Penetration Testing & actionable report
Find your weaknesses before an attacker does. Realistic intrusion testing, clear report, prioritized remediation plan.
🇫🇷 Version française disponible : flashmodz.be/entreprises/pentest
Pentest types
One format for each attack surface.
External
Public attack surface: website, API, VPN, public services.
Internal
Internal network, Active Directory, segmentation, lateral movement.
Web / Application
OWASP Top 10, business logic, authentication, API.
Cloud / Infra
AWS, Azure, GCP: IAM, exposed services, IaC review.
Custom scope
Defined with you based on your actual risk surface.
Our methodology
Scoping
Perimeter, objectives, testing window, rules of engagement, authorizations.
Recon & exploitation
OSINT, scanning, controlled exploitation of identified vulnerabilities.
Post-exploitation
Pivots, privilege escalation, persistence, within agreed scope.
Report & debrief
Executive + technical reports, prioritized remediation plan, oral debrief.
What you receive
Executive report
Business risk synthesis for C-level reading.
Technical report
Detailed findings (CVSS, proof of exploitation, recommendations).
Prioritized remediation plan
Quick wins · Mid-term · Strategic: clear decisions.
Oral debrief (1 h)
With your IT team to understand, validate, plan.
Critical findings retest
Included up to 30 days after report delivery.
Framework & compliance
Recognized standards, absolute confidentiality, regulatory alignment.
Standards
- • OWASP (Top 10, ASVS, WSTG)
- • PTES (Penetration Testing Standard)
- • MITRE ATT&CK
- • NIST SP 800-115
Compliance
- • NIS2 aligned (test/audit obligation)
- • ISO 27001 aligned (A.12, A.14 controls)
- • GDPR aligned (article 32)
- • DORA-compliant for financial sector
Confidentiality
- • NDA mandatory before any test
- • Written authorization mandate required
- • Data stored encrypted (AES-256)
- • Post-mission destruction documented
Indicative pricing
Fixed-price by scope. Detailed quote after a 30-minute scoping call.
Targeted external pentest
Full web / application pentest
Internal pentest
Annual program (4 tests)
| Format | Duration | Price |
|---|---|---|
| Targeted external pentest | 3 to 5 days | From €4,500 |
| Full web / application pentest | 5 to 10 days | From €8,000 |
| Internal pentest | 5 to 10 days | From €9,000 |
| Annual program (4 tests) | Yearly retainer | On request |
Frequently asked questions
Everything CISOs and decision-makers ask before a pentest.
Will my activity be disrupted during the test?
No, and it's a key point of the scoping. Exploitations are controlled and risky actions are scheduled outside production hours. A testing window is defined together.
How is it different from an audit or an automated scan?
A scan detects known vulnerabilities. A pentest reproduces a realistic attack with exploitation, attack chains and business logic. You get a real risk picture, not a theoretical list.
What authorizations do I need to provide?
A written mandate signed by a legal representative of your organization, explicitly authorizing testing on the defined perimeter. Template provided during scoping. NDA always included.
When will I receive the report and in what format?
Within 5-10 business days after testing ends. Encrypted PDF format (executive + technical reports separated), with an oral debrief via video or onsite.
Can you help us fix the findings?
Yes, either as part of a focused stabilization sprint or as a fractional Team Lead engagement. Pentest can be chained with these formats to reach effective remediation.
Reply within 24 hours, NDA available on request
Describe your need. We come back with scoping and a detailed quote.
A doubt, an urgency, a project?
One call is enough to scope your need and estimate a testing window.
Call