Ethical hacking

Penetration testing for businesses

We try to get into your network the way an attacker would, only with your permission and without any damage. You will find out where they would really get in and what to do about it.

External and internal tests Evidence for NIS2 and ISO 27001
Penetration test of a corporate network, IT HELP specialist analysing vulnerabilities

What a penetration test is

A penetration test is a controlled attempt to break into your systems using the same techniques real attackers use, but with your written consent and without causing any damage. Unlike an automated scan, we also verify whether a weakness found can genuinely be exploited. The output is a list of confirmed vulnerabilities ranked by severity and a concrete remediation plan. It is also one of the ways to demonstrate that your measures work under NIS2 and ISO 27001.

The penetration tests we run

Six perspectives on your security. We always agree the scope up front, based on what you actually need.

External penetration test

The attacker's view from the internet. We check everything you have exposed to the outside world: firewall, VPN, mail and web servers, plus remote access. Related: network and firewall protection →

Internal penetration test

A simulation of an attacker who is already inside the network, or of a disgruntled employee. It shows how far someone can move across the network and whether your segmentation actually holds.

Web application and API test

Your company website, e-shop, customer portal or the interfaces between systems. We look for flaws in login, permissions and input handling that could expose other people's data.

Wi-Fi network security test

We verify the strength of your encryption, the separation of the guest network from the corporate one, and whether Wi-Fi can be used to reach internal systems. More about network protection →

Social engineering and phishing

We test the weakest link, which is people. A controlled phishing campaign shows how many employees click and who enters a password. Results are anonymous. Training follows on →

Physical security test

Can someone reach the server room, a free network socket or an unlocked computer? We check your access controls and how staff respond to an unfamiliar face.

Black box, grey box, white box

They differ in how much information about your environment we receive at the start. We will recommend what makes the most sense in your situation.

Black box

No knowledge

We start with what anyone on the internet can find out about you, which is usually just your company name and domain. This most closely mirrors a real attack from outside.

When: when you want to know how you stand against an opportunistic attacker.

Grey box

Partial knowledge

We get a basic overview of the environment and a standard user account. Less time goes into reconnaissance and more into the testing itself, so we usually find more.

When: the best value for money, which is why we choose it most often.

White box

Full knowledge

We have the documentation, network diagrams and administrator access, and sometimes the source code. The deepest and most complete view, revealing even flaws hidden in the configuration.

When: for critical systems and ahead of certification.

How a penetration test works

1 Scope and consent We agree what is tested, what is off limits and when. We sign a testing authorisation and an NDA.
2 Information gathering We map what is visible from outside: services, domains, system versions and entry points.
3 Finding vulnerabilities We combine automated scanning with manual analysis, which uncovers what the tools miss.
4 Controlled verification We safely attempt to exploit each finding, so you know what is a real threat and what is a false alarm.
5 Report and handover You get the report, we go through it together and explain what to tackle first.
We will not take your operations down We plan tests so they do not disrupt how your business runs. Riskier steps are done by agreement outside working hours, and we stay reachable throughout the test so anything can be stopped immediately. Get a test

What you get at the end

The final report is written so that both management and technical staff can follow it. No raw scanner output.

Executive summaryBrief and jargon-free: what the overall risk is, what could happen and what it means for the business. Ready to take to a board meeting.
Technical findingsEvery vulnerability with a description, proof, a severity rating and the exact steps needed to fix it.
Remediation planFindings ranked by priority, so you know what to fix now, what to fix this quarter and what is cosmetic.

Penetration test, IT audit or vulnerability scan?

Three different things that often get mixed up. They work best together, but they answer a different question.

Vulnerability scan IT audit Penetration test
Answers the question Which known weaknesses do we have? Do we have things set up correctly? Can someone really get in?
How it works Automatically, by a tool Review of settings and documentation Manually, by a person, with verification
False alarms Frequent, they need checking Rare Ruled out, findings are confirmed
How often Continuously, even monthly After major changes Typically once a year
Where to find it Monitoring and oversight Complete IT audit This page

If you are not yet sure what exactly you need, get in touch. We will advise based on the state your IT is in.

An IT HELP specialist running a penetration test of a corporate network in a server room

What the test gives you

You find out how an attacker would get in, before anyone actually tries.
You verify that the measures you pay for really work.
You get evidence for NIS2 and ISO 27001 and for customers who ask.
You stop debating what counts as risk, because you have proof.
You direct spending where the gap actually is, not where the marketing points.
Management gets a readable report, not an impenetrable dump.

Penetration testing and regulation

No law mandates a penetration test as a standalone obligation. It is, however, one of the most direct ways to show that your security measures genuinely work.

