# Penetration testing

> Let’s find what to fix first.

A penetration test goes after your systems by hand and gives you a clear, ranked list to work from.

**Key points**

- Real exploitation, not a scanner report
- Findings you can reproduce, ranked by what to fix first
- Web, network, cloud, mobile and red team

## We test everything that matters to your business

### Applications and APIs

Your public web estate and the interfaces behind it, tested the way somebody with time and motive would test them.

### Network and cloud

Perimeter, internal segments and cloud configuration, including the paths that only open once a first foothold exists.

### The people and their real-life behaviour

A red team engagement that treats your staff and process as part of the attack surface, because an attacker does.

## What a test actually exercises

- **Web applications** — Authentication and session handling, access control between accounts and roles, injection, and the business logic a scanner cannot read — the checkout that can be made to charge nothing, the export that returns another tenant’s rows.
- **APIs** — REST, GraphQL and the internal interfaces behind them: object-level authorisation, mass assignment, rate limiting, and what the responses give away when they fail.
- **External network** — Everything you expose on purpose and everything you expose by accident — forgotten hosts, stale DNS, management interfaces that were only ever meant to be reachable from the office.
- **Internal network** — What one compromised laptop is worth: segmentation, credential reuse, privilege escalation, and how far it gets before anything notices.
- **Cloud** — Identity and permissions first, because that is where cloud breaches happen — over-broad roles, exposed storage, keys in places keys should not be.
- **Mobile** — The application on the device and the traffic leaving it: local storage, certificate handling, and the backend it talks to.
- **People and process** — On a red team engagement — phishing, pretext calls, and physical access, run against your real staff under rules agreed with you in writing.

## How it runs

1. **Scope** — What is in, what is out, and what would count as too far. Agreed in writing before anything starts.
2. **Test** — We go after it the way an attacker would, by hand. Every finding is proven rather than asserted, with the steps to reproduce it.
3. **Report** — You get the findings in the order they are worth fixing, each with what it takes to close it.

## What you get

**A clear, prioritised report — and a retest** — Every finding with proof, business impact and a fix, ordered by what an attacker reaches first rather than by scanner severity. Your developers get the reproduction steps; your board gets a page it can act on. When you have fixed them, we test again and confirm it in writing.

---

Canonical: https://centio.bg/uslugi/penetration-testing