Skip to content
TheoSec

02Point-in-time · Scoped to you

Testing that proves
impact, not severity.

A scanner will tell you a port is open. A penetration test tells you what someone can do with it, how far they get, and what it would cost you. Every engagement here is manual, scoped to your environment, and delivered with a retest included.

  • Web applications & APIs
  • External & internal networks
  • Cloud infrastructure (AWS, Azure, GCP)
  • Mobile & IoT devices

//The difference

Automated tooling is a starting point, not a deliverable.

A great deal of what is sold as penetration testing is a vulnerability scan with a cover page. You can tell because the findings are all CVEs and missing headers, and nothing in the report demonstrates that anyone actually got in.

We run scanners too — they are efficient at the boring parts. But the findings that matter come from chaining a low-severity information leak into a valid session, or noticing that a workflow can be run out of order. No tool finds those.

If we claim something is exploitable, the report shows you the proof.

01What we test

Four surfaces, scoped to whichever ones you actually have.

Most engagements combine two or three of these. Scope is set by what matters to your business, not by a package tier.

Web applications & APIs

Authenticated, manual testing of your application logic — where the interesting failures actually live.

  • OWASP Top 10 and beyond
  • Business logic and workflow abuse
  • Authentication, session and access control
  • REST, GraphQL and internal APIs

Networks

External perimeter and internal assumed-breach testing, including lateral movement and privilege escalation.

  • External perimeter assessment
  • Internal / assumed-breach scenarios
  • Active Directory attack paths
  • Wireless and segmentation testing

Cloud infrastructure

Configuration and identity review across AWS, Azure and GCP, plus the container and serverless layers on top.

  • IAM roles, trust policies and escalation paths
  • Storage exposure and data access
  • Container and Kubernetes security
  • Serverless function permissions

Mobile & IoT

Application and device testing including reverse engineering, traffic interception and firmware analysis.

  • iOS and Android application testing
  • Static and dynamic analysis
  • Firmware extraction and review
  • Hardware and physical interfaces

02Methodology

Aligned to OWASP, PTES and NIST — executed by hand.

Recognised frameworks provide the coverage guarantees. Judgement provides the findings that matter.

  1. 01

    Scope

    We agree what is in bounds, what a realistic threat actor looks like for you, and what constitutes a meaningful result.

  2. 02

    Reconnaissance

    Mapping the target properly before touching it. Time spent here is what separates a real test from a scan.

  3. 03

    Exploitation

    Controlled exploitation to establish genuine impact and chain findings together the way an attacker would.

  4. 04

    Report & retest

    Written report, live walkthrough with your engineers, and a retest once remediation is done to confirm the fix.

03What you receive

Three things, all of them useful.

The report

An executive summary your board can read, full technical detail your engineers can reproduce, CVSS scoring, and a remediation order of work that reflects real risk rather than raw severity.

The walkthrough

A live session with your technical team going through the findings, the exploitation path, and the fixes. Questions answered by the people who did the work, not an account manager.

The retest

Once you have remediated, we verify the fixes actually hold and issue an updated report. A finding is not closed because a ticket was closed.

04Compliance

Documentation your auditor will accept.

Reports are structured to satisfy the testing requirements in the frameworks below. Worth saying plainly: passing an audit and being difficult to compromise are different goals. This work is aimed at the second, and produces the evidence for the first as a by-product.

  • PCI-DSS
  • ISO 27001
  • SOC 2
  • HIPAA
  • GDPR
  • POPIA

Next step

Tell me what you are worried about.

Scoping starts with a conversation about your environment and your actual concerns — not a quantity of days. If a smaller piece of work would answer your question, that is what we will propose.

daniel@theosec.com · +27 63 484 1051