NIS2, Directive (EU) 2022/2555 The Directive requires in-scope organisations to adopt security measures and to verify that they are effective. A penetration test is not mandatory in itself, but it is a practical way to evidence that your measures work. To find out whether the rules apply to you, see the GAP analysis or our NIS2 page.
Cybersecurity audits under the national implementing rules Audit frameworks built on NIS2 commonly list, among the documents an auditor may request, “the report from the most recent penetration testing”, including methodology, scope and evidence of the testers' qualifications, and this applies where penetration tests have been carried out. So the test is not compulsory, but if you have one, the auditor will ask for the report, which is why it pays to have a solid one.
ISO/IEC 27001 The standard does not mandate a pentest directly, but controls A.8.8 (technical vulnerability management) and A.8.29 (security testing) ask you for evidence that your measures work. A test report is evidence that auditors routinely accept. IT HELP itself holds ISO 27001 and ISO 9001.
Customer and supply chain requirements Supply chain security is a separate area of measures under NIS2. Regulated companies therefore write into supplier contracts the right to request evidence of security. So even if your own company is out of scope, your customer may still ask for a test.

We are not a law firm. Always confirm the exact scope of your company's obligations with a lawyer as well.

Why choose penetration testing from IT HELP

We are not your typical IT crowd. We look after your technology with real expertise and a human touch, and we speak a language you understand.

30+years of IT experience
ISO27001 & 9001
6types of test

We run penetration tests remotely, wherever you are based, with on-site visits when they are needed. Most tests we can do remotely; for internal and physical tests we come to you in person.

Our partners

Microsoft partner ESET partner Dell partner Synology partner VMware partner Epson partner TeamViewer partner Veeam partner KROS partner

Frequently asked questions

How much does a penetration test cost?

The price depends on the scope, meaning the number of IP addresses, applications and sites, on the type of test (external, internal, web application) and on the method chosen. A smaller external test costs a fraction of what full testing of an entire environment does. Get in touch and after a short conversation about scope we will prepare a tailored, no-obligation quote.

What is the difference between a penetration test and an IT audit?

An audit checks whether you have things set up correctly, meaning configurations, licences, processes and documentation. A penetration test practically verifies whether they can actually be broken through. The audit answers “is everything in order?”, the test answers “can someone get in?”. They work best together, and we recommend starting with a complete IT audit.

Is a penetration test the same as vulnerability scanning?

No. A scan is an automated tool that compares your systems against a database of known flaws and prints a list, which usually contains plenty of false alarms. A penetration test is done by a person who verifies each finding by attempting to exploit it. That is how you know what is a genuine risk and what is only a theoretical note.

How long does a penetration test take?

It depends on the scope. A smaller external test is a matter of a few days, while full testing of a larger environment takes longer and is usually split into phases. We agree the exact timing and duration up front when defining the scope, so you know what to expect.

Could the test take our operations down?

We plan tests so they do not put your operations at risk. Riskier steps are done by agreement outside working hours and we stay reachable during the test so anything can be stopped immediately. The scope, and the systems we must not touch, are agreed in writing beforehand.

How often should penetration tests be done?

In most companies, once a year. An extra test makes sense after a major change, for example after rolling out a new application, moving to the cloud, rebuilding the network or following a security incident. Between tests we recommend ongoing vulnerability scanning and monitoring.

Does NIS2 require penetration testing?

The NIS2 Directive (EU) 2022/2555 does not explicitly list a penetration test as an obligation. It does, however, require you to adopt security measures and verify their effectiveness. A penetration test is one of the most direct ways to evidence that verification. You will find the details on our NIS2 page.

Do we need a penetration test for ISO 27001?

ISO/IEC 27001 requires technical vulnerability management and verification that measures are effective. It does not prescribe a specific form, but a penetration test report is commonly accepted evidence in both certification and surveillance audits. IT HELP itself holds ISO 27001 and ISO 9001.

What does the final report contain?

A jargon-free executive summary for management, a technical section describing every vulnerability with proof and a severity rating, and a remediation plan ranked by priority. We go through the report with you and explain what to tackle first.

We are a small company, is it worth it for us?

Yes, we adapt the scope of the test to the size of your company. Smaller companies are often targets of automated attacks that do not discriminate, and an external test of what they expose to the internet is frequently enough. If you are unsure, get in touch and we will tell you honestly whether a test makes sense for you.

What do you need from us before we start?

Above all, written authorisation to test and a non-disclosure agreement. Then a contact person, a list of the systems in scope and those we must not touch. For internal and grey box tests we also need network access or a standard user account.

Do you also look after companies outside your immediate area?

Yes. We work with clients wherever they are based. External and web tests are run remotely from anywhere, and for internal and physical tests we come to you on site.

Find out how someone would get in

Get in touch and we will agree the scope of a penetration test that makes sense for your company. The quote is free and non-binding.

“Your trust inspires us”

Your next step

Complete IT audit

Complete IT audit

A full picture of the state of your IT, not just one way in.

→ View service
Network and device protection

Network and device protection

We can fix the findings from the test straight away and secure the network.

→ View service
NIS2 compliance GAP analysis

NIS2 compliance GAP analysis

Find out whether the rules apply to you and exactly what you must meet.

→ View service

IT HELP Hotline

+421 948 07 97 07

+421 2 5244 2951

+421 948 07 97 07

hotline@ithelp.digital

Where to Find Us

IT HELP
Čajakova 26, Bratislava, Slovakia
Franz Mika Weg 7/1/25, Wien, Austria
Svatošská 23, Karlovy Vary, Czech Republic

We are available on business days Monday – Friday, 8:00 AM – 5:00 PM (or by arrangement)