can fix the findings from the test straight away and secure the network.
→ View service
NIS2 compliance GAP analysis
Find out whether the rules apply to you and exactly what you must meet.
→ View serviceWhere to Find Us
IT HELP
Čajakova 26, Bratislava, Slovakia
Franz Mika Weg 7/1/25, Wien, Austria
Svatošská 23, Karlovy Vary, Czech Republic
We are available on business days Monday – Friday, 8:00 AM – 5:00 PM (or by arrangement)